Threat Model Update via NLP Attribute Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat models are resource-intensive to maintain and require significant effort to update when new threats are discovered, as they need to be reviewed across potentially thousands of applications to determine susceptibility and necessary updates.

Innovation Solution

A threat modeling tool utilizing natural language processing and machine learning to automatically identify and update threat models by comparing newly identified threats with existing models, thereby focusing resources on impacted applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review of all existing threat models is performed when a new threat is discovered, then complete security assessment is achieved, but significant time and computational resources are consumed

Engineering Contradiction:
Improvesecurity assessment completenessVSAvoidthreat model update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary natural language processing system that acts as a mediator between new threat intelligence and existing threat models. The NLP system automatically parses threat descriptions, extracts relevant attributes, and matches them against threat model attributes, eliminating the need for manual review of all threat models while maintaining comprehensive security assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual review process with an automated computational system. The NLP-based system automatically compares new threat attributes with existing threat model attributes using algorithmic matching, substituting human analysts and manual processes with automated text processing and comparison mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive review of all threat models is conducted to ensure security, then all vulnerabilities are identified, but processing resources are heavily consumed

Engineering Contradiction:
Improvevulnerability identification completenessVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the relevant attributes from new threat descriptions using NLP techniques. Instead of processing entire threat models or conducting comprehensive reviews, the system identifies and extracts key attributes (such as affected software components, vulnerability types, and threat characteristics) and matches only those against corresponding attributes in existing threat models, significantly reducing processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by performing attribute-based matching rather than complete threat model reviews. The system processes only the essential attributes needed for vulnerability identification, using a subset of the full threat model data to achieve effective security assessment with reduced computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If frequent updates to threat models are performed to maintain current security posture, then security reliability is improved, but the complexity of maintenance increases

Engineering Contradiction:
Improvesecurity posture currencyVSAvoidthreat model maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated NLP-based threat model updates. The system automatically parses new threat intelligence, extracts attributes, performs matching against existing threat models, and generates update recommendations without requiring manual intervention. This automation maintains current security posture while eliminating the complexity of manual maintenance processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary action by pre-processing and structuring threat intelligence data using NLP techniques before matching occurs. The system预先 extracts and normalizes attributes from threat descriptions, creating a ready-to-match format that simplifies the subsequent comparison process and enables rapid updates when new threats are identified.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12111933B2System and method for dynamically updating existing threat models based on newly identified active threats
Publication Date: 2024.10.08 BANK OF AMERICA CORP
  • US12111933B2 patent drawing
  • US12111933B2 patent drawing
  • US12111933B2 patent drawing

AI summary

A system includes a database, a memory, and a processor. The database stores data associated with a known security threat. The memory includes a threat model associated with a software application. The processor identifies, based on natural language processing of the data associated with the known security threat, one or more attributes of software susceptible to the known security threat. The processor also identifies, based on natural language processing of the threat model, one or more attributes of the software application. The processor additionally determines, based on a comparison between the one or more attributes of software susceptible to the known security threat and the one or more attributes of the software application, that the software application is susceptible to the known security threat. In response, the processor updates the threat model to reflect the susceptibility of the software application to the known security threat.