Threat Modeling System with Dynamic Compensating Control Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat modeling systems lack efficient methods for dynamically updating threat models and assessing compensating controls, leading to incomplete or inaccurate risk assessments and mitigation strategies.

Innovation Solution

The system includes a data store with threat model components, threats, and compensating controls, allowing users to create relational diagrams and reports that dynamically update based on user inputs, enabling the identification of mitigated threats and the assessment of compensating controls' effectiveness without manual penetration testing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional threat modeling systems are used, then threat analysis can be performed, but the process is resource-intensive and requires manual penetration testing which is time-consuming and costly

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidtime for penetration testing
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates virtual copies of security controls and threats that can be simulated computationally. Instead of performing actual penetration tests, the system uses modeled representations of attacks and defenses to assess risk, dramatically reducing time and resource requirements while maintaining assessment accuracy.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary computational analysis of threat scenarios before actual security incidents occur. By pre-modeling various attack vectors and control effectiveness in a virtual environment, the system prepares risk assessments in advance without requiring time-consuming manual penetration testing when real threats emerge.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive threat modeling is performed, then complete risk assessment is achieved, but the system complexity and data management burden increase

Engineering Contradiction:
Improverisk assessment completenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the threat modeling system into distinct modular components: threat definitions, control definitions, scenario builders, and assessment engines. Each component handles specific aspects of risk analysis independently, allowing comprehensive threat modeling while managing system complexity through clear separation of concerns and standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs universal data structures and modeling frameworks that can represent multiple types of threats, controls, and scenarios using the same underlying architecture. This multi-functional approach allows the system to handle diverse security assessment needs without proportionally increasing complexity, as the same core engine serves multiple assessment purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If manual threat analysis methods are used, then detailed security assessment can be conducted, but productivity and speed of risk management are reduced

Engineering Contradiction:
Improvethreat analysis detailVSAvoidrisk management speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system incorporates automated feedback loops where computational models continuously analyze threat scenarios, evaluate control effectiveness, and update risk assessments based on simulated outcomes. This automated feedback mechanism maintains detailed analysis quality while dramatically increasing productivity by eliminating manual iteration cycles inherent in traditional threat modeling approaches.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces manual mechanical analysis processes with computational modeling systems. Instead of security analysts manually working through each threat scenario and control evaluation, automated algorithms perform the analytical work, preserving the detail and thoroughness of manual analysis while achieving orders of magnitude improvement in processing speed and productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11620386B2Threat modeling systems and related methods including mitigating components
Publication Date: 2023.04.04 THREATMODELER SOFTWARE INC
  • US11620386B2 patent drawing
  • US11620386B2 patent drawing
  • US11620386B2 patent drawing

AI summary

Threat modeling methods include providing one or more data stores storing threat model components, threats, and security requirements, each threat associated with at least one of the threat model components, each security requirement including a stored indication of whether it is a compensating control, and each compensating control associated with one of the threats. One or more computing devices communicatively coupled with the one or more data stores display a relational diagram of a system, an application, and/or a process, using visual representations of the threat model components, the diagram defining a threat model. The one or more computing devices display a threat report displaying each threat associated with one of the threat model components included in the threat model. The one or more computing devices further display a compensating control report displaying each compensating control that is associated with one of the threats included in the threat report.