Threat Modeling System for Automated Diagram Import

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional threat modeling methodologies are inadequate for assessing organizational risk, as they focus on individual applications, require security experts, are resource-intensive, and cannot scale to meet the needs of enterprises with multiple software applications, nor do they effectively model application interactions, third-party elements, or communicate risks to non-experts.

Innovation Solution

A threat modeling system that uses databases to store threat model components and threats, with mapping files correlating these components with third-party diagram components, allowing for the generation of relational diagrams and threat reports that visualize and communicate potential threats and their impacts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional threat modeling methodologies are used to analyze individual applications, then security analysis can be performed, but the process cannot scale to meet the needs of enterprises with multiple software applications and is resource-intensive

Engineering Contradiction:
Improvethreat modeling scalabilityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the threat modeling process into distinct components: data flow diagram creation, automatic threat identification, and risk assessment. This segmentation allows the system to handle multiple applications by processing each through standardized segments, improving scalability without proportionally increasing overall system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The threat modeling system is designed as a universal platform that can analyze multiple different software applications through a common interface and methodology. The system uses standardized data flow diagram templates and threat libraries that can be applied across diverse applications, enabling enterprise-wide scalability while maintaining consistent security analysis practices

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If traditional threat modeling requires security subject-matter experts for creation, use, and maintenance, then accurate threat analysis can be achieved, but the process becomes inaccessible to non-experts and harder to maintain

Engineering Contradiction:
Improvethreat analysis accuracyVSAvoiduser accessibility
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system enables non-expert users to perform threat modeling through automated features. The system automatically generates data flow diagrams from application specifications, identifies threats using pre-configured libraries, and assesses risks without requiring manual intervention from security experts. This self-service capability maintains analysis accuracy while dramatically improving accessibility

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an automated intermediary layer between non-expert users and complex threat analysis tasks. This intermediary automatically translates user inputs into security analyses using expert-level algorithms and threat libraries, allowing non-experts to access expert-level analysis capabilities without needing specialized knowledge

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If traditional threat modeling focuses on single applications operating in isolation, then detailed application-level security can be assessed, but application-application interactions and organizational risk are not fully accounted for

Engineering Contradiction:
Improveapplication-level security analysisVSAvoidorganizational risk assessment capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system merges individual application threat models into a comprehensive organizational view. By automatically analyzing data flow diagrams across multiple applications and identifying inter-application data flows, the system combines isolated application-level analyses into an integrated organizational risk assessment, maintaining precision at both levels simultaneously

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If traditional threat modeling methodologies are resource-intensive to build and maintain, then thorough security analysis can be performed, but the process cannot be effectively scaled to enterprises generating tens of software applications per year

Engineering Contradiction:
Improvesecurity analysis thoroughnessVSAvoidsoftware development throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary threat identification and data flow diagram generation automatically during the software development process, before formal security reviews are needed. By pre-identifying threats and documenting data flows as applications are built, the system maintains thorough security analysis while reducing the time and resources needed for later security assessments, enabling faster software delivery

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10713366B2Systems and methods for automated threat model generation from third party diagram files
Publication Date: 2020.07.14 THREATMODELER SOFTWARE INC
  • US10713366B2 patent drawing
  • US10713366B2 patent drawing
  • US10713366B2 patent drawing

AI summary

Threat modeling systems include one or more computing devices communicatively coupled with one or more databases, the database(s) including threat model components and threats associated with one another. One or more mapping files coupled with the database(s) correlate the threat model components with visual diagram components of a third party software application. An import interface initiates reading of a third party generated data file by the computing device(s), the data file including a subset of the third party diagram components and relationships between the subset. An interface receiving input initiates a determination of threat model components correlated with the subset. A diagram interface displays a relational diagram using visual representations of threat model components correlated with the subset, the relational diagram defining a threat model. A threat report interface includes a threat report displaying each threat that is associated with one of the threat model components of the threat model.