Automated Threat Modeling via Application Relationship Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing manual threat modeling techniques for software products are prone to human error, incomplete, and not performed frequently enough, leading to inaccuracies and increased latency in addressing security threats and policy compliance issues in distributed systems.

Innovation Solution

Automated threat modeling using a graph-based approach that captures intra-application and inter-application relationships, employing static and dynamic analysis, and rules engines to identify security threats and vulnerabilities, with the ability to trigger repeated security reviews throughout the software lifecycle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual threat modeling techniques are used, then human expertise can be applied to identify security threats, but human error and incomplete analysis increase, reducing reliability

Engineering Contradiction:
Improvethreat modeling accuracyVSAvoidsecurity threat detection completeness
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent replaces manual threat modeling processes with automated computer-based analysis. The system uses software to perform static and dynamic analysis of application relationships, substituting human mechanical analysis with automated computational methods that eliminate human error and provide consistent, repeatable results across multiple analysis cycles.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service threat modeling by automatically analyzing application relationships without requiring continuous human intervention. The automated analysis engine can independently execute threat modeling tasks, generate reports, and update analyses when changes are detected in the application environment.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual threat modeling is performed, then detailed security analysis can be conducted, but the frequency of threat modeling decreases, increasing latency in addressing security threats

Engineering Contradiction:
Improvesecurity complianceVSAvoidlatency in addressing security threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous threat modeling through automated analysis that can operate continuously without interruption. The system maintains ongoing monitoring of application relationships and performs repeated security analyses, ensuring continuous security assessment rather than periodic manual reviews.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs periodic threat modeling automatically at scheduled intervals or when triggered by specific events such as code changes or configuration updates. This periodic automated action ensures regular security reassessment without requiring manual initiation, reducing the time between security threats and their detection.

Inventive Principle:
Principle #19Periodic action

3Reliability

If comprehensive threat modeling of entire distributed systems is performed, then complete security coverage is achieved, but the complexity and time required for analysis increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidthreat modeling system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the distributed system into individual application components and analyzes their relationships through a graph model. Each application and its dependencies are represented as separate nodes and edges, allowing the system to break down complex threat modeling into manageable segments that can be analyzed independently and then integrated.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from traditional flat threat modeling to a multi-dimensional graph-based representation. The graph model adds dimensions for application relationships, data flows, and dependency structures, enabling comprehensive security coverage while organizing complexity in a structured, visualizable format that simplifies analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If repeated security reviews are conducted throughout the software lifecycle, then security compliance improves, but the time and resources required increase

Engineering Contradiction:
Improvepolicy complianceVSAvoidtime for security reviews
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary threat modeling during the software development lifecycle at multiple stages before deployment. By conducting automated security analysis early in development and before code changes are deployed, the system prevents security issues from reaching production environments, reducing the need for extensive post-deployment security reviews.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where threat modeling results automatically trigger notifications and remediation workflows. When security issues are detected, the system provides feedback to developers and security teams, enabling rapid response and correction. This automated feedback mechanism reduces the time required for security compliance by eliminating manual review cycles.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240289450A1Automated threat modeling using application relationships
Publication Date: 2024.08.29 AMAZON TECH INC
  • US20240289450A1 patent drawing
  • US20240289450A1 patent drawing
  • US20240289450A1 patent drawing

AI summary

Methods, systems, and computer-readable media for automated threat modeling using application relationships are disclosed. A graph is determined that includes of nodes and edges. At least a portion of the nodes represent software components, and at least a portion of the edges represent relationships between software components. An event is received, and a sub-graph associated with the event is determined. The event is indicative of a change to one or more of the nodes or edges in the graph. Threat modeling is performed on the sub-graph using one or more analyzers. The one or more analyzers determine whether the sub-graph is in compliance with one or more policies.