Threat Modeling for Complex System Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity threat modeling techniques are inadequate for complex systems like aircraft, as they focus on individual systems rather than the entire platform, failing to address large-scale integrations effectively.

Innovation Solution

A system comprising a processor and memory that implements a data flow diagram creator, threat indicator, and threat analyzer to model and analyze cybersecurity threats across a complex-system platform, identifying elements, data flows, and security controls, and providing structured information to mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional threat modeling techniques are used for individual systems, then analysis simplicity is maintained, but comprehensive security coverage for complex-system platforms is lost

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex-system platform into hierarchical levels (platform level, system level, component level) and applies threat modeling at each level separately. This allows comprehensive security coverage across the entire platform while managing analysis complexity through structured division of the analysis scope.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested threat models where component-level threats are contained within system-level models, which are in turn contained within platform-level models. This nesting structure enables comprehensive analysis by systematically incorporating threats from multiple levels while organizing the complexity in a manageable hierarchical framework.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If threat modeling focuses on individual systems, then analysis time is reduced, but integration security risks are missed

Engineering Contradiction:
Improveintegration securityVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary threat identification at the component level before integrating systems, and conducts platform-level threat modeling that encompasses all integrated systems. This preliminary action ensures integration security risks are identified early in the design phase, preventing security gaps before they manifest in the integrated platform.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges individual system threat models into a comprehensive platform-level threat model that captures integration security risks. By combining threat analyses from multiple levels and perspectives, the methodology identifies security risks that emerge only when systems are integrated, providing holistic coverage of integration security.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If comprehensive platform-wide threat modeling is implemented, then security coverage is improved, but analysis complexity increases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidmodeling complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides platform-wide threat modeling into discrete hierarchical levels and structured components, allowing comprehensive analysis to be broken down into manageable segments that can be analyzed systematically without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent develops a universal threat modeling framework that can be applied across all levels of the complex-system platform (component, system, and platform levels). This multi-functional approach provides consistent methodology and notation throughout, reducing modeling complexity by using the same framework universally rather than developing separate approaches for each level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9602529B2Threat modeling and analysis
Publication Date: 2017.03.21 THE BOEING CO
  • US9602529B2 patent drawing
  • US9602529B2 patent drawing
  • US9602529B2 patent drawing

AI summary

A system is provided for modeling and analysis of cybersecurity threats may include a data flow diagram (DFD) creator, threat indicator and threat analyzer. The DFD creator may identify elements of an information system, and compose a DFD including nodes and edges representing components and data flows of the information system. The threat indicator may identify a cybersecurity threat to a particular element of the information system, and add a secondary node representing the cybersecurity threat to the DFD to thereby produce a threat-model DFD for the information system. In metadata associated with the nodes, edges and secondary node, the DFD creator and threat indicator may provide structured information including attributes of the components, data flows and cybersecurity threat. And the threat analyzer may perform an analysis of the cybersecurity threat based on the threat-model DFD and metadata associated with the nodes, edges and secondary node thereof.