IP Library Granted Patent US 12,536,302
Granted Patent B2
US 12,536,302 · App. 18/457,420 · Granted Jan 27, 2026

Live threat modeling framework

Inventors: John Walker (Kannapolis, NC); Ankur Desai (Whitestone, NY)
Assignee: Wells Fargo Bank, N.A.
G06F21/577G06F8/77G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,302
App. No.
18/457,420
Granted
Jan 27, 2026
Kind
B2
Abstract

An example computer system for live threat modeling for an enterprise can include: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to: prepare abstracts for applications associated with the enterprise to form a threat model; monitor development phases of the applications; and apply the threat model to the applications during each of the development phases to identify risk.

Claims (32)

1 . A computer system for live threat modeling for an enterprise, comprising:

one or more processors; and

non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to:

prepare abstracts for applications associated with the enterprise to form a threat model, wherein the abstracts are dynamic structured data representations of the applications throughout development phases of the applications;

monitor the development phases of the applications;

apply the threat model to incremental changes to the applications as defined by the abstracts during each of the development phases to identify risk; and

automatically update the threat model through one or more calls to an application programming interface in near-real time using the abstracts.

2 . The computer system of claim 1 , wherein the abstracts define build information for the applications, functionality associated with the applications, and dependencies associated with the applications.

3 . The computer system of claim 1 , wherein the threat model is stored in a database, and the database is automatically updated.

4 . The computer system of claim 1 , wherein the development phases include:

a design phase during which the applications are coded;

a build phase during which the applications are compiled; and

a deployment phase during which the applications are introduced into a production environment.

5 . The computer system of claim 1 , comprising further instructions which, when executed by the one or more processors, causes the computer system to generate a dashboard to provide threat information associated with the enterprise.

6 . The computer system of claim 5 , wherein the dashboard includes one or more menus to filter the threat information.

7 . The computer system of claim 6 , wherein the one or more menus include a first menu to filter by line of business and a second menu to filter by one or more of the applications.

8 . The computer system of claim 1 , comprising further instructions which, when executed by the one or more processors, causes the computer system to mitigate the risk associated with the applications.

9 . A method for live threat modeling for an enterprise, comprising:

preparing abstracts for applications associated with the enterprise to form a threat model, wherein the abstracts are dynamic structured data representations of the applications throughout development phases of the applications;

monitoring the development phases of the applications;

applying the threat model to incremental changes to the applications as defined by the abstracts during each of the development phases to identify risk; and

automatically updating the threat model through one or more calls to an application programming interface in near-real time using the abstracts.

10 . The method of claim 9 , wherein the abstracts define build information for the applications, functionality associated with the applications, and dependencies associated with the applications.

11 . The method of claim 9 , wherein the threat model is stored in a database, and the database is automatically updated.

12 . The method of claim 9 , wherein the development phases include:

a design phase during which the applications are coded;

a build phase during which the applications are compiled; and

a deployment phase during which the applications are introduced into a production environment.

13 . The method of claim 9 , further comprising generating a dashboard to provide threat information associated with the enterprise.

14 . The method of claim 13 , wherein the dashboard includes one or more menus to filter the threat information.

15 . The method of claim 14 , wherein the one or more menus include a first menu to filter by line of business and a second menu to filter by one or more of the applications.

16 . The method of claim 9 , further comprising mitigating the risk associated with the applications.

Assignments (2)
STATEMENT OF CHANGE OF ADDRESS OF ASSIGNEE Recorded Jun 17, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071644/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2024
From: WALKER, JOHN
To: WELLS FARGO BANK, N.A.
Reel/Frame 066226/0806 →
Continuity (1)
Related Publication 20250077679A1 · Mar 6, 2025
References Cited (11)
US 7243374B2 · Howard · 2007 [cited by examiner]
US 8091065B2 · Mir · 2012 [cited by examiner]
US 20150347759A1 · Cabrera · 2015 [cited by examiner]
US 20170169230A1 · Zheng · 2017 [cited by examiner]
US 20190028498A1 · Fach · 2019 [cited by examiner]
US 20200186563A1 · Convertino · 2020 [cited by examiner]
US 20210294901A1 · Agarwwal · 2021 [cited by examiner]
OWASP Foundation, Inc., “About the OWASP Foundation”, www.owasp.org/about/, copyright 2023, 6 pages. [cited by applicant]
National Institute of Standards and Technology, “Cybersecurity Framework”, accessed Aug. 29, 2023, 4 pages. [cited by applicant]
U.S. Appl. No. 18/456,777, filed Aug. 28, 2023. [cited by applicant]
U.S. Appl. No. 17/308,478, filed May 5, 2021. [cited by applicant]