IP Library Granted Patent US 12,306,959
Granted Patent B2
US 12,306,959 · App. 18/497,355 · Granted May 20, 2025

Threat model chaining and attack simulation systems and related methods

Inventors: Anuraag Agarwwal (Jersey City, NJ); Pratik Anil Thakker (Wood Ridge, NJ)
Assignee: THREATMODELER SOFTWARE INC.
G06F21/577G06F21/563G06F30/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,306,959
App. No.
18/497,355
Granted
May 20, 2025
Kind
B2
Abstract

Systems and methods for determining one or more security threats associated with code in a code file are described. The method includes analyzing the code file to identify one or more properties, of a plurality of properties associated with one or more resources included in the code file. For each property of the identified one or more properties, the method further includes identifying a value for the property defined in the code file, and determining whether a security threat is associated with the property based on the identified value for the property and information regarding security threats associated with one or more values of the plurality of properties.

Claims (48)

1. A threat model chaining method, comprising:

providing one or more databases, the one or more databases storing:

a plurality of threat model components, each threat model component defining one or more elements of systems, applications, or processes; and

a plurality of threat models, each threat model associated with at least one threat model component of the plurality of threat model components;

providing one or more interfaces, including a diagram interface, configured to be displayed on one or more end user computing devices communicatively coupled with the one or more databases;

configuring the diagram interface to display a relational diagram of one of a system, an application, or a process, using visual representations of at least one first threat model component, the relational diagram defining a first threat model based on the at least one first threat model component; and

configuring the diagram interface to, in response to receiving one or more first user inputs, add at least one second threat model component to the displayed relational diagram and thereby update the first threat model by adding at least one second threat model associated with the at least one second threat model component to the first threat model,

wherein the at least one second threat model component is not a part of the first threat model before being added,

wherein the at least one second threat model component comprises a predefined interrelated group of two or more elements of the system, the application, or the process, and

wherein the at least one second threat model component changes a composition of the system, the application, or the process.

2. The threat model chaining method of claim 1 , further comprising configuring the diagram interface to, in response to receiving a user selection of one threat model component of the at least one first threat model component or the at least one second threat model component, visually display attack paths of all threats associated with the selected threat model component.

3. The threat model chaining method of claim 2 ,

wherein the one or more databases further store a plurality of compensating controls, each compensating control designed to mitigate at least one threat identified in at least one threat model of the plurality of threat models,

the method further comprising configuring the diagram interface to, in response to receiving a user toggle of a first compensating control of the selected threat model component to an on state, toggle all attack paths, of the displayed attack paths, mitigatable by the first compensating control to a mitigated display state.

4. The threat model chaining method of claim 3 , further comprising configuring the diagram interface to, in response to receiving a user toggle of the first compensating control to an off state, toggle all the attack paths mitigatable by the first compensating control to an unmitigated display state.

5. The threat model chaining method of claim 3 , further comprising configuring the diagram interface to, in response to receiving a second user selection to remove the first compensating control from the updated first threat model, toggle all the attack paths mitigatable by the first compensating control to an unmitigated display state.

6. The threat model chaining method of claim 2 ,

wherein the selected threat model component includes a plurality of elements,

the method further comprising configuring the diagram interface to, in response to receiving a second user selection corresponding to one or more elements of the plurality of elements, visually display only attack paths of all threats associated with the selected one or more elements.

7. The threat model chaining method of claim 2 , further comprising configuring the diagram interface to, in response to receiving a second user selection to alter a profile of an attacking component, alter the visually displayed attack paths.

8. The threat model chaining method of claim 1 , further comprising, in response to receiving one or more second user inputs, storing one or more additional threat model components in the one or more databases, and storing one or more additional threat models associated with the one or more additional threat model components in the one or more databases.

9. The threat model chaining method of claim 1 ,

wherein at least one element of the two or more elements of the at least one second threat model component is another threat model component of the plurality of threat model components, and

wherein the at least one second threat model associated with the at least one second threat model component includes another threat model associated with the another threat model component, thereby defining nested threat models.

10. A threat model chaining system, comprising:

one or more memory devices configured to store one or more databases, the one or more databases storing:

a plurality of threat model components, each threat model component defining one or more elements of systems, applications, or processes; and

a plurality of threat models, each threat model associated with at least one threat model component of the plurality of threat model components; and

one or more computing devices communicatively coupled with the one or more memory devices storing the one or more databases, the one or more computing devices configured to:

display, on one or more displays of the one or more computing devices one or more input interfaces including a diagram interface, wherein the diagram interface is configured to display a relational diagram of one of a system, an application, or a process, using visual representations of at least one first threat model component, the relational diagram defining a first threat model based on the at least one first threat model component; and

in response to receiving one or more first user inputs, add at least one second threat model component to the displayed relational diagram and thereby update the first threat model by adding at least one second threat model associated with the at least one second threat model component to the first threat model,

wherein the at least one second threat model component is not a part of the first threat model before being added,

wherein the at least one second threat model component comprises a predefined interrelated group of two or more elements of the system, the application, or the process, and

wherein the at least one second threat model component changes a composition of the system, the application, or the process.

11. The threat model chaining system of claim 10 , wherein the diagram interface is further configured to, in response to receiving a user selection of one threat model component of the at least one first threat model component or the at least one second threat model component, visually display attack paths of all threats associated with the selected threat model component.

12. The threat model chaining system of claim 10 , wherein the one or more computing devices are further configured to, in response to receiving one or more second user inputs, storing one or more additional threat model components in the one or more databases, and storing one or more additional threat models associated with the one or more additional threat model components in the one or more databases.

13. The threat model chaining system of claim 11 ,

wherein the one or more databases further store a plurality of compensating controls, each compensating control designed to mitigate at least one threat identified in at least one threat model of the plurality of threat models, and

wherein the diagram interface is further configured to, in response to receiving a user toggle of a first compensating control of the selected threat model component to an on state, toggle all attack paths, of the displayed attack paths, mitigatable by the first compensating control to a mitigated display state.

14. The threat model chaining system of claim 13 , wherein the diagram interface is further configured to, in response to receiving a user toggle of the first compensating control to an off state, toggle all the attack paths mitigatable by the first compensating control to an unmitigated display state.

15. The threat model chaining system of claim 13 , wherein the diagram interface is further configured to, in response to receiving a second user selection to remove the first compensating control from the updated first threat model, toggle all the attack paths mitigatable by the first compensating control to an unmitigated display state.

16. The threat model chaining system of claim 11 ,

wherein the selected threat model component includes a plurality of elements, and

wherein the diagram interface is further configured to, in response to receiving a second user selection corresponding to one or more elements of the plurality of elements, visually display only attack paths of all threats associated with the selected one or more elements.

17. The threat model chaining system of claim 11 , wherein the diagram interface is further configured to, in response to receiving a second user selection to alter a profile of an attacking component, alter the visually displayed attack paths.

18. The threat model chaining system of claim 10 ,

wherein at least one element of the two or more elements of the at least one second threat model component is another threat model component of the plurality of threat model components, and

wherein the at least one second threat model associated with the at least one second threat model component includes another threat model associated with the another threat model component, thereby defining nested threat models.

Assignments (3)
SECURITY INTEREST Recorded Dec 30, 2025
From: THREATMODELER SOFTWARE, INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 073340/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2025
From: THAKKER, PRATIK ANIL
To: THREATMODELER SOFTWARE INC.
Reel/Frame 070321/0139 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2023
From: AGARWWAL, ANURAAG
To: THREATMODELER SOFTWARE INC.
Reel/Frame 065389/0323 →
Continuity (13)
Continuation 17709670 · Mar 31, 2022
Continuation 17479815 · Sep 20, 2021
Continuation In Part 16950509 · Nov 17, 2020
Continuation In Part 16947798 · Aug 17, 2020
Continuation In Part 16664679 · Oct 25, 2019
Continuation In Part 16228738 · Dec 20, 2018
Continuation In Part 15922856 · Mar 15, 2018
Continuation In Part 15888021 · Feb 3, 2018
Provisional Application 62507691 · May 17, 2017
Provisional Application 62520954 · Jun 16, 2017
Provisional Application 62527671 · Jun 30, 2017
Provisional Application 62530295 · Jul 10, 2017
Related Publication 20240330482A1 · Oct 3, 2024
References Cited (115)
US 4959015A · Rasinski · 1990 [cited by applicant]
US 6952779B1 · Cohen · 2005 [cited by applicant]
US 7096502B1 · Fox · 2006 [cited by applicant]
US 7260844B1 · Tidwell · 2007 [cited by applicant]
US 7433829B2 · Borgia · 2008 [cited by applicant]
US 7624448B2 · Coffman · 2009 [cited by applicant]
US 7761918B2 · Gula · 2010 [cited by applicant]
US 7891003B2 · Mir · 2011 [cited by applicant]
US 7900259B2 · Jeschke · 2011 [cited by applicant]
US 8099760B2 · Cohen · 2012 [cited by applicant]
US 8191139B2 · Heimerdinger · 2012 [cited by applicant]
US 8255995B2 · Kraemer · 2012 [cited by applicant]
US 8312549B2 · Goldberg · 2012 [cited by applicant]
US 8407801B2 · Ikegami · 2013 [cited by applicant]
US 8413237B2 · O'Rourke · 2013 [cited by applicant]
US 8413249B1 · Chou · 2013 [cited by applicant]
US 8726394B2 · Maor · 2014 [cited by applicant]
US 9043924B2 · Maor · 2015 [cited by applicant]
US 9141790B2 · Roundy · 2015 [cited by applicant]
US 9497203B2 · Honig · 2016 [cited by applicant]
US 9602529B2 · Jones et al. · 2017 [cited by applicant]
US 9680855B2 · Schultz · 2017 [cited by applicant]
US 9774613B2 · Thomas · 2017 [cited by applicant]
US 9910986B1 · Saxe et al. · 2018 [cited by applicant]
US 9948652B2 · Yu et al. · 2018 [cited by applicant]
US 10104109B2 · Singla et al. · 2018 [cited by applicant]
US 10200399B2 · Agarwal · 2019 [cited by applicant]
US 10216938B2 · Reith et al. · 2019 [cited by applicant]
US 10255439B2 · Agarwal · 2019 [cited by applicant]
US 10262132B2 · Reinecke · 2019 [cited by applicant]
US 10270798B2 · Zaffarano · 2019 [cited by applicant]
US 10318735B2 · Saxe · 2019 [cited by applicant]
US 10331973B2 · Wang · 2019 [cited by applicant]
US 10367827B2 · Seward · 2019 [cited by examiner]
US 10503907B2 · Zheng et al. · 2019 [cited by applicant]
US 10664603B2 · Agarwal · 2020 [cited by applicant]
US 10681068B1 · Galliano et al. · 2020 [cited by applicant]
US 10699008B2 · Agarwal · 2020 [cited by applicant]
US 10706144B1 · Moritz · 2020 [cited by examiner]
US 10713366B2 · Agarwal · 2020 [cited by applicant]
US 10747876B2 · Agarwal · 2020 [cited by applicant]
US 10757127B2 · Schultz et al. · 2020 [cited by applicant]
US 10878093B2 · Saxe · 2020 [cited by applicant]
US 10896256B1 · Saxe · 2021 [cited by applicant]
US 10938838B2 · Saxe · 2021 [cited by applicant]
US 10972485B2 · Ladnai · 2021 [cited by applicant]
US 10984112B2 · Agarwal · 2021 [cited by applicant]
US 11159559B2 · Agarwwal · 2021 [cited by applicant]
US 11200228B2 · Keenan et al. · 2021 [cited by applicant]
US 11303665B2 · Liu · 2022 [cited by examiner]
US 11314872B2 · Agarwwal · 2022 [cited by applicant]
US 11405419B2 · Chen · 2022 [cited by examiner]
US 11568059B2 · Agarwal · 2023 [cited by applicant]
US 11575700B2 · Sayag · 2023 [cited by examiner]
US 11841954B2 · Agarwwal · 2023 [cited by examiner]
US 11853427B2 · Saxe · 2023 [cited by examiner]
US 20010027388A1 · Beverina · 2001 [cited by applicant]
US 20060015941A1 · McKenna · 2006 [cited by applicant]
US 20060241991A1 · Pudhukottai · 2006 [cited by applicant]
US 20110126111A1 · Gill · 2011 [cited by applicant]
US 20110178942A1 · Watters · 2011 [cited by applicant]
US 20110277034A1 · Hanson · 2011 [cited by applicant]
US 20140137257A1 · Martinez · 2014 [cited by applicant]
US 20140157417A1 · Grubel · 2014 [cited by applicant]
US 20140236665A1 · Baker · 2014 [cited by applicant]
US 20150033346A1 · Hebert · 2015 [cited by applicant]
US 20160162690A1 · Reith · 2016 [cited by applicant]
US 20160248798A1 · Cabrera · 2016 [cited by applicant]
US 20170213037A1 · Toledano · 2017 [cited by applicant]
US 20180255084A1 · Kotinas · 2018 [cited by applicant]
US 20180324207A1 · Reybok, Jr. · 2018 [cited by applicant]
US 20200342116A1 · Agarwal · 2020 [cited by applicant]
Threat Risk Modeling, published online at least as early as Feb. 3, 2018 by OWASP, available at https://www.owasp.org/index.php/Threat_Risk_Modeling. [cited by applicant]
Threat Model, Wikipedia, published online at least as early as Feb. 3, 2018, available at https://en.wikipedia.org/wiki/Threat_model (note that some of the material in this Wikipedia article appears to be posted by one … [cited by applicant]
Comparisons of Threat Model Modeling Methodologies, published online by ThreatModeler at least as early as Apr. 15, 2016, available at http://threatmodeler.com/comparison-threat-modeling-methodologies/ (note that this a… [cited by applicant]
Microsoft Threat Modeling Tool, published online by Microsoft, different sections published at different times from Aug. 22, 2017 to Jan. 24, 2018, available online at https://docs.microsoft.com/en-US/azure/opbuildpdf/s… [cited by applicant]
A description of an on-sale version of systems and methods, on sale in the U.S. by applicants at least as early as Dec. 31, 2011, which on-sale version disclosed some of the elements disclosed in the present application… [cited by applicant]
Lockheed Martin Corporation, “Seven Ways to Apply the Cyber Kill Chain with a Threat Intelligence Platform,” published at least as early as 2015. [cited by applicant]
Roy, Maurer. “Top Database Security Threats and How to Mitigate Them.” Jul. 30, 2015. Retrieved from “https://www.shrm.org/resouresandtools/hr-topics/risk-management/pages/top-database-security-threats.aspx” (Year: 2015… [cited by applicant]
A. Amini, N. Jamil, A.R. Ahmad and M.R. Z'aba, 2015. Threat Modeling Approaches for Securing Cloud Computing. Journal of Applied Sciences, 15: 953-967. Retrieved from “https://scialert.net/fulltextmobile/?doi=jas.2015.9… [cited by applicant]
Lucid Charts AWS Import details, disclosing automatically generating a diagram for an existing computing network, the diagram groups components (and apparently allows refreshing to update the diagram based on changes in… [cited by applicant]
Office Action issued in U.S. Appl. No. 16/664,679 mailed Dec. 26, 2019. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 16/664,679 mailed Apr. 8, 2020. [cited by applicant]
Office Action issued in U.S. Appl. No. 16/228,738 mailed Aug. 8, 2019. [cited by applicant]
Office Action issued in U.S. Appl. No. 16/228,738 mailed Nov. 20, 2019. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 16/228,738 mailed Feb. 24, 2020. [cited by applicant]
Office Action issued in U.S. Appl. No. 15/922,856 mailed Jun. 21, 2018. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 15/922,856 mailed Nov. 6, 2018. [cited by applicant]
Office Action issued in U.S. Appl. No. 15/888,021 mailed May 14, 2018. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 15/888,021 mailed Nov. 20, 2018. [cited by applicant]
Office Action issued in U.S. Appl. No. 16/542,263 mailed Nov. 18, 2019. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 16/542,263 mailed Mar. 5, 2020. [cited by applicant]
Office Action issued in U.S. Appl. No. 16/270,276 mailed Oct. 18, 2019. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 16/270,276 mailed Jan. 27, 2020. [cited by applicant]
Bruce Potter. “Microsoft SDL Threat Modeling Tool”. Network Security. vol. 2009, Issue 1, pp. 15-18. (Elsevier 2009) (Year: 2009). [cited by applicant]
Office Action issued in U.S. Appl. No. 16/950,509 mailed Apr. 21, 2021. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 16/950,509 mailed Jun. 21, 2021. [cited by applicant]
Office Action issued in U.S. Appl. No. 17/479,815 mailed Dec. 29, 2021. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 17/479,815 mailed Feb. 25, 2022. [cited by applicant]
Office Action issued in U.S. Appl. No. 17/709,670 mailed Dec. 7, 2022. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 17/709,670 mailed Jul. 31, 2023. [cited by applicant]
Uceda Velez et al. “Risk Centric Threat Modeling Process for Attack Simulation and Threat Analysis”, 2015, pp. 1-76, John Wiley & Sons, Inc. [cited by applicant]
Shostack “Threat Modeling Designing for Security”, 2014, excerpts, John Wiley & Sons, Inc. [cited by applicant]
Swiderski “Threat Modeling”, Microsoft Professional, 2004, excerpts, Microsoft Press. [cited by applicant]
Howard, et al. “The Security Development Lifecycle” 2006, pp. 101-132, Microsoft Press. [cited by applicant]
Kent, “Risk=Likelihood×Impact” CIO Article, 2016, pp. 1-4. [cited by applicant]
Souppaya, “Guide to Data-Centric System Threat Modeling,” NIST Special Publication 800-154, 2016, pp. 1-25. [cited by applicant]
Freund et al. “Measuring and Managing Information Risk: A Fair Approach”, 2015, excerpts. [cited by applicant]
National Institute of Standards and Technology “Guide for Conducting Risk Assessments” NIST Special Publication 800-30, Revision 1, 2012, pp. 1-95. [cited by applicant]
Committee on National Security Systems. “Committee on National Security Systems (CNSS) Glossary”, CNSSI No. 4009, 2015, pp. 1-165. [cited by applicant]
Lee. “Integrating Electricity Subsector Failure Scenarios into a Risk Assessment Methodology”, Electric Power Research Institute, 2013, pp. 1-54. [cited by applicant]
Petition as Filed for Inter Partes Review of U.S. Pat. No. 10,713,366, IPR2023-00656, 2023, pp. 1-107. [cited by applicant]
Final Written Decision in the Inter Partes Review of U.S. Pat. No. 10,713,366, IPR2023-00656, 2023, pp. 1-57. [cited by applicant]
Petition as Filed for Inter Partes Review of U.S. Pat. No. 10,699,008, IPR2023-00821, 2023, pp. 1-75. [cited by applicant]
Final Written Decision in the Inter Partes Review of U.S. Pat. No. 10,699,008, IPR2023-00821, 2023, pp. 1-78. [cited by applicant]
Cited By (1)
US 12,481,767