Automated threat model generation
View Patent ↗Embodiments of the present invention include computer-implemented methods, systems, and computer program products where program code executing on a processor(s) obtains an artifact of a given computing system. The program code determines a type for the artifact. The program code designates a given analysis tool from a plurality of analysis tools, to process the artifact. The program code processes the artifact by utilizing the given analysis tool, to determine facts of the artifact. The program code determines which facts of the one or more facts comprise elements of a threat model. The program code stores the elements of the threat model and the facts. The program code generates a threat model for the given computing system, based on consolidating the elements of the threat model for the artifact with additional elements of the threat models of additional artifacts.
1 . A system for automated threat modeling, comprising:
a memory; and
one or more processors in communication with the memory, wherein the computer system is configured to perform a method, said method comprising:
ingesting, by the one or more processors, one or more compiled binary artifacts from a computing system, wherein the binary artifacts are selected from the group consisting of: executable files, shared object libraries, container images, firmware, compiled microservices, and other artifacts;
performing, by the one or more processors, at least one analysis on the binary artifacts, wherein the at least one analysis comprises at least one of:
performing, by the one or more processors, a static analysis on the binary artifacts to extract values; and
executing, by the one or more processors, the binary artifacts to perform a dynamic analysis to capture interactions;
generating, by the one or more processors, a dependency graph based on results of the at least one analysis static analysis, wherein the dependency graph represents internal and external component interactions;
utilizing, by the one or more processors, the dependency graph to automatically identify and label trust boundaries and potential threat surfaces; and
based on identifying the trust boundaries and potential threat surfaces, deriving, by the one or more processors, a structured threat model comprising a representation of a threat landscape of the computing system.
2 . The system of claim 1 , wherein the values are selected from the group consisting of: functions, symbols, imported libraries, and internal dependencies.
3 . The system of claim 1 , wherein the interactions are selected from the group consisting of: runtime interactions, system calls, network connections, and data flows.
4 . The system of claim 1 , wherein the at least one analysis comprises executing the binary artifacts and executing the binary artifacts comprises executing the binary artifacts within an instrumented runtime environment.
5 . The system of claim 1 , wherein the at least one analysis comprises and wherein the dynamic analysis comprises:
observing, by the one or more processors, computing elements or interactions selected from the group consisting of: runtime network connections, inter-process communications, and access to sensitive system resources.
6 . The system of claim 1 , wherein the structured threat model output comprises a data flow diagram (DFD), and wherein the DFD indicates data ingress, egress, and storage points.
7 . The system of claim 1 , wherein automatically identifying the trust boundaries comprises:
analyzing, by the one or more processors, the dependency graph to identify a presence of an event from a group of pre-defined events.
8 . The system of claim 7 , wherein the group of predefined events comprise: a change in privilege level, a change in authentication context, a crossing of a network or process isolation, and a crossing of another boundary.
9 . A computer-implemented method for automating threat modeling of a computing systems, comprising:
ingesting, by one or more processors, one or more compiled binary artifacts from the computing system, wherein the binary artifacts are selected from the group consisting of: executable files, shared object libraries, container images, firmware, compiled microservices, and other artifacts;
performing, by the one or more processors, at least one analysis on the binary artifacts, wherein the at least one analysis comprises at least one of:
performing, by the one or more processors, a static analysis on the binary artifacts to extract values; and
executing, by the one or more processors, the binary artifacts to perform a dynamic analysis to capture interactions;
generating, by the one or more processors, a dependency graph based on results of the at least one analysis, wherein the dependency graph represents internal and external component interactions;
utilizing, by the one or more processors, the dependency graph to automatically identify and label trust boundaries and potential threat surfaces; and
based on identifying the trust boundaries and potential threat surfaces, deriving, by the one or more processors, a structured threat model comprising a representation of a threat landscape of the computing system.
10 . The method of claim 9 , wherein the structured threat model comprises trust boundaries, sensitive operations, and attack surfaces.
11 . The method of claim 9 , further comprising:
visualizing, by the one or more processors, the structured threat model in an interface of the computing system.
12 . The method of claim 9 , further comprising:
automatically analyzing, by the one or more processors, the structured threat model; and
based on the automatically analyzing, implementing, by the one or more processors, a configuration change in the computing system.
13 . The method of claim 9 , wherein deriving the structured threat model comprises:
automatically classifying, by the one or more processors, the interactions according to standard security framework.
14 . The method of claim 10 , wherein sensitive operations are selected from the group consisting of: cryptographic functions, authentication checks, authorization checks, and access control logic.
15 . The method of claim 9 , further comprising:
annotating, by the one or more processors, a portion of the binary artifacts and a portion of the structured threat model with metadata indicating security-relevant findings.
16 . A computer program product for automating threat model generation, the computer program product comprising:
one or more computer readable storage media and program instructions collectively stored on the one or more computer readable storage media readable by at least one processing circuit to:
ingest one or more compiled binary artifacts from a computing system wherein the binary artifacts are selected from the group consisting of: executable files, shared object libraries, container images, firmware, compiled microservices, and other artifacts;
perform at least one analysis on the binary artifacts, wherein the at least one analysis comprises at least one of:
perform a static analysis on the binary artifacts to extract values; and
execute the binary artifacts to perform a dynamic analysis to capture interactions;
generate a dependency graph based on results of the at least one analysis, wherein the dependency graph represents internal and external component interactions;
utilize the dependency graph to automatically identify and label trust boundaries and potential threat surfaces; and
based on identifying the trust boundaries and potential threat surfaces, derive a threat model comprising a representation of a threat landscape of the computing system.
17 . The computer program product of claim 16 , wherein the threat model is of a characteristic selected from the group consisting of: structured, visual, human readable, and machine-readable.
18 . The computer program product of claim 16 , wherein the threat model further represents a security posture of the computing system.
19 . The computer program product of claim 16 , wherein the interactions comprise runtime behaviors, and wherein the program instructions are further readable to: identify the runtime behaviors through instrumentation techniques, wherein the instrumentation techniques are selected from the group consisting of: tracing and memory introspection.