IP Library › Granted Patent US 12,639,431
Granted Patent B2
US 12,639,431 · App. 18/759,286 · Granted May 26, 2026

Automated threat model generation

Inventor: Robert J. Mooney, III (Mercer Island, WA)
G06F21/563G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,431
App. No.
18/759,286
Granted
May 26, 2026
Kind
B2
Abstract

Embodiments of the present invention include computer-implemented methods, systems, and computer program products where program code executing on a processor(s) obtains an artifact of a given computing system. The program code determines a type for the artifact. The program code designates a given analysis tool from a plurality of analysis tools, to process the artifact. The program code processes the artifact by utilizing the given analysis tool, to determine facts of the artifact. The program code determines which facts of the one or more facts comprise elements of a threat model. The program code stores the elements of the threat model and the facts. The program code generates a threat model for the given computing system, based on consolidating the elements of the threat model for the artifact with additional elements of the threat models of additional artifacts.

Claims (50)

1 . A system for automated threat modeling, comprising:

a memory; and

one or more processors in communication with the memory, wherein the computer system is configured to perform a method, said method comprising:

ingesting, by the one or more processors, one or more compiled binary artifacts from a computing system, wherein the binary artifacts are selected from the group consisting of: executable files, shared object libraries, container images, firmware, compiled microservices, and other artifacts;

performing, by the one or more processors, at least one analysis on the binary artifacts, wherein the at least one analysis comprises at least one of:

performing, by the one or more processors, a static analysis on the binary artifacts to extract values; and

executing, by the one or more processors, the binary artifacts to perform a dynamic analysis to capture interactions;

generating, by the one or more processors, a dependency graph based on results of the at least one analysis static analysis, wherein the dependency graph represents internal and external component interactions;

utilizing, by the one or more processors, the dependency graph to automatically identify and label trust boundaries and potential threat surfaces; and

based on identifying the trust boundaries and potential threat surfaces, deriving, by the one or more processors, a structured threat model comprising a representation of a threat landscape of the computing system.

2 . The system of claim 1 , wherein the values are selected from the group consisting of: functions, symbols, imported libraries, and internal dependencies.

3 . The system of claim 1 , wherein the interactions are selected from the group consisting of: runtime interactions, system calls, network connections, and data flows.

4 . The system of claim 1 , wherein the at least one analysis comprises executing the binary artifacts and executing the binary artifacts comprises executing the binary artifacts within an instrumented runtime environment.

5 . The system of claim 1 , wherein the at least one analysis comprises and wherein the dynamic analysis comprises:

observing, by the one or more processors, computing elements or interactions selected from the group consisting of: runtime network connections, inter-process communications, and access to sensitive system resources.

6 . The system of claim 1 , wherein the structured threat model output comprises a data flow diagram (DFD), and wherein the DFD indicates data ingress, egress, and storage points.

7 . The system of claim 1 , wherein automatically identifying the trust boundaries comprises:

analyzing, by the one or more processors, the dependency graph to identify a presence of an event from a group of pre-defined events.

8 . The system of claim 7 , wherein the group of predefined events comprise: a change in privilege level, a change in authentication context, a crossing of a network or process isolation, and a crossing of another boundary.

9 . A computer-implemented method for automating threat modeling of a computing systems, comprising:

ingesting, by one or more processors, one or more compiled binary artifacts from the computing system, wherein the binary artifacts are selected from the group consisting of: executable files, shared object libraries, container images, firmware, compiled microservices, and other artifacts;

performing, by the one or more processors, at least one analysis on the binary artifacts, wherein the at least one analysis comprises at least one of:

performing, by the one or more processors, a static analysis on the binary artifacts to extract values; and

executing, by the one or more processors, the binary artifacts to perform a dynamic analysis to capture interactions;

generating, by the one or more processors, a dependency graph based on results of the at least one analysis, wherein the dependency graph represents internal and external component interactions;

utilizing, by the one or more processors, the dependency graph to automatically identify and label trust boundaries and potential threat surfaces; and

based on identifying the trust boundaries and potential threat surfaces, deriving, by the one or more processors, a structured threat model comprising a representation of a threat landscape of the computing system.

10 . The method of claim 9 , wherein the structured threat model comprises trust boundaries, sensitive operations, and attack surfaces.

11 . The method of claim 9 , further comprising:

visualizing, by the one or more processors, the structured threat model in an interface of the computing system.

12 . The method of claim 9 , further comprising:

automatically analyzing, by the one or more processors, the structured threat model; and

based on the automatically analyzing, implementing, by the one or more processors, a configuration change in the computing system.

13 . The method of claim 9 , wherein deriving the structured threat model comprises:

automatically classifying, by the one or more processors, the interactions according to standard security framework.

14 . The method of claim 10 , wherein sensitive operations are selected from the group consisting of: cryptographic functions, authentication checks, authorization checks, and access control logic.

15 . The method of claim 9 , further comprising:

annotating, by the one or more processors, a portion of the binary artifacts and a portion of the structured threat model with metadata indicating security-relevant findings.

16 . A computer program product for automating threat model generation, the computer program product comprising:

one or more computer readable storage media and program instructions collectively stored on the one or more computer readable storage media readable by at least one processing circuit to:

ingest one or more compiled binary artifacts from a computing system wherein the binary artifacts are selected from the group consisting of: executable files, shared object libraries, container images, firmware, compiled microservices, and other artifacts;

perform at least one analysis on the binary artifacts, wherein the at least one analysis comprises at least one of:

perform a static analysis on the binary artifacts to extract values; and

execute the binary artifacts to perform a dynamic analysis to capture interactions;

generate a dependency graph based on results of the at least one analysis, wherein the dependency graph represents internal and external component interactions;

utilize the dependency graph to automatically identify and label trust boundaries and potential threat surfaces; and

based on identifying the trust boundaries and potential threat surfaces, derive a threat model comprising a representation of a threat landscape of the computing system.

17 . The computer program product of claim 16 , wherein the threat model is of a characteristic selected from the group consisting of: structured, visual, human readable, and machine-readable.

18 . The computer program product of claim 16 , wherein the threat model further represents a security posture of the computing system.

19 . The computer program product of claim 16 , wherein the interactions comprise runtime behaviors, and wherein the program instructions are further readable to: identify the runtime behaviors through instrumentation techniques, wherein the instrumentation techniques are selected from the group consisting of: tracing and memory introspection.

Continuity (3)
Continuation 17566609 · Dec 30, 2021
Provisional Application 63132317 · Dec 30, 2020
Related Publication 20240354408A1 · Oct 24, 2024
References Cited (5)
US 7891003B2 · Mir · 2011 [cited by examiner]
US 8887286B2 · Dupont · 2014 [cited by examiner]
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 11323464B2 · Jakobsson · 2022 [cited by examiner]
US 20170103674A1 · Sadeh-Koniecpol · 2017 [cited by examiner]