首页> 外国专利> Automated threat modeling using machine-readable threat models

Automated threat modeling using machine-readable threat models

机译:使用机器可读威胁模型进行自动威胁建模

摘要

This disclosure describes techniques for automating a system-level security review of a network-based service. The techniques may include generating and utilizing a machine-readable threat model to identify system-level security threats to the network-based service. The network-based service may be scanned upon being provisioned in a service-provider network, and the machine-readable threat model may be generated based on results of the scan. The machine-readable threat model may represent components of the network-based service, system-level security constraints configured to identify system-level security threats to the service, and mitigations to remedy violations to the system-level security constraints. The network-based service may be continuously, or periodically, scanned to identify changes in the network-based service. The techniques further include updating the machine-readable threat model to account for the detected changes to the network-based service, and analyzing the updated machine-readable threat model to determine whether the changes to the network-based service violate a system-level security constraint.
机译:本公开描述了用于使基于网络的服务的系统级安全性检查自动化的技术。该技术可以包括生成和利用机器可读威胁模型来识别对基于网络的服务的系统级安全威胁。基于网络的服务可以在被提供给服务提供商网络时被扫描,并且可以基于扫描结果来生成机器可读威胁模型。机器可读威胁模型可以表示基于网络的服务的组件,被配置为标识对该服务的系统级安全威胁的系统级安全性约束以及缓解对系统级安全性约束的违反的缓解措施。基于网络的服务可以被连续地或周期性地扫描以识别基于网络的服务中的改变。所述技术还包括:更新机器可读威胁模型以解决对基于网络的服务的检测到的改变;以及分析更新后的机器可读威胁模型,以确定对基于网络的服务的改变是否违反了系统级安全性。约束。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号