AI Code Vulnerability Assessment With Entity-Specific Severity Ratings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack the capability to identify security vulnerabilities in software code developed, used, and managed by entities, necessitating a system that can effectively detect and address these vulnerabilities.

Innovation Solution

A system utilizing a vulnerability identification system equipped with a generative artificial intelligence engine that extracts internal and external standards, calculates modified severity ratings, performs assessments, and takes remediation actions to identify and mitigate software code vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional vulnerability scanning methods are used, then the system can detect known vulnerabilities, but it cannot identify entity-specific vulnerabilities or adapt to custom coding standards

Engineering Contradiction:
Improveadaptability to entity-specific standardsVSAvoidvulnerability detection accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system segments vulnerability assessment into multiple independent components: extracting internal entity standards, extracting external coding standards, calculating base severity ratings, and generating entity-specific modified severity ratings. This segmentation allows each component to be optimized independently while working together to achieve both adaptability and precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameters of vulnerability assessment by introducing entity-specific modifications to severity ratings. Instead of using fixed external severity ratings, the system calculates modified severity ratings that incorporate internal entity standards, custom weighting factors, and organization-specific risk tolerances, thereby adapting the assessment to entity-specific contexts while maintaining detection accuracy.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive code assessment is performed using multiple standards and custom severity ratings, then vulnerability detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system achieves universality by creating a multi-functional platform that can simultaneously extract multiple types of standards (internal and external), process various coding languages and frameworks, calculate different types of severity ratings, and generate comprehensive vulnerability assessments. This universal approach consolidates multiple functions into a single system, improving detection accuracy without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces intermediary components that mediate between raw code data and final vulnerability assessments. These intermediaries include standard extraction modules, severity rating calculation engines, and modification layers that transform external severity ratings into entity-specific modified severity ratings. These intermediaries simplify the overall system architecture by breaking down complex processing into manageable stages.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If manual review of all vulnerability outputs is performed, then false positives can be identified, but productivity and assessment speed decrease

Engineering Contradiction:
Improvereduction of false positivesVSAvoidassessment speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements self-service capabilities through automated false positive identification mechanisms. The system automatically analyzes vulnerability outputs, cross-references them against extracted internal standards and external standards, and identifies patterns indicative of false positives. This self-service approach reduces reliance on manual review while maintaining high precision in vulnerability detection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where vulnerability assessment results are continuously analyzed and used to refine future assessments. When false positives are identified (either automatically or through limited manual review), the system learns from these cases and adjusts its detection algorithms, severity rating calculations, and standard extraction processes to reduce future false positives, thereby maintaining productivity while improving precision over time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260044608A1System and method for identifying security vulnerabilities in software code
Publication Date: 2026.02.12 BANK OF AMERICA CORP
  • US20260044608A1 patent drawing
  • US20260044608A1 patent drawing
  • US20260044608A1 patent drawing

AI summary

Embodiments of the present invention provide a system for identifying security vulnerabilities in software code. The system is configured for extracting, from an entity system, internal standards associated with software code of entity applications associated with an entity, extracting external standards associated with the software code of the entity applications from external systems, extracting severity ratings associated with known vulnerabilities, calculating modified severity ratings associated with the known vulnerabilities that are specific to the entity, performing assessment of the software code associated with the entity applications, via an artificial intelligence engine, to generate an output associated with the assessment of the software code based at least on the internal standards, the external standards, and the modified severity ratings, and performing one or more actions based on the generated output associated with the assessment of the software code.