Application Security Assessment via Entry Point Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security assessment methods for enterprise applications are resource-intensive and fail to accurately estimate security coverage, as they do not account for varying levels of security threats across different entry points of applications.
Innovation Solution
A method and device for evaluating security assessment by receiving application entry data, identifying security threat entry points, computing a coverage index value, and generating a recommendation report to indicate security coverage, which helps in identifying areas that need security attention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive security assessment methods (SAST/DAST) are used to ensure thorough security coverage, then security reliability is improved, but time consumption and resource requirements increase significantly
Solution Approach 1:
The patent segments the application entry points into different categories (UI entry points, web interface entry points, database entry points, etc.) and applies different security assessment strategies to each category. This allows the system to focus resources on high-risk entry points while reducing assessment time for lower-risk areas, resolving the contradiction between comprehensive security coverage and time consumption.
2Reliability
If uniform security standards are applied to all applications, then security consistency is improved, but adaptability to different application types and risk levels deteriorates
Solution Approach 1:
The patent implements local quality by assigning different security assessment weights and criteria to different entry point categories based on their specific risk profiles. For example, database entry points may receive higher security weights than UI entry points. This allows the system to maintain overall security consistency while adapting to the specific characteristics and risk levels of different application areas.
Data Source
AI summary
Embodiments of the present disclosure disclose a method and a device for evaluating security assessment of an application. The method comprises receiving application entry data associated with a plurality of entry points of the application. Also, the method comprises identifying at least one security threat entry point based on the application entry data. Further, the method comprises computing a coverage index value based on the application entry data and the at least one security threat entry point and generating a recommendation report indicating security coverage of the application based on the coverage index value.


