Application Security Server Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and size of service provider networks, coupled with the large number of applications executing within them, complicate efforts to maintain security, as existing security technologies have not proven entirely satisfactory in effectively assessing and managing security risks across these environments.

Innovation Solution

An application security system that includes an application security server capable of calculating a security risk score for each application based on various factors, such as instance count, interdependencies, and sensitivity, and dynamically adjusts testing regimes to prioritize and categorize applications for appropriate security testing, including automated and manual testing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security technologies are used to assess security risks in service provider networks, then basic security monitoring is provided, but the assessment effectiveness and ability to manage security risks across complex environments is insufficient

Engineering Contradiction:
Improvesecurity risk assessment effectivenessVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex network security assessment task into multiple independent components: vulnerability scanners assess individual applications, dependency mappers analyze specific relationship types, risk calculators evaluate discrete risk factors, and the central server aggregates results. This segmentation allows each component to specialize in specific aspects of security assessment, improving overall effectiveness while managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The central server acts as an intermediary that coordinates between various security assessment tools, applications, and users. It receives vulnerability data from scanners, processes dependency information from mappers, calculates risk scores, and presents unified security assessments to users. This intermediary approach enables effective security risk management across complex environments by centralizing coordination while distributing assessment functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security testing is performed on all applications in the network, then thorough security assessment is achieved, but the time and resources required become prohibitively large

Engineering Contradiction:
Improvesecurity assessment thoroughnessVSAvoidtesting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies different levels of security testing intensity to different applications based on their specific risk profiles. High-risk applications with critical vulnerabilities and extensive dependencies receive comprehensive testing, while low-risk applications receive streamlined assessment. This local quality approach ensures thorough security assessment is focused where most needed, reducing overall testing time while maintaining reliability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The risk calculation dynamically adjusts testing parameters based on vulnerability severity, dependency complexity, and application criticality. The system changes test depth, scan frequency, and resource allocation according to calculated risk scores, enabling thorough assessment of high-risk applications while minimizing testing time for lower-risk applications. This parameter adaptation resolves the contradiction between comprehensiveness and time consumption.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If security testing resources are distributed evenly across all applications, then consistent coverage is provided, but high-risk applications do not receive sufficient prioritized attention

Engineering Contradiction:
Improveresource distribution simplicityVSAvoidsecurity priority management
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts security resource allocation based on real-time risk calculations. As vulnerabilities, dependencies, and threat landscapes change, the risk scores are recalculated and resource distribution automatically adjusts to prioritize high-risk applications. This dynamic approach replaces static even distribution with adaptive allocation that maintains operational simplicity while improving security priority management through automated risk-based adjustments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10262145B2Systems and methods for security and risk assessment and testing of applications
Publication Date: 2019.04.16 NETFLIX INC
  • US10262145B2 patent drawing
  • US10262145B2 patent drawing
  • US10262145B2 patent drawing

AI summary

Provided herein are systems and methods for monitoring and assessing the security and risk presented by applications deployed in a complex computing environment. An exemplary application security system an application security server having a processing device in communication with one or more storage systems and includes a security testing system with a plurality of security test modules. The test modules include a first module associated with a first application associated with one or more application instances configured to receive and transmit over a network. The processing device calculates a security risk score for the first application based on information about the first application, determines a security priority level associated with first application, the security priority level of the first application being based on the security risk score for the first application, and associates the security priority level of the first application with the first application in a database of application security information.