Automated Security Testing for Hardware Software Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The architecture of hardware and software systems ensures functional safety but often fails to guarantee informational security, requiring additional measures that may not consider the interests of authorized users or functional safety requirements.

Innovation Solution

Automated testing systems use a threat model compared to a usage model to detect vulnerabilities in hardware and software systems, identifying components vulnerable to unauthorized use, threat realization methods, and attack vectors, while ensuring the interests of authorized users and functional safety are met.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional security means are added to ensure informational security, then security is improved, but system complexity and potential conflict with functional safety requirements worsen

Engineering Contradiction:
Improveinformational securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing automated security testing during the design phase before the system is deployed. The testing system compares the architecture description against a database of known vulnerabilities and security requirements, identifying and addressing security issues before they can affect operational systems. This prevents the need for complex retroactive security additions that would conflict with functional safety.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The testing system enables the design process to self-diagnose security vulnerabilities by automatically comparing the architecture description against security databases and generating reports of non-compliant elements. This self-service approach allows developers to identify and fix security issues independently without requiring external security experts, reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If automated testing is performed to detect vulnerabilities, then security detection capability is improved, but testing time and computational resources worsen

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidtesting time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary security testing during the design phase using automated comparison of architecture descriptions against vulnerability databases. This early detection approach identifies security issues before deployment, eliminating the need for time-consuming post-deployment penetration testing and vulnerability assessments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual security auditing and vulnerability assessment processes with automated computational testing. The system uses algorithms to automatically compare architecture descriptions against security databases, substituting human analysts with machine-based automated testing that is both faster and more consistent.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If security testing is integrated into the design process, then security compliance is improved, but design process complexity worsens

Engineering Contradiction:
Improvesecurity complianceVSAvoiddesign process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security testing functions directly into the existing design process workflow. The automated testing system integrates with architecture description generation, allowing security compliance checking to occur as part of the normal design activities rather than as a separate parallel process. This unified approach improves security compliance without significantly increasing design process complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The testing system is designed to be universal, handling multiple security standards, vulnerability types, and architecture description formats through a single integrated platform. This multi-functional capability allows the system to address various security compliance requirements without requiring separate specialized tools for each standard, thereby avoiding additional design process complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11030319B2Method for automated testing of hardware and software systems
Publication Date: 2021.06.08 AO KASPERSKY LAB
  • US11030319B2 patent drawing
  • US11030319B2 patent drawing
  • US11030319B2 patent drawing

AI summary

Disclosed herein are methods and systems for automated testing of hardware and software systems. An exemplary method comprises receiving a formalized architecture description describing an architecture of a system being designed, receiving a formalized threat description describing threats to systems similar to the system being designed, building, by a processor, a use model based on the formalized description, building, by a processor, a threat model based on the formalized threat description, determining, by a processor, kinds of use of the system by comparing the threat model to the use model and determining, by a processor, components of the system based on the kinds of use.