Automated Cloud Package Risk Scoring for Deployment Speed

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current manual review processes for software packages in cloud-based enterprise environments are time-consuming and delay the availability of newly developed software, as they require extensive manual verification for security standards, leading to inefficiencies in dissemination and resource allocation.

Innovation Solution

A cloud computer system implements a package risk assessment module that analyzes package metadata, developer metadata, and code vulnerability to calculate an overall risk score, enabling automated approval or queuing of software packages, thereby reducing the need for manual review and accelerating deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review processes are used for security assessment, then security standards are verified, but approval time increases and productivity decreases

Engineering Contradiction:
Improvesecurity standards verificationVSAvoidsoftware package approval speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs self-assessment of software packages by automatically analyzing package metadata, developer metadata, and code vulnerability information to generate risk scores, eliminating the need for extensive manual review while maintaining security standards

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual review processes are replaced with automated computational analysis that evaluates security risks through algorithmic assessment of package and developer metadata, substituting human manual verification with machine-based security evaluation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If extensive manual verification is performed, then security risk is reduced, but time consumption and resource allocation efficiency worsen

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary automated analysis of package metadata, developer history, and code vulnerability information before manual review, pre-filtering packages to identify only those requiring human verification and reducing overall verification time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated risk assessment system independently evaluates security risks without requiring extensive manual verification, performing self-service security assessment that reduces both time consumption and resource allocation while maintaining risk reduction effectiveness

Inventive Principle:
Principle #25Self-service

3Productivity

If automated risk assessment is implemented, then productivity increases, but measurement precision of security risk may decrease

Engineering Contradiction:
Improveapproval process speedVSAvoidsecurity risk assessment accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The risk assessment is divided into multiple independent analysis components evaluating different aspects such as package metadata, developer metadata, and code vulnerability information, with each component contributing to the overall risk score through weighted aggregation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system incorporates feedback mechanisms where risk assessment results are continuously refined based on historical data, developer responses, and outcome analysis, improving measurement precision over time while maintaining high productivity

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11204983B2Scoring cloud packages for risk assessment automation
Publication Date: 2021.12.21 SALESFORCE INC
  • US11204983B2 patent drawing
  • US11204983B2 patent drawing
  • US11204983B2 patent drawing

AI summary

Techniques are disclosed for determining whether to permit distribution of a software package—for example, via an application exchange service of a cloud computer system. The computer system may calculate a risk score for the software package based on various factors, including package metadata that specifies one of a plurality of package types supported by the application exchange service. The specified package type may be indicative of an amount of developer control on the software package after distribution. Based on comparing the calculated risk score to a risk threshold, the computer system may determine whether to permit distribution of the software package via the application exchange service. Scoring software packages based on package metadata may reduce the number of packages requiring manual review, which may advantageously reduce an amount of time between package development and deployment.