Dynamic Software Security Assessment via Directed Attack Vectors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise software systems lack adequate security assessment structures to effectively identify and mitigate vulnerabilities, particularly in web-based applications, making them susceptible to cyberattacks and data breaches, despite the use of antivirus software and firewalls.
Innovation Solution
A cloud-based system that dynamically assesses security vulnerabilities by subjecting software applications to directed attack vectors during execution, generating a dynamic security vulnerability score to identify and prioritize risks, and providing insights for improvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If antivirus software and firewalls are deployed to protect enterprise systems, then preventative security measures are improved, but security vulnerabilities may still remain undetected and unassessed
Solution Approach 1:
The system implements feedback by continuously monitoring software applications during execution and dynamically assessing security vulnerabilities. The assessment results feed back into the system to update security scores and prioritize remediation efforts, creating a closed-loop security assessment process that improves both preventative measures and vulnerability detection precision.
Solution Approach 2:
The system enables self-service security assessment by automatically directing attack vectors against software applications and evaluating their responses without requiring manual security testing. The software applications themselves provide the testing environment through their normal execution, allowing the system to assess vulnerabilities while the applications are being used.
2Measurement precision
If dynamic security assessment is implemented by directing attack vectors during execution, then vulnerability identification is improved, but system complexity and testing overhead increase
Solution Approach 1:
The system achieves universality by designing an assessment mechanism that can evaluate multiple types of security vulnerabilities across different software applications using a unified approach. The same infrastructure directs various attack vectors and assesses different security aspects, reducing the need for separate specialized testing systems for each vulnerability type.
Solution Approach 2:
The system introduces an intermediary assessment layer that sits between the attack vectors and the software applications. This intermediary component manages the complexity of directing multiple attack vectors, coordinates the testing process, and aggregates results, thereby isolating the complexity from both the attack vector generation and the application execution.
3Measurement precision
If comprehensive security testing is performed on software applications, then security vulnerability detection is improved, but testing time and execution overhead increase
Solution Approach 1:
The system maintains continuity of useful action by performing security assessments during the normal execution of software applications rather than requiring separate dedicated testing periods. The attack vectors are directed and vulnerabilities are assessed continuously as the applications run, allowing security testing to occur alongside productive work without significant interruption.
Solution Approach 2:
The system applies partial action by directing a focused set of attack vectors targeting specific security concerns rather than attempting exhaustive testing of all possible vulnerability types. This selective approach identifies the most critical vulnerabilities while minimizing testing time and overhead.
Data Source
AI summary
A method and system of applying a security vulnerability assessment of a software program. The method comprises directing, from a security assessing server, to a software program under execution, a plurality of attack vectors, diagnosing a set of results associated with the software program under execution as comprising a security vulnerability, the set of results produced based at least in part on the plurality of attack vectors, and assessing a monetary premium of a risk insurance policy merited by an enterprise based at least in part on a level of control ceded to an attacker in accordance with the set of results.


