Application Security Testing System Using Exposure Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security testing methods are manually intensive and resource-constrained, requiring individual assessments of every application, which is impractical due to finite resources and limited scope, making it difficult to implement effective security testing across all applications in a business environment.

Innovation Solution

A system that assesses applications using assessment parameters and indicators to calculate a total exposure score, determining which applications qualify for security testing based on this score, and prioritizing testing on applications with higher exposure scores, thereby focusing efforts on the most vulnerable applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security testing is conducted on every application, then comprehensive security assessment is achieved, but resource consumption and time requirements become unmanageable

Engineering Contradiction:
Improvesecurity assessment comprehensivenessVSAvoidtesting efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments applications into different risk categories based on exposure scores derived from multiple assessment parameters (data sensitivity, user access, internet exposure, etc.). This segmentation allows the system to focus comprehensive security testing on high-risk applications while applying simplified assessment to lower-risk applications, thereby maintaining security comprehensiveness while improving testing efficiency and resource allocation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security testing resources are allocated to all applications equally, then uniform security coverage is achieved, but resources are wasted on low-risk applications

Engineering Contradiction:
Improvesecurity coverage uniformityVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements local quality by applying different assessment depths and testing intensities to different applications based on their specific risk profiles. High-risk applications receive comprehensive multi-parameter assessment and extensive security testing, while low-risk applications receive streamlined assessment. This localized approach ensures adequate security coverage for all applications while optimizing resource utilization by concentrating efforts where they are most needed.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If detailed assessment parameters are evaluated for each application, then accurate risk scoring is achieved, but assessment complexity increases

Engineering Contradiction:
Improverisk scoring accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by automatically collecting baseline assessment data (application inventory, data classification, access permissions, internet exposure) before conducting security testing. This preliminary assessment establishes exposure scores that guide subsequent testing efforts, allowing the system to maintain high measurement precision through multiple assessment parameters while reducing overall complexity by preparing information in advance rather than gathering it during the testing process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9392012B2Application security testing system
Publication Date: 2016.07.12 BANK OF AMERICA CORP
  • US9392012B2 patent drawing
  • US9392012B2 patent drawing
  • US9392012B2 patent drawing

AI summary

Embodiments of the invention are directed to an apparatus, method, and computer program product for an exposure based application security testing system. In some embodiments, the apparatus is configured to: access an application, wherein the application comprises an assessment parameter, wherein the assessment parameter comprises one or more assessment sub-parameters, wherein the one or more assessment sub-parameters comprise one or more assessment indicators; process the application, wherein processing the application comprises calculating a total exposure score for the application based on at least an application exposure score and a protective control score; determine whether the application qualifies for security testing based on at least the calculated total exposure score; and initiating the presentation of the qualified application to the user to implement security testing.