Dynamic Linked Security Test Sequences for Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security testing methods fail to effectively simulate human-driven attempts to breach applications, as they are typically run individually and lack the ability to accurately represent real-world unauthorized access scenarios, leading to resource inefficiencies and sub-optimal effectiveness.

Innovation Solution

A system and method for dynamically generating linked security tests using machine learning models to create and maintain databases of security test sequences, where tests are iteratively performed and results are used to generate supplementary sequences based on failure probabilities, conserving resources and improving testing effectiveness without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security tests are run individually as per current methods, then the testing process is simple to implement, but the effectiveness in detecting vulnerabilities is sub-optimal and resource efficiency is poor

Engineering Contradiction:
Improvevulnerability detection effectivenessVSAvoidtesting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic test sequence generation where the testing system adaptively creates and executes sequences of security tests based on real-time results. The system dynamically adjusts the testing process by generating supplementary test sequences that link multiple tests together, transforming static individual tests into dynamic interconnected test flows that improve vulnerability detection while managing complexity through automation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically generating test sequences and executing them without human intervention. The patent employs machine learning models that autonomously analyze test results, generate supplementary test sequences, and iterate through multiple rounds of testing, enabling the system to self-optimize its testing effectiveness while reducing the need for manual test management

Inventive Principle:
Principle #25Self-service

2Productivity

If individual security tests are performed without linking, then the implementation is straightforward, but resource efficiency deteriorates due to redundant testing

Engineering Contradiction:
Improveresource efficiencyVSAvoidtesting process complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges individual security tests into linked test sequences where multiple tests are executed in coordinated groups. By combining related tests into sequences and using machine learning to identify patterns across tests, the system eliminates redundant testing while maintaining comprehensive coverage, thereby improving resource efficiency without significantly increasing perceived complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where test results from individual tests and sequences are automatically analyzed by machine learning models. This feedback drives the generation of supplementary test sequences that target identified vulnerabilities more effectively, creating a closed-loop system that continuously improves resource efficiency by learning from previous test outcomes and avoiding redundant testing

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If manual test sequence creation is used, then the system requires less computational resources, but the ability to simulate real-world breach attempts is insufficient

Engineering Contradiction:
Improvesimulation of real-world breach attemptsVSAvoidcomputational resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system employs machine learning models that autonomously generate test sequences by analyzing patterns from previous tests and simulating real-world breach attempts. This self-service capability allows the system to automatically adapt its testing approach to match realistic attack scenarios without requiring manual configuration, achieving high adaptability while the models efficiently manage computational resource consumption through learned patterns

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by using machine learning models to pre-analyze application characteristics and pre-generate targeted test sequences before actual security testing begins. This preliminary analysis enables the system to simulate real-world breach attempts more effectively by preparing adaptive test sequences in advance, reducing the need for extensive computational resources during the actual testing phase

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12086273B2Electronic system for identifying faulty code and vulnerabilities in software programs using linked evaluation tools
Publication Date: 2024.09.10 BANK OF AMERICA CORP
  • US12086273B2 patent drawing
  • US12086273B2 patent drawing
  • US12086273B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for dynamically generating linked security tests. The present invention may be configured to perform security tests on an application, generate, based on the results of the security tests, security test sequences that include at least one security test that the application failed, perform the security test sequences on the application, and, iteratively and until the application passes each security test sequence in an iteration, generate additional security test sequences. The present invention may be further configured to provide results of the security tests and security test sequences to one or more machine learning models to generate supplementary security test sequences and determine probabilities of the application failing the supplementary security test sequences.