Machine Learning Security Analysis Effort Estimation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Estimating the effort and cost of analyzing software systems for security vulnerabilities is challenging due to their complexity and interdependencies, leading to inaccurate and subjective assessments that result in suboptimal resource utilization and financial performance for security intelligence platform providers.

Innovation Solution

A method and system utilizing machine learning-based analytics with dynamic and static analysis tools to generate quantitative estimates of security analysis effort and cost, employing an intermediate code representation that allows analysis without requiring source code disclosure, and using modified analysis tools to collect data from various sources within the software system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If human experts perform security analysis estimation, then subjective judgment and experience are applied, but accuracy and repeatability deteriorate due to system complexity

Engineering Contradiction:
Improveestimation accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces human expert judgment (mechanical/cognitive system) with automated machine learning algorithms and statistical analysis tools. The system uses decomposition of software features, complexity categorization, code structure analysis, and static/runtime dependency tracking to objectively measure security analysis effort, eliminating subjective human estimation while maintaining accuracy despite system complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If subjective estimation methods are used, then quick assessments are obtained, but resource utilization and financial performance deteriorate

Engineering Contradiction:
Improveestimation speedVSAvoidresource allocation reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary automated analysis of software system attributes, complexity metrics, and interdependencies before security assessment begins. By pre-calculating these parameters using machine learning models trained on historical data, the system establishes accurate baseline estimates that guide resource allocation and pricing decisions, eliminating the need for reactive subjective adjustments.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If detailed analysis of software attributes and interdependencies is performed, then estimation accuracy improves, but analysis time and computational resources increase

Engineering Contradiction:
Improveestimation precisionVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the security analysis estimation process into distinct measurable components: software feature decomposition, complexity categorization, code structure analysis, and static/runtime dependency identification. Each segment is analyzed independently using specialized algorithms, allowing parallel processing and reducing overall analysis time while maintaining comprehensive precision through aggregation of segment results.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10614226B2Machine learning statistical methods estimating software system's security analysis assessment or audit effort, cost and processing decisions
Publication Date: 2020.04.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10614226B2 patent drawing
  • US10614226B2 patent drawing
  • US10614226B2 patent drawing

AI summary

A method, system and computer-usable medium for generating a security analysis effort, cost and process scope estimates, comprising: analyzing a software system; identifying a complexity level of a security analysis, the complexity level of the security analysis comprising identification of an effort level for the security analysis; and, generating the security analysis effort estimate, the security analysis effort estimate comprising an estimate of an effort expenditure to perform a security analysis on the software system at the identified complexity level.