Multi-Tool Orchestration for Software Security Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software security analysis tools lack orchestration capabilities, requiring users to manually manage and integrate multiple tools for scanning activities, leading to inefficiencies in triggering, monitoring, and aggregating scan results.
Innovation Solution
A multi-tool security analysis system that acts as an orchestration layer, selectively activating and monitoring scans across various software security analysis tools, aggregating results, and providing a unified interface for visualization, including SAST, DAST, and OSA tools, without relying on specific taxonomies or protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple software security analysis tools are used to perform comprehensive security scanning, then the security analysis capability is improved, but the complexity of tool management and integration increases
Solution Approach 1:
The patent combines multiple independent software security analysis tools into a single integrated platform that provides unified orchestration, scan management, and result aggregation. This merging approach maintains comprehensive security analysis capability while reducing management complexity by presenting a single interface to users.
Solution Approach 2:
The disclosed system creates a universal security analysis platform that can execute multiple types of security scans (SAST, DAST, OSA, IAST) through a single interface. This multi-functional approach allows the system to perform diverse security analysis tasks while maintaining consistent tool management procedures.
2Reliability
If multiple software security analysis tools are orchestrated and monitored, then the comprehensive security coverage is improved, but the time and effort required for tool coordination increases
Solution Approach 1:
The system performs preliminary configuration and setup of multiple security analysis tools during an initial orchestration phase. This preliminary action establishes the framework for automated coordination, reducing the time required for tool management during subsequent security scanning operations.
Solution Approach 2:
The disclosed system implements automated self-service mechanisms that enable the security analysis platform to independently coordinate and manage multiple tools without requiring continuous manual intervention. The system automatically handles tool activation, scan execution, and result aggregation, significantly reducing coordination time.
3Reliability
If scan results from multiple independent tools are aggregated, then the comprehensiveness of security findings is improved, but the difficulty of result integration and interpretation increases
Solution Approach 1:
The system segments and standardizes scan results from multiple independent security tools into a unified format with consistent structure and classification. This segmentation approach maintains the comprehensiveness of findings while making them easier to interpret by presenting them in a standardized, organized manner.
Solution Approach 2:
The disclosed system transforms heterogeneous scan results from different security tools into homogeneous, standardized output formats. By normalizing the structure, classification, and presentation of findings, the system maintains comprehensive security coverage while significantly improving the ease of result interpretation and analysis.
Data Source
AI summary
A system for performing code security scan includes a non-transitory computer readable medium and a processor. The non-transitory computer readable medium stores a plurality of identifiers each identifying a software security analysis tool of one of several categories, including SAST, DAST and OSA tools. The processor receives an identification of code to be scanned. The processor selects at least two identifiers from the plurality of identifiers. The at least two identifiers identify at least two select software security analysis tools for execution on the identified code. The processor receives an execution result from each select software security analysis tool after performing execution on the identified code. The processor aggregates the execution result from each select software security analysis tool. A user interface displays an aggregation of the execution result from each select software security analysis tool.


