Multi-Tool Orchestration for Software Security Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software security analysis tools lack orchestration capabilities, requiring users to manually manage and integrate multiple tools for scanning activities, leading to inefficiencies in triggering, monitoring, and aggregating scan results.

Innovation Solution

A multi-tool security analysis system that acts as an orchestration layer, selectively activating and monitoring scans across various software security analysis tools, aggregating results, and providing a unified interface for visualization, including SAST, DAST, and OSA tools, without relying on specific taxonomies or protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple software security analysis tools are used to perform comprehensive security scanning, then the security analysis capability is improved, but the complexity of tool management and integration increases

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoidtool management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple independent software security analysis tools into a single integrated platform that provides unified orchestration, scan management, and result aggregation. This merging approach maintains comprehensive security analysis capability while reducing management complexity by presenting a single interface to users.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The disclosed system creates a universal security analysis platform that can execute multiple types of security scans (SAST, DAST, OSA, IAST) through a single interface. This multi-functional approach allows the system to perform diverse security analysis tasks while maintaining consistent tool management procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple software security analysis tools are orchestrated and monitored, then the comprehensive security coverage is improved, but the time and effort required for tool coordination increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidtool coordination time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary configuration and setup of multiple security analysis tools during an initial orchestration phase. This preliminary action establishes the framework for automated coordination, reducing the time required for tool management during subsequent security scanning operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The disclosed system implements automated self-service mechanisms that enable the security analysis platform to independently coordinate and manage multiple tools without requiring continuous manual intervention. The system automatically handles tool activation, scan execution, and result aggregation, significantly reducing coordination time.

Inventive Principle:
Principle #25Self-service

3Reliability

If scan results from multiple independent tools are aggregated, then the comprehensiveness of security findings is improved, but the difficulty of result integration and interpretation increases

Engineering Contradiction:
Improvefindings comprehensivenessVSAvoidresult interpretation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments and standardizes scan results from multiple independent security tools into a unified format with consistent structure and classification. This segmentation approach maintains the comprehensiveness of findings while making them easier to interpret by presenting them in a standardized, organized manner.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The disclosed system transforms heterogeneous scan results from different security tools into homogeneous, standardized output formats. By normalizing the structure, classification, and presentation of findings, the system maintains comprehensive security coverage while significantly improving the ease of result interpretation and analysis.

Inventive Principle:
Principle #33Homogeneity

Data Source

PatentUS20220261480A1Methods and systems for multi-tool orchestration
Publication Date: 2022.08.18 CAPITAL ONE SERVICES LLC
  • US20220261480A1 patent drawing
  • US20220261480A1 patent drawing
  • US20220261480A1 patent drawing

AI summary

A system for performing code security scan includes a non-transitory computer readable medium and a processor. The non-transitory computer readable medium stores a plurality of identifiers each identifying a software security analysis tool of one of several categories, including SAST, DAST and OSA tools. The processor receives an identification of code to be scanned. The processor selects at least two identifiers from the plurality of identifiers. The at least two identifiers identify at least two select software security analysis tools for execution on the identified code. The processor receives an execution result from each select software security analysis tool after performing execution on the identified code. The processor aggregates the execution result from each select software security analysis tool. A user interface displays an aggregation of the execution result from each select software security analysis tool.