Neural Network for Software Vulnerability Testing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software security vulnerability testing in enterprise systems is hindered by high incidences of false positives, leading to inefficient diagnostic tools and a false sense of security, as existing methods fail to accurately identify and prioritize real vulnerabilities in dynamic testing.
Innovation Solution
Implementing an AI-based neural network system that trains on supervised classification to differentiate between actual and false positive security vulnerabilities by directing attack vectors at software applications during execution, using a convolutional neural network to adjust weights and reduce false positive defects through backpropagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional dynamic testing methods are used to identify security vulnerabilities, then testing coverage is achieved, but false positive identification rate increases
Solution Approach 1:
A neural network classifier is introduced as an intermediary between the dynamic testing process and vulnerability identification. The classifier processes testing results and distinguishes between true vulnerabilities and false positives, thereby improving identification accuracy while reducing false positive rates.
Solution Approach 2:
The patent replaces traditional mechanical/manual vulnerability assessment methods with an AI-based neural network system. This substitution enables automated, intelligent analysis of dynamic testing results, significantly improving measurement precision and reducing false positives compared to conventional approaches.
2Reliability
If security testing is performed on enterprise software systems, then security vulnerabilities are detected, but diagnostic efficiency decreases due to false positives
Solution Approach 1:
The neural network classifier provides feedback by analyzing dynamic testing results and identifying which findings represent true vulnerabilities versus false positives. This feedback mechanism enables security teams to focus on actual issues, thereby maintaining high detection reliability while significantly improving diagnostic efficiency.
Solution Approach 2:
The system performs self-service by automatically distinguishing true vulnerabilities from false positives through the neural network classifier. This eliminates the need for manual verification of each testing finding, thereby maintaining reliable vulnerability detection while dramatically improving diagnostic efficiency.
3Reliability
If comprehensive security testing is implemented, then security coverage is improved, but time consumption increases due to false positive analysis
Solution Approach 1:
The neural network classifier performs preliminary action by pre-processing and analyzing dynamic testing results before they reach security analysts. By automatically filtering out false positives in advance, the system maintains comprehensive security testing coverage while eliminating time-consuming manual analysis of false positives.
Data Source
AI summary
Method and system of deploying a trained machine learning neural network in dynamic testing of security vulnerability in software applications. The method comprises directing, from a security assessing server computing device, to a software program under execution, a series of attack vectors, deploying a set of results produced in accordance with the software program under execution and the attack vectors to an input layer of the trained machine learning neural network, the trained machine learning neural network comprising an output layer that is interconnected with the input layer via a set of intermediate layers, and identifying, in accordance with a predetermined threshold percentage value of false positive software security vulnerability defects, one or more software security vulnerability defects associated with the results produced, the software security vulnerability defects being generated in accordance with the output layer of the trained machine learning neural network.


