Partially Functional Application Vulnerability Testing with Feature Files
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional vulnerability assessment is performed on fully functional software applications, leading to extensive modifications and potential downstream issues, as DAST tools require a complete application to detect vulnerabilities, which is not feasible for partially functional applications.
Innovation Solution
Systems and methods for vulnerability assessment on partially functional applications using feature files and script sets that mimic complete application functionality, allowing for early detection and minimal modifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If vulnerability assessment is performed on fully functional applications using conventional DAST tools, then comprehensive security detection is achieved, but extensive modifications and downstream changes are required
Solution Approach 1:
The patent segments the application into compartmentalized features that can be tested independently. Each feature is evaluated separately using feature files that define security testing parameters, allowing vulnerability assessment without requiring the entire application to be fully functional or requiring extensive modifications to the complete system.
Solution Approach 2:
The patent performs vulnerability assessment on individual features before they are integrated into the complete application. By conducting security testing in advance on isolated features using feature files and script sets, the system identifies vulnerabilities early in the development cycle, preventing the need for extensive modifications later when the application is fully assembled.
2Reliability
If vulnerability assessment is delayed until beta testing phase, then application is sufficiently complete for DAST tools, but detection and curing becomes more complex and time-consuming
Solution Approach 1:
The patent performs vulnerability assessment on individual features before they are integrated into the complete application. By conducting security testing in advance on isolated features using feature files and script sets, the system identifies vulnerabilities early in the development cycle, preventing the need for extensive modifications later when the application is fully assembled.
Solution Approach 2:
The patent segments the application into compartmentalized features that can be tested independently. Each feature is evaluated separately using feature files that define security testing parameters, allowing vulnerability assessment without requiring the entire application to be fully functional or requiring extensive modifications to the complete system.
3Loss of time
If DAST tools are used on partially functional applications, then early vulnerability detection is possible, but tools cannot properly query incomplete application functions
Solution Approach 1:
The patent creates feature files that contain script sets representing the expected behavior and security parameters of application features. These feature files serve as virtual models or copies of the actual application functions, allowing DAST tools to query and assess security on partially functional applications by comparing actual behavior against the defined feature specifications without requiring the complete application to be operational.
Data Source
AI summary
Systems and methods are described herein for performing vulnerability assessment on partially functional software applications (e.g., software applications currently at a phase in the development cycle prior to a user acceptance testing phase). By doing so, the system may detect vulnerabilities, if any, more easily based on the fewer functional components of the application. Additionally or alternatively, curing any vulnerabilities will require fewer modifications to the application's software, architecture, and/or intended functionality (as these characteristics are also earlier in their development cycle).


