Partially Functional Application Vulnerability Testing with Feature Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional vulnerability assessment is performed on fully functional software applications, leading to extensive modifications and potential downstream issues, as DAST tools require a complete application to detect vulnerabilities, which is not feasible for partially functional applications.

Innovation Solution

Systems and methods for vulnerability assessment on partially functional applications using feature files and script sets that mimic complete application functionality, allowing for early detection and minimal modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If vulnerability assessment is performed on fully functional applications using conventional DAST tools, then comprehensive security detection is achieved, but extensive modifications and downstream changes are required

Engineering Contradiction:
Improvevulnerability detection completenessVSAvoidapplication modification extent
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the application into compartmentalized features that can be tested independently. Each feature is evaluated separately using feature files that define security testing parameters, allowing vulnerability assessment without requiring the entire application to be fully functional or requiring extensive modifications to the complete system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs vulnerability assessment on individual features before they are integrated into the complete application. By conducting security testing in advance on isolated features using feature files and script sets, the system identifies vulnerabilities early in the development cycle, preventing the need for extensive modifications later when the application is fully assembled.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If vulnerability assessment is delayed until beta testing phase, then application is sufficiently complete for DAST tools, but detection and curing becomes more complex and time-consuming

Engineering Contradiction:
Improveapplication completenessVSAvoidvulnerability curing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs vulnerability assessment on individual features before they are integrated into the complete application. By conducting security testing in advance on isolated features using feature files and script sets, the system identifies vulnerabilities early in the development cycle, preventing the need for extensive modifications later when the application is fully assembled.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the application into compartmentalized features that can be tested independently. Each feature is evaluated separately using feature files that define security testing parameters, allowing vulnerability assessment without requiring the entire application to be fully functional or requiring extensive modifications to the complete system.

Inventive Principle:
Principle #1Segmentation

3Loss of time

If DAST tools are used on partially functional applications, then early vulnerability detection is possible, but tools cannot properly query incomplete application functions

Engineering Contradiction:
Improvedetection timingVSAvoidtool compatibility
Core Design Contradiction:
Loss of timeVSEase of operation

Solution Approach 1:

The patent creates feature files that contain script sets representing the expected behavior and security parameters of application features. These feature files serve as virtual models or copies of the actual application functions, allowing DAST tools to query and assess security on partially functional applications by comparing actual behavior against the defined feature specifications without requiring the complete application to be operational.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12393697B2Systems and methods for performing vulnerability assessment on partially functional applications
Publication Date: 2025.08.19 CITIBANK N A
  • US12393697B2 patent drawing
  • US12393697B2 patent drawing
  • US12393697B2 patent drawing

AI summary

Systems and methods are described herein for performing vulnerability assessment on partially functional software applications (e.g., software applications currently at a phase in the development cycle prior to a user acceptance testing phase). By doing so, the system may detect vulnerabilities, if any, more easily based on the fewer functional components of the application. Additionally or alternatively, curing any vulnerabilities will require fewer modifications to the application's software, architecture, and/or intended functionality (as these characteristics are also earlier in their development cycle).