Sensitive Data Leak-Detection Engine for Pre-Deployment Code Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security management systems lack comprehensive computing logic and infrastructure for efficient sensitive data leak-detection, particularly in large-scale software development environments, leading to inefficiencies and increased computational costs.
Innovation Solution
A sensitive data leak-detection engine integrated into the software development environment, utilizing a logging framework, onboarding engine, and code scanning package to automate sensitive data scanning during the development stage, identifying potential leaks through a mock library and generating notifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security management systems are used for sensitive data leak-detection, then basic security checking can be performed, but computational overhead and resource consumption increase significantly
Solution Approach 1:
The system performs sensitive data scanning during the development stage before code is deployed to production environments. By detecting and addressing sensitive data leaks in advance, the system prevents the need for computationally intensive scanning of production systems, thereby reducing overall computational overhead while maintaining detection reliability
Solution Approach 2:
The security management system is divided into distinct functional components including a sensitive data leak-detection engine, logging framework, onboarding engine, and code scanning package. This segmentation allows each component to operate independently with optimized resource allocation, reducing the computational burden on any single system element
2Reliability
If comprehensive sensitive data scanning is implemented in production systems, then all sensitive data leaks can be detected, but CPU usage and memory requirements increase significantly
Solution Approach 1:
The system shifts security scanning operations to the development stage, performing sensitive data detection before code reaches production. This preliminary action ensures comprehensive detection coverage while preserving production system performance by eliminating the need for continuous scanning in live environments
3Reliability
If integrated sensitive data leak-detection is implemented during development stage, then security management is improved, but integration complexity with existing development processes increases
Solution Approach 1:
The sensitive data leak-detection engine is designed as a universal system that can integrate with multiple different development workflows and logging frameworks through standardized interfaces. The mock library for common logger and configurable scanning parameters enable the system to work across diverse development environments without requiring custom integration for each case
Solution Approach 2:
The system introduces an intermediary logging framework that sits between the development code and the security detection engine. This intermediary layer standardizes data collection and filtering, simplifying integration with existing development processes while maintaining comprehensive detection capabilities
4Ease of operation
If automated onboarding process is implemented for sensitive data scanning, then ease of operation is improved, but initial setup time and configuration complexity increase
Solution Approach 1:
The onboarding engine implements automated configuration that allows the system to self-configure by detecting existing development environments, logging frameworks, and code structures. This self-service capability reduces manual setup requirements and accelerates the onboarding process while maintaining ease of operation for developers
Data Source
AI summary
Methods, systems, and computer storage media for providing a sensitive data scanning in a sensitive data leak-detection engine of a security management system. Sensitive data scanning—for example confidential information scanning or credential scanning—provides sensitive data leak-detection via a software development environment during a software development process. In operation, a request—to execute a sensitive data scanning operation on an instance of in-development code—is accessed. The sensitive data scanning operation executable via a sensitive data leak-detection engine that provides code security management services in a software development environment. A code scanning package is accessed. The code scanning package comprises software development environment code scanning parameters. Based on the software development environment code scanning parameters, the in-development code is scanned for sensitive data. A notification comprising a sensitive data scan result associated with the in-development code is generated. The notification is communicated to cause the notification to be displayed.


