Predictive Application Security Scoring via ML

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing technologies face challenges in effectively identifying and assessing the severity of vulnerabilities in applications during development and deployment, as existing methods often rely on disparate security tools that provide inconsistent and difficult-to-consolidate data, hindering early action on security issues.

Innovation Solution

A system and method that collect metrics from DevSecOps tools, combine them with information from external sources like vulnerability databases and social media, and apply a machine learning model to generate a predictive security score, using natural language processing to determine severity and weight metrics for a comprehensive security posture assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If multiple disparate security tools are used to identify vulnerabilities, then the quantity of vulnerability detection increases, but the consistency and consolidability of data decreases

Engineering Contradiction:
Improvequantity of vulnerability detectionVSAvoidconsistency of security data
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent combines data from multiple disparate security tools (static analysis, dynamic analysis, SAST, DAST, SCA tools) into a unified security scoring system. The machine learning model aggregates metrics from these different sources and applies consistent weighting and normalization to produce reliable, consolidated security scores that maintain data consistency across diverse tool outputs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system transforms raw vulnerability data from multiple tools into standardized parameters through metric normalization and weighting. The machine learning model converts heterogeneous security metrics into a unified scoring framework, changing the parameter representation to enable consistent comparison and aggregation across different security tool outputs.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If traditional security assessment methods are used, then the simplicity of implementation is maintained, but the accuracy of vulnerability severity assessment decreases

Engineering Contradiction:
Improvesimplicity of implementationVSAvoidaccuracy of vulnerability severity assessment
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces a machine learning model as an intermediary between raw security metrics and final vulnerability assessment. This intermediary layer processes multiple security metrics, applies learned weights and relationships, and produces accurate severity predictions. The system maintains ease of operation by automating this complex analysis while improving measurement precision through data-driven assessments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces traditional manual or rule-based security assessment mechanisms with a machine learning-based predictive model. This substitution enables automated, data-driven severity assessment that is both accurate and easy to implement, as the model handles the complex analysis automatically without requiring manual configuration of assessment rules.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of information

If comprehensive data from multiple sources is collected, then the completeness of security assessment improves, but the complexity of data processing increases

Engineering Contradiction:
Improvecompleteness of security assessmentVSAvoidcomplexity of data processing
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts and focuses on the most relevant security metrics from comprehensive data sources using a machine learning model. The system identifies and extracts key features from multiple data sources (vulnerability metrics, code quality metrics, security scan results) that contribute most to accurate security assessment, processing only the essential data while maintaining completeness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms comprehensive raw data from multiple sources into a reduced set of weighted metrics that the machine learning model can process efficiently. By changing the parameter representation and applying dimensionality reduction through metric selection and weighting, the system maintains assessment completeness while reducing processing complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12032706B2Application security scoring
Publication Date: 2024.07.09 KYNDRYL INC
  • US12032706B2 patent drawing
  • US12032706B2 patent drawing
  • US12032706B2 patent drawing

AI summary

A method includes receiving, by a computing device, metrics identifying vulnerabilities in an application; collecting, by the computing device, information related to the vulnerabilities; assigning, by the computing device, weights to the metrics using collected information; applying, by the computing device, a machine learning model on the weighted metrics; and generating, by the computing device, a predictive score for the vulnerabilities using the machine learning model.