Automated Repository Trust Scoring via Security Criteria

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for determining trusted repositories are subjective, time-consuming, and inconsistent, especially when evaluating hundreds or thousands of repositories, as they rely on human review and do not account for objective metrics, leading to potential security vulnerabilities.

Innovation Solution

A computer system identifies and applies security criteria to a repository under evaluation, comparing the results to a trust baseline derived from a set of trusted repositories to generate scores and make recommendations on trustworthiness, thereby automating the trust review process and reducing subjectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If human review is used to determine trusted repositories, then subjective judgment can be applied, but the process becomes time-consuming and inconsistent

Engineering Contradiction:
Improvetrust determination accuracyVSAvoidreview time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the manual human review process with an automated computer-based system that applies security criteria and generates trust scores. This substitution eliminates the time-consuming nature of human review while maintaining reliability through objective, consistent evaluation metrics applied uniformly across all repositories.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the subjective human judgment process into an objective parameter-based evaluation system. By defining specific security criteria parameters (e.g., code scanning results, update frequency, user activity metrics) and measuring repositories against these parameters, the system achieves consistent, repeatable results without human subjectivity or time constraints.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If human review is used to evaluate repositories, then individual judgment is applied, but consistency and reliability decrease due to subjective variability

Engineering Contradiction:
Improvereview flexibilityVSAvoidreview consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent converts subjective human judgment into objective parameter measurement. By establishing defined security criteria parameters (code scanning vulnerabilities, repository update frequency, release history, user fork activity, owner trust status) and measuring each repository against these parameters, the system eliminates reviewer subjectivity and ensures consistent results across all evaluations.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements a feedback mechanism where repositories are evaluated against established security criteria parameters, generating standardized trust scores. This feedback loop ensures that all repositories are assessed using the same objective metrics, eliminating the inconsistency that arises from different human reviewers applying varying subjective standards.

Inventive Principle:
Principle #23Feedback

3Reliability

If code scanning is performed to identify vulnerabilities, then security detection is improved, but the process remains separate from trust determination

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidprocess integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the previously separate code scanning process with the trust determination process. By integrating security criteria evaluation (including code scanning results) into the unified trust score calculation, the system eliminates process fragmentation. The trust score now comprehensively incorporates security findings alongside other factors like update frequency and user activity, creating a single integrated evaluation mechanism.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12124583B2Trusted repository review
Publication Date: 2024.10.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12124583B2 patent drawing
  • US12124583B2 patent drawing
  • US12124583B2 patent drawing

AI summary

A method performs a trust review of repositories is provided. A computer system identifies security criteria for the trust review. The computer system applies the security criteria on a repository under evaluation. The computer system determines a recommendation for the repository under evaluation using a comparison of a result of applying the security criteria on the repository under evaluation to a trust baseline for a set of trusted repositories. According to other illustrative embodiments, a trust system and a computer program product for performing a trust review are provided.