SDLC Security Data Normalization for Cross-Tool Risk Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software development life cycle (SDLC) methodologies fail to effectively integrate and analyze security risks across different phases due to incompatible data formats and tools, leading to overlooked security issues and increased development risks.

Innovation Solution

A data normalization module that collects, normalizes, and aggregates data from various software tools throughout the SDLC, using a common information model to map and correlate data across phases, enabling continuous security analysis and risk scoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data from multiple software tools are used throughout the SDLC, then security analysis coverage is improved, but data compatibility and integration complexity worsen due to incompatible data formats and tools

Engineering Contradiction:
Improvesecurity analysis coverageVSAvoiddata integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a data normalization module as an intermediary component that receives data from multiple software tools used throughout the SDLC (planning, development, testing, deployment phases). This module normalizes the heterogeneous data from different tools into a unified format, enabling comprehensive security analysis without requiring direct integration between all tools. The normalization module acts as the mediator that resolves data compatibility issues while maintaining security analysis coverage across all phases.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by transforming data from various software tools through normalization processes that adjust data formats, schemas, and structures into a common standardized format. This parameter transformation enables consistent security risk assessment across different tool outputs while maintaining the original security-relevant information from each tool's data structure.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If data is pre-processed based on anticipated analysis needs, then retrieval efficiency is improved, but data flexibility and analysis scope worsen due to discarded remainder data

Engineering Contradiction:
Improvedata retrieval efficiencyVSAvoidanalysis flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by performing data normalization during the data collection phase, before security analysis is executed. The normalization module standardizes data from all software tools upfront, creating a unified data structure that enables both efficient retrieval and flexible analysis. This preliminary normalization prevents the need for later data transformation while maintaining access to all original data elements for comprehensive security assessment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The normalized data structure created by the patent serves multiple functions: it enables efficient data retrieval through standardized formatting, supports flexible analysis across different security phases, and maintains compatibility with various analysis methods. The universal normalized format allows the same data to be used for different types of security analyses without requiring separate preprocessing for each analysis type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If massive quantities of raw data are stored for later retrieval, then analysis flexibility is improved, but storage costs and data management complexity worsen

Engineering Contradiction:
Improveanalysis flexibilityVSAvoiddata storage volume
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential security-relevant data elements from the raw data generated by software tools throughout the SDLC. The normalization module identifies and extracts critical security information while filtering out redundant or non-essential data. This extraction process reduces the volume of data that needs to be stored and managed, while maintaining all necessary information for comprehensive security analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by storing normalized data with varying levels of detail based on their security relevance. Critical security data elements are maintained with high fidelity and detailed information, while less critical elements are stored in summarized or aggregated forms. This differentiated storage approach optimizes storage efficiency while preserving analysis flexibility for security-critical information.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20260105160A1Managing security of a software development life cycle
Publication Date: 2026.04.16 CISCO TECHNOLOGY INC
  • US20260105160A1 patent drawing
  • US20260105160A1 patent drawing
  • US20260105160A1 patent drawing

AI summary

Data are mapped from multiple tools to a common information model during the development life cycle of a software application. The common information model normalizes the data, enabling the data to be correlated even when development tasks are performed by separate entities using different tools. Using the common information model, security issues are identified in a later part of the software development life cycle based on data generated at an earlier phase, such as on an ongoing basis throughout the life cycle. A user can investigate the security issues and associated risk using an interactive dashboard.