SDLC Security Data Normalization for Cross-Tool Risk Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software development life cycle (SDLC) methodologies fail to effectively integrate and analyze security risks across different phases due to incompatible data formats and tools, leading to overlooked security issues and increased development risks.
Innovation Solution
A data normalization module that collects, normalizes, and aggregates data from various software tools throughout the SDLC, using a common information model to map and correlate data across phases, enabling continuous security analysis and risk scoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data from multiple software tools are used throughout the SDLC, then security analysis coverage is improved, but data compatibility and integration complexity worsen due to incompatible data formats and tools
Solution Approach 1:
The patent introduces a data normalization module as an intermediary component that receives data from multiple software tools used throughout the SDLC (planning, development, testing, deployment phases). This module normalizes the heterogeneous data from different tools into a unified format, enabling comprehensive security analysis without requiring direct integration between all tools. The normalization module acts as the mediator that resolves data compatibility issues while maintaining security analysis coverage across all phases.
Solution Approach 2:
The patent applies parameter changes by transforming data from various software tools through normalization processes that adjust data formats, schemas, and structures into a common standardized format. This parameter transformation enables consistent security risk assessment across different tool outputs while maintaining the original security-relevant information from each tool's data structure.
2Productivity
If data is pre-processed based on anticipated analysis needs, then retrieval efficiency is improved, but data flexibility and analysis scope worsen due to discarded remainder data
Solution Approach 1:
The patent implements preliminary action by performing data normalization during the data collection phase, before security analysis is executed. The normalization module standardizes data from all software tools upfront, creating a unified data structure that enables both efficient retrieval and flexible analysis. This preliminary normalization prevents the need for later data transformation while maintaining access to all original data elements for comprehensive security assessment.
Solution Approach 2:
The normalized data structure created by the patent serves multiple functions: it enables efficient data retrieval through standardized formatting, supports flexible analysis across different security phases, and maintains compatibility with various analysis methods. The universal normalized format allows the same data to be used for different types of security analyses without requiring separate preprocessing for each analysis type.
3Adaptability or versatility
If massive quantities of raw data are stored for later retrieval, then analysis flexibility is improved, but storage costs and data management complexity worsen
Solution Approach 1:
The patent extracts only the essential security-relevant data elements from the raw data generated by software tools throughout the SDLC. The normalization module identifies and extracts critical security information while filtering out redundant or non-essential data. This extraction process reduces the volume of data that needs to be stored and managed, while maintaining all necessary information for comprehensive security analysis.
Solution Approach 2:
The patent applies local quality by storing normalized data with varying levels of detail based on their security relevance. Critical security data elements are maintained with high fidelity and detailed information, while less critical elements are stored in summarized or aggregated forms. This differentiated storage approach optimizes storage efficiency while preserving analysis flexibility for security-critical information.
Data Source
AI summary
Data are mapped from multiple tools to a common information model during the development life cycle of a software application. The common information model normalizes the data, enabling the data to be correlated even when development tasks are performed by separate entities using different tools. Using the common information model, security issues are identified in a later part of the software development life cycle based on data generated at an earlier phase, such as on an ongoing basis throughout the life cycle. A user can investigate the security issues and associated risk using an interactive dashboard.


