Automated Security Assessment for Online Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional database systems face challenges in efficiently performing security assessments, which are time-consuming and costly for cloud service providers, especially when dealing with multi-tenant databases and software applications.

Innovation Solution

The implementation of mechanisms and methods for performing security assessments in an online services system, including receiving a security assessment agreement, configuration data, and scanning data, and sending this information to security assessment systems to automate the testing process, facilitating security reviews across various database architectures such as Oracle and DB2.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security assessment methods are used in database systems, then security testing can be performed, but the process is time-consuming and costly

Engineering Contradiction:
Improvesecurity assessmentVSAvoidtime-consuming
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting configuration data and scanning data before the actual security assessment. This preparation phase includes gathering software configuration information, dependency data, and vulnerability scanning results in advance, so that when security assessment is needed, the analysis can be performed more quickly using pre-collected information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a virtual representation or copy of the software application's configuration and scanning data. Instead of performing exhaustive security tests on the actual running system, the patent uses copied configuration data, dependency information, and scanning results to perform security assessments, significantly reducing the time and resources required while maintaining assessment accuracy.

Inventive Principle:
Principle #26Copying

2Reliability

If conventional security assessment methods are used in database systems, then security testing can be performed, but the process is costly

Engineering Contradiction:
Improvesecurity assessmentVSAvoidcostly
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system creates a virtual representation or copy of the software application's configuration and scanning data. Instead of performing exhaustive security tests on the actual running system, the patent uses copied configuration data, dependency information, and scanning results to perform security assessments, significantly reducing the time and resources required while maintaining assessment accuracy.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces manual, mechanical security assessment processes with an automated computer-implemented system. The processor automatically collects configuration data, performs vulnerability analysis, and generates security assessments without requiring manual intervention for each assessment task, thereby reducing operational costs and enabling scalable security evaluation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated security assessment systems are implemented, then security testing efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity testing efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system is designed with multi-functionality to handle various security assessment tasks through a single integrated platform. The processor can perform configuration analysis, vulnerability scanning, dependency checking, and security reporting within one system, eliminating the need for multiple separate tools and reducing overall system complexity despite the range of functions provided.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security assessment system performs self-service by automatically collecting its own configuration data, executing vulnerability scans, and generating assessments without requiring external intervention. The system autonomously manages the security assessment workflow, reducing the operational complexity of managing and coordinating multiple separate security tools and processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8904541B2Performing security assessments in an online services system
Publication Date: 2014.12.02 SALESFORCE INC
  • US8904541B2 patent drawing
  • US8904541B2 patent drawing
  • US8904541B2 patent drawing

AI summary

A system and method for performing security assessments in an online services system. In one embodiment, a method includes receiving an accepted security assessment agreement from a user, where the security assessment agreement is associated with a software application utilized in an online services system. The method also includes receiving configuration data associated with the software application; receiving scanning data associated with the software application; and sending the configuration data and scanning data to one or more security assessment systems.