Security Engine Applying Posture to Software Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software development lacks consistent implementation of security protections, leading to vulnerabilities that can be exploited, and existing methods like penetration testing and source code scanning are reactive and costly, failing to provide proactive measures for ensuring security postures during the planning and design phases.
Innovation Solution
A method and system that utilize a security engine to apply and enforce a predefined security posture by combining security protections, a representation of the security posture, and a software application model to generate outputs for analysis, implementation, and assurance of security requirements, ensuring consistent and uniform application of security measures across software projects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If reactive security testing methods (penetration testing, source code scanning) are used, then security vulnerabilities can be detected, but the cost and time consumption increase significantly
Solution Approach 1:
The patent applies preliminary action by implementing security protections during the planning and design phases of software development, before the actual coding begins. Security requirements are identified and integrated into the software model early in the development lifecycle, preventing vulnerabilities rather than detecting them later through costly penetration testing or source code scanning.
2Reliability
If reactive security testing methods are used, then security vulnerabilities can be detected, but the implementation cost increases
Solution Approach 1:
The patent applies preliminary action by implementing security protections during the planning and design phases of software development, before the actual coding begins. Security requirements are identified and integrated into the software model early in the development lifecycle, preventing vulnerabilities rather than detecting them later through costly penetration testing or source code scanning.
3Reliability
If security protections are applied consistently across all software projects, then security posture is improved, but the complexity of implementation increases
Solution Approach 1:
The patent applies universality by creating a generalized software model that can represent different software applications and their security requirements in a unified framework. The model uses standardized elements (data items, interfaces, processing logic) that can be applied across diverse software projects, enabling consistent security protection application without increasing implementation complexity.
Solution Approach 2:
The patent applies parameter changes by transforming security requirements into model parameters that can be systematically applied to the software model. Security protections are defined as configurable parameters within the model, allowing consistent application across different software projects while maintaining flexibility for project-specific variations.
4Reliability
If security requirements are identified during planning and design phases, then proactive security protection is achieved, but the difficulty of requirements identification increases
Solution Approach 1:
The patent applies the intermediary principle by introducing a software model as a mediator between security requirements and the actual software implementation. The model serves as an intermediate representation that makes security requirements visible, measurable, and manageable during the planning and design phases, reducing the difficulty of identifying and tracking security requirements.
Data Source
AI summary
A computer implemented method of applying a technical application security posture to a software project is described. The method allows an industry or corporate wide technical security posture to be enumerated. It further allows multiple software applications to be represented based on existing or proposed software (source code) producing a model representation of the application. Implementations of the technical security posture can then be combined with the software application model to ensure the necessary technical security posture is applied to the application implementation.


