Automated Security Feedback Platform for Code Quality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security testing methods lack automated mechanisms to identify and provide positive feedback on developers' use of secure coding best practices, limiting the recognition and implementation of affirmative secure coding techniques.

Innovation Solution

A comprehensive and customizable software security assessment platform that includes an analysis engine to examine code, identify applicable best practices, and provide positive feedback on their implementation, utilizing a communications server for interaction with external systems and threat databases, and integrating with dynamic, static, and manual testing engines to assess and report on security vulnerabilities and best practice adherence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If automated mechanisms are introduced to identify and provide feedback on secure coding best practices, then developer knowledge and coding quality improve, but system complexity and implementation cost increase

Engineering Contradiction:
Improvecoding qualityVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system implements automated feedback mechanisms that analyze code against secure coding best practices and provide actionable recommendations to developers. The feedback loop includes identifying best practice violations, suggesting specific corrections, and tracking improvement over time, thereby enhancing coding quality through continuous automated guidance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary analysis layer between the development environment and the codebase. This intermediary component automatically scans code, evaluates it against security standards, and translates findings into developer-friendly feedback, reducing the complexity burden on the core development process while maintaining high coding quality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security assessment platforms are deployed to analyze code and provide feedback, then security risks are reduced, but processing time and computational resources increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security assessments during the coding process itself rather than as a separate post-development step. By integrating best practice analysis into the development workflow and providing real-time feedback, the system reduces security risks early while minimizing additional processing time through efficient, incremental code analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements selective analysis that focuses on identifying and addressing the most critical security vulnerabilities and best practice violations first. Rather than analyzing every aspect of the code equally, the system prioritizes high-impact security issues, thereby achieving substantial security improvement with reduced processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9286063B2Methods and systems for providing feedback and suggested programming methods
Publication Date: 2016.03.15 VERACODE INC
  • US9286063B2 patent drawing
  • US9286063B2 patent drawing
  • US9286063B2 patent drawing

AI summary

The techniques and supporting systems described herein provide a comprehensive and customizable approach to identifying the use of best practices during the design and development of software applications, as well as recommending additional enhancements or courses of action that may be implemented to further improve the application. Target software application code is received specific application security best practices applicable to the target software application are identified. Locations in the code where the various best practices ought to be implemented are then identified, and a determination is made whether the relevant best practices are implemented for each location. Finally, positive feedback is provided to the developers for what appears to be their correct implementation of best practices.