Security Findings Acquisition System Orchestrating Entity Lifecycle Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Obtaining comprehensive and reliable security information across various stages of an entity's lifecycle in a production environment is complex due to the multitude of security assessment applications involved, making it difficult for users to determine entity security effectively.
Innovation Solution
A Security Findings Acquisition (SFA) system orchestrates the generation of SFA records by determining entity associations with a directed acyclic graph (DAG) and SFA anchors, using a lineage builder and resolver to obtain security assessment data from multiple security modeling assessment systems, thereby minimizing user involvement and providing a complete security view.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security assessment applications are used to evaluate entity security, then security assessment coverage is improved, but system complexity and difficulty of determining entity security increase
Solution Approach 1:
The patent segments the security assessment process into distinct components: multiple security assessment applications are divided and assigned to evaluate specific entities or entity components independently. Each application focuses on particular security aspects, and their results are then aggregated to form a comprehensive security view, thereby maintaining high coverage while managing complexity through structured division of labor
Solution Approach 2:
The patent introduces an intermediary system that collects, standardizes, and aggregates security findings from multiple security assessment applications. This intermediary layer translates diverse application outputs into a unified format, making it easier to determine overall entity security without users needing to directly manage the complexity of multiple applications
2Reliability
If multiple security assessment applications are used to evaluate entity security, then security assessment coverage is improved, but ease of operation deteriorates
Solution Approach 1:
The patent merges the outputs of multiple security assessment applications into a single consolidated security view. By combining findings from various applications and presenting them in an integrated manner, users can determine entity security easily without needing to separately analyze results from each individual application, thus maintaining comprehensive coverage while improving ease of operation
3Reliability
If comprehensive security information is obtained across all lifecycle stages, then reliability of security information is improved, but loss of time and processing complexity increase
Solution Approach 1:
The patent implements preliminary action by having security assessment applications continuously evaluate entities and store security findings in advance across all lifecycle stages. When security information is needed, it is already available from prior assessments, eliminating the need for time-consuming on-demand analysis while maintaining comprehensive and reliable security information
Data Source
AI summary
Techniques described herein relate to a method for generating security findings acquisition (SFA) records. The method includes obtaining, by a security finding acquisition system (SFAS) orchestrator, an entity context request associated with an entity; making a first determination, by the SFAS orchestrator, that the entity is not associated with an entity directed acyclic graph (DAG); in response to the first determination: obtaining, by the SFAS orchestrator, the entity DAG associated with the entity from a lineage builder; making a second determination, by the SFAS orchestrator, that the entity is not associated with SFA anchors; in response to the second determination: obtaining, by the SFAS orchestrator, the SFA anchors associated with the entity from a resolver; obtaining, by the SFAS orchestrator, the SFA records associated with the entity from an extractor using the SFA anchors; and performing, by the SFAS orchestrator, security actions using the SFA records.


