Security Risk Identification via Code Metric Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security risk analysis models rely on historical statistical data and known coding risk factors, failing to detect potential security issues that have not been reported or identified, and only focus on individual code components, missing the holistic security posture of a system.
Innovation Solution
A system that receives source code and history information, divides it into security-related and non-related components, calculates security metrics based on version and defect history, and compares these metrics to generate a visual representation highlighting areas of concern, enabling targeted security improvements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security risk analysis models use historical statistical data and known coding risk factors, then they can identify reported defects and common risks, but they fail to detect potential security issues that have not been reported or identified
Solution Approach 1:
The patent applies preliminary action by performing security metric calculation and comparison before traditional defect detection. It calculates security metrics based on version control history and defect history, then compares these metrics to identify potential security issues before they are reported or identified by traditional models. This proactive approach enables detection of previously unknown security risks.
Solution Approach 2:
The patent introduces a new dimension for security analysis by using security metrics derived from version control history and defect history, rather than relying solely on historical statistical data and known coding risk factors. This dimensional change allows the system to detect security issues that traditional single-dimension approaches miss, thereby improving detection accuracy without losing information about potential risks.
2Measurement precision
If traditional models focus on individual code components, then they can analyze specific security issues, but they miss the holistic security posture of a system
Solution Approach 1:
The patent merges individual component security metrics with system-wide context by calculating security metrics for each code component based on version control history and defect history, then comparing these metrics to identify areas of concern. This combination preserves component-level analysis precision while simultaneously providing holistic system security posture, eliminating the information loss that occurs when focusing only on individual components.
Solution Approach 2:
The security metric comparison system serves multiple functions simultaneously: it performs component-level security analysis, identifies system-wide security patterns, and highlights areas of concern. This multi-functionality allows the system to maintain precise component-level analysis while also providing comprehensive system-wide security context, resolving the contradiction between focused analysis and holistic view.
3Measurement precision
If security analysis processes analyze all code components in detail, then they can identify all potential risks, but they require significant time and computational resources
Solution Approach 1:
The patent applies local quality by focusing security analysis resources on specific areas of concern identified through security metric comparison. Instead of analyzing all code components uniformly, the system calculates security metrics for each component, compares them to identify anomalies, and then concentrates detailed analysis on the highlighted areas. This approach maintains comprehensive security coverage while significantly reducing the time required by avoiding unnecessary detailed analysis of low-risk components.
Solution Approach 2:
The system performs partial action by initially calculating security metrics for all components to identify areas of concern, then performing more detailed analysis only on those specific areas. This two-stage approach provides comprehensive security coverage through the initial metric comparison while reducing overall analysis time by limiting detailed examination to only the necessary portions of the codebase.
Data Source
AI summary
An example system includes a processor to receive a source code and history information, wherein the history information includes a version control history or a defect history, or a combination of the version control history and the defect history. The processor is to also divide the source code into security-related components and security-non-related components. The processor is to further calculate security metrics for each of the security-related components and each of the security-non-related components based on the history information. The processor is also to compare the security metrics of the security-related components with the security metrics of the security-non-related components. The processor is to further generate a visual representation comprising a highlighted area of concern based on the comparison.


