Security Risk Identification in Secure Software Lifecycle

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software developers face challenges in integrating security features into the software development lifecycle due to overwhelming security-related information, outdated security guidance, and a lack of timely and context-specific tools to identify and mitigate vulnerabilities, leading to increased risks of security breaches.

Innovation Solution

A system and method that integrates a security knowledge database with code scanners and a prioritization engine to generate a prioritized security requirements task list, applicable across all stages of the software lifecycle, identifying vulnerabilities and providing guidance for risk mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If developers use multiple security tools and repositories to ensure comprehensive security coverage, then security thoroughness is improved, but device complexity and ease of operation deteriorate due to overwhelming information and difficulty in navigation

Engineering Contradiction:
Improvesecurity thoroughnessVSAvoidtool and information complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the overwhelming security information and tools into a structured taxonomy organized by software lifecycle phases (requirements, design, development, testing, deployment, maintenance). This segmentation allows developers to navigate and access security guidance in manageable portions relevant to their current work phase, reducing complexity while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security guidance system that serves multiple functions: it provides security requirements, design guidance, coding standards, testing procedures, and maintenance recommendations all within a single integrated platform. This multi-functional approach eliminates the need for developers to navigate multiple separate repositories and tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If developers focus on detecting vulnerabilities after coding is complete, then security detection capability is improved, but productivity and time efficiency deteriorate due to costly and difficult post-coding fixes

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoiddevelopment time efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary security actions by providing security requirements and guidance documents that can be integrated into the software development process from the earliest stages. Security is built into requirements analysis, design, and coding phases before vulnerabilities can occur, making detection and prevention more efficient than post-coding remediation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes feedback mechanisms through automated security testing tools that provide real-time feedback during the development process. Security tests are integrated into the development workflow, allowing developers to receive immediate feedback on security issues and correct them while the code is still modifiable, improving both detection capability and development efficiency.

Inventive Principle:
Principle #23Feedback

3Reliability

If security guidance documents are updated frequently to reflect new technologies and vulnerabilities, then security relevance is improved, but loss of time and stability deteriorate due to constant changes and outdated information cycles

Engineering Contradiction:
Improvesecurity relevanceVSAvoidtime for updates and maintenance
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a dynamic security guidance system that automatically updates requirements and guidance documents in response to new vulnerabilities, threats, and technologies. The system monitors security landscapes and proactively updates relevant documentation, ensuring continuous relevance without requiring manual intervention or causing instability through frequent changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent ensures continuity of useful action by maintaining a continuously updated security knowledge base that evolves with the security landscape. The system provides ongoing security guidance throughout the entire software lifecycle, from initial requirements through maintenance, ensuring security relevance is maintained without time loss from updates.

Inventive Principle:
Principle #20Continuity of useful action

4Productivity

If requirements analysts focus on functional requirements without security expertise, then development speed is improved, but security quality deteriorates due to missed security opportunities

Engineering Contradiction:
Improvedevelopment speedVSAvoidsecurity quality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces security guidance documents and automated tools as intermediaries between requirements analysts and security requirements. These intermediaries provide security-specific templates, checklists, and guidance that enable non-security-expert analysts to accurately capture security requirements without slowing down the development process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters of requirement collection by providing security-specific templates and formats that guide analysts in capturing both functional and security requirements consistently. This standardization enables non-expert analysts to produce high-quality security requirements efficiently by following structured guidelines rather than relying on their security expertise.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11853430B2Security risk identification in a secure software lifecycle
Publication Date: 2023.12.26 SECURITY COMPASS TECH LTD
  • US11853430B2 patent drawing
  • US11853430B2 patent drawing
  • US11853430B2 patent drawing

AI summary

A system and method for security risk identification in a secure software lifecycle. A knowledge database has a plurality of security elements which are identified for a particular software application depending on software environment and prioritized in a task list. Code vulnerabilities are identified using code scanners, with security requirements updated based on identified vulnerabilities, lack of vulnerabilities for weaknesses covered by a code scanner, potential weaknesses not adequately covered by code scanners, and software environment changes.