Automated Security Testing via Attack-Architecture Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software applications face challenges in efficient, scalable, and repeatable security testing due to the difficulty in identifying and addressing various potential attacks, often requiring extensive resources and expertise, which can lead to insufficiently tested applications.

Innovation Solution

A system that determines an attack model with linked attack components, associates these with architectural components using attack tags, and generates attack test workflows to efficiently test software architectures, prioritizing test cases based on resources and objectives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If developers execute security tests using their extensive knowledge of the software application, then the testing is tailored to the specific application, but the developers may not be experts in application security testing

Engineering Contradiction:
Improveapplication-specific testing knowledgeVSAvoidsecurity testing expertise
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an automated security testing system that acts as an intermediary between developers and security testing expertise. The system includes a test generation module that automatically creates security test cases, a test execution module that runs the tests, and a result analysis module that interprets results. This intermediary system provides expert-level security testing capabilities without requiring developers to be security experts, while still being adapted to the specific application being tested.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If third-party security experts test specific software applications, then broad and extensive knowledge of potential threats is obtained, but the experts may not have a desired level of expertise with respect to a specific software application being tested

Engineering Contradiction:
Improvesecurity testing expertiseVSAvoidapplication-specific knowledge
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a self-service automated security testing system that generates, executes, and analyzes security tests without requiring external security experts. The system automatically analyzes the software application's code, architecture, and configuration to generate application-specific security test cases. This self-service approach eliminates the need for third-party experts while maintaining both security expertise and application-specific knowledge through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of manual security testing by experts with an automated computational system. The automated system uses software agents, algorithms, and computational methods to perform security testing functions that previously required human experts. This substitution maintains the benefits of expert knowledge while eliminating the drawbacks of requiring human experts to be available and adaptable to each specific application.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If all types of attacks are tested against the software application, then comprehensive security coverage is achieved, but it may be difficult or impossible to test all attacks given available resources

Engineering Contradiction:
Improvesecurity testing coverageVSAvoidtesting efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the comprehensive security testing process into distinct modular components: a test generation module that creates test cases, a test execution module that runs tests, and a result analysis module that interprets outcomes. Each module handles specific aspects of security testing independently. This segmentation allows the system to efficiently manage comprehensive testing by dividing it into manageable tasks that can be executed systematically within available resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically adjusts testing parameters such as test depth, attack vectors to test, and resource allocation based on the specific application being tested and available resources. The system analyzes the application's characteristics and automatically configures the testing scope and intensity, changing parameters to optimize the balance between comprehensive coverage and resource efficiency for each testing engagement.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If security testing spans the entire development life cycle from design through deployment, then thorough security validation is achieved, but the time and resources required increase significantly

Engineering Contradiction:
Improvesecurity testing thoroughnessVSAvoidtesting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary security testing actions early in the development life cycle, during the design and coding phases. The automated system can analyze code as it is written and generate security test cases before deployment. This preliminary action allows security testing to be integrated into the development flow rather than added as a separate time-consuming phase, achieving thorough validation while minimizing time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous automated security testing that operates throughout the entire development life cycle without interruption. The system continuously monitors code changes, automatically generates updated test cases, and executes tests as development progresses. This continuous action eliminates the need for separate, time-consuming testing phases and maintains security validation throughout development, achieving thoroughness without proportional time increase.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9483648B2Security testing for software applications
Publication Date: 2016.11.01 SAP SE
  • US9483648B2 patent drawing
  • US9483648B2 patent drawing
  • US9483648B2 patent drawing

AI summary

A mapping engine may be used to determine an attack model enumerating software attacks, the software attacks being represented by linked attack components, and may be used to determine a software architecture to be tested, the software architecture being represented by linked architectural components in an architecture diagram. The mapping engine may then associate each attack component and each architectural component with at least one attack tag characterizing attack requirements. A global test plan generator may be used to determine an attack test model, including associating attack components with corresponding architectural components, based on associated attack tags, and may thus generate attack test workflows from the attack test model, to thereby test the software architecture.