Software Asset Health Scoring for Lifecycle Security Risks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software asset management systems lack effective methods to assess and mitigate security risks and vulnerabilities across the software development lifecycle, particularly in industries handling confidential information.

Innovation Solution

A computing system that utilizes an AI/ML engine to compute a health score based on various attributes of software assets, including context, operating environment, criticality, and developer factors, to predict security risks and proactively implement remediation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional software asset management processes are used, then the SDLC/ALM framework can be maintained, but security risks and vulnerabilities cannot be effectively assessed or mitigated in real-time

Engineering Contradiction:
Improvesecurity risk assessment capabilityVSAvoidtime for vulnerability remediation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting and analyzing software asset attributes (code quality, security compliance, technical debt) before vulnerabilities manifest into critical issues. The health score computation proactively identifies assets at risk, enabling preemptive remediation rather than reactive response after breaches occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where software asset attributes are constantly monitored, health scores are computed and updated in real-time, and remediation actions are triggered based on threshold breaches. This closed-loop feedback mechanism enables dynamic adjustment of security postures and prioritization of remediation efforts based on current asset health states.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive security assessments are performed across all software assets, then security risk detection improves, but system complexity and computational resources increase

Engineering Contradiction:
Improvesecurity risk detection accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the comprehensive security assessment task into discrete, manageable components by evaluating individual software asset attributes (code quality metrics, security compliance indicators, technical debt measures) separately. Each attribute is scored independently, and these segmented scores are aggregated into an overall health score, making the complex assessment process modular and scalable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms the complex security assessment problem into a parameter-based health score model. Multiple qualitative and quantitative parameters (attribute values, weights, thresholds) are defined and manipulated to convert diverse security metrics into a unified health score metric, simplifying the complexity of comprehensive security evaluation into a standardized scoring framework.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If real-time health score computation is implemented, then security risk prediction capability improves, but computational resources and processing time increase

Engineering Contradiction:
Improvesecurity remediation efficiencyVSAvoidcomputational resource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by computing health scores selectively based on priority levels and threshold breaches rather than continuously re-evaluating all assets at maximum frequency. Remediation actions are triggered only when health scores cross predefined thresholds, avoiding excessive computational processing while maintaining effective security monitoring and response capabilities.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12417288B1Software asset health score
Publication Date: 2025.09.16 WELLS FARGO BANK NA
  • US12417288B1 patent drawing
  • US12417288B1 patent drawing
  • US12417288B1 patent drawing

AI summary

Techniques are described for assessing the health of one or more applications. For example, this disclosure describes a computing device configured to obtain information associated with one or more software assets, wherein the information associated with one or more software assets comprises information associated with a lifecycle of the one or more software assets. The computing device is also configured to compute, based on at least a portion of the information associated with the one or more software assets, a health score that indicates a security risk of the one or more software assets. The computing device is further configured to perform an action based on the health score.