Software Component Security Analysis via Tool Registry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Third-party software applications integrated with core products pose security vulnerabilities, risking financial, regulatory, and reputational damage to organizations, as many online marketplaces perform inadequate or no security analysis.

Innovation Solution

A method for adapting a security tool to perform security analysis on software applications by maintaining a registry of security tools, receiving code for the application, and generating tool-specific packages to analyze components for vulnerabilities, applicable to various database architectures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security analysis is performed on all software application components, then security reliability is improved, but analysis time and processing complexity increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the security analysis process by dividing software applications into individual components and matching each component with specific security tools from a registry. This segmentation allows parallel processing of multiple components simultaneously, reducing overall analysis time while maintaining comprehensive security coverage across all components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by maintaining a pre-configured registry of security tools with their specific component criteria before analysis begins. This pre-preparation eliminates the need to configure security tools during the analysis process, significantly reducing processing time while ensuring comprehensive security analysis is performed on all software components.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If a registry of security tools with component criteria is maintained, then security analysis precision is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity analysis precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified security tool registry that serves multiple functions: storing security tools, defining component criteria, enabling matching, and facilitating analysis. This single multi-functional system replaces what would otherwise require separate configurations for each security tool and component type, reducing overall system complexity while maintaining high analysis precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary matching mechanism that bridges security tools and software components through component criteria. This intermediary layer simplifies the system by providing a standardized interface for matching, eliminating the need for complex direct pairings between each security tool and every possible component type, thus reducing system complexity while preserving precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If tool-specific packages are generated for each component, then security coverage is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the generation of tool-specific packages with the component matching process itself. Rather than generating separate packages as a distinct step, the matching mechanism directly produces the appropriate security tool assignments as part of the analysis workflow. This integration reduces processing overhead while ensuring comprehensive security coverage through targeted tool-component pairings.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9507940B2Adapting a security tool for performing security analysis on a software application
Publication Date: 2016.11.29 SALESFORCE INC
  • US9507940B2 patent drawing
  • US9507940B2 patent drawing
  • US9507940B2 patent drawing

AI summary

A system and method for adapting a security tool for performing security analysis on a software application. In one embodiment, a method includes maintaining a registry of security tools; receiving code for a software application; and comparing component criteria for each security tool against each component of the software application, wherein the component criteria for each respective security tool indicate which components the respective security tool is designed to analyze for security vulnerabilities. The method also includes generating a tool-specific package for each component of the software application, wherein the tool-specific package comprises one or more security tools that are designed to analyze the respective component for security vulnerabilities.