Software Security Assessment Linking Static and Dynamic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software testing methods fail to effectively maintain links between software applications and their security test results, leading to valuable information about vulnerabilities and testing methodologies being unknown to users, and there is a need for a system that can produce and maintain these links throughout the software lifecycle.

Innovation Solution

A computer-implemented method and system that creates a programmatic association between security analysis test results and software applications, allowing users to access and review these results on demand, with periodic assessments and benchmarking capabilities, using a centralized database and testing engines for various vulnerability tests, and anonymizing techniques to share assessment data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security testing techniques are used to identify vulnerabilities, then security weaknesses can be detected, but the test results are decoupled from the software and become inaccessible to users throughout the software lifecycle

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidtest results accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent embeds security test results into the software application package during the build process, before deployment. This preliminary action ensures that security information is permanently associated with the software and remains accessible throughout its entire lifecycle, preventing the decoupling problem described in the contradiction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the security test results and embeds them within the software package itself. This copying approach ensures that the security information travels with the software to all deployment environments and remains accessible to users regardless of where the software is installed or executed.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive security analysis techniques are applied to all applications, then thorough vulnerability detection is achieved, but significant time and resources are consumed

Engineering Contradiction:
Improvevulnerability detection thoroughnessVSAvoidtesting duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements risk-based testing that applies different levels of security analysis to different applications based on their specific characteristics, sensitivity, and criticality. High-risk applications receive comprehensive analysis while lower-risk applications receive streamlined testing, optimizing the balance between thoroughness and resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically adjusts testing parameters such as test depth, analysis intensity, and resource allocation based on application-specific factors including sensitivity classification, criticality level, and risk profile. This allows the system to scale testing efforts appropriately rather than applying uniform comprehensive analysis to all applications.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If sensitive proprietary software is tested by external experts, then objective security assessment is obtained, but proprietary information security risks increase

Engineering Contradiction:
Improveassessment objectivityVSAvoidproprietary information exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure intermediary testing environment where external experts can perform objective security assessments without directly accessing the organization's internal proprietary systems. The testing is conducted in an isolated, controlled environment that prevents unauthorized data exfiltration while maintaining assessment objectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates isolated copies of the software for external testing purposes, allowing objective security assessment without exposing the original proprietary systems. The test copies are prepared in a controlled manner and the testing process is monitored to ensure proprietary information security while maintaining assessment integrity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11593492B2Assessment and analysis of software security flaws
Publication Date: 2023.02.28 VERACODE INC
  • US11593492B2 patent drawing
  • US11593492B2 patent drawing
  • US11593492B2 patent drawing

AI summary

At least a static analysis and a dynamic analysis to perform for a first software application are determined based, at least in part, on a profile of the first software application. The first software application is analyzed with the static analysis to generate static analysis results. The first software application is analyzed with dynamic analysis to generate dynamic analysis results. An assessment report is generated based on the static analysis results and the dynamic analysis results, wherein the assessment report indicates a security score of the first software application that is based, at least in part, on the static analysis results and the dynamic analysis results.