Software Security Assessment Linking Static and Dynamic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software testing methods fail to effectively maintain links between software applications and their security test results, leading to valuable information about vulnerabilities and testing methodologies being unknown to users, and there is a need for a system that can produce and maintain these links throughout the software lifecycle.
Innovation Solution
A computer-implemented method and system that creates a programmatic association between security analysis test results and software applications, allowing users to access and review these results on demand, with periodic assessments and benchmarking capabilities, using a centralized database and testing engines for various vulnerability tests, and anonymizing techniques to share assessment data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security testing techniques are used to identify vulnerabilities, then security weaknesses can be detected, but the test results are decoupled from the software and become inaccessible to users throughout the software lifecycle
Solution Approach 1:
The patent embeds security test results into the software application package during the build process, before deployment. This preliminary action ensures that security information is permanently associated with the software and remains accessible throughout its entire lifecycle, preventing the decoupling problem described in the contradiction.
Solution Approach 2:
The patent creates a copy of the security test results and embeds them within the software package itself. This copying approach ensures that the security information travels with the software to all deployment environments and remains accessible to users regardless of where the software is installed or executed.
2Reliability
If comprehensive security analysis techniques are applied to all applications, then thorough vulnerability detection is achieved, but significant time and resources are consumed
Solution Approach 1:
The patent implements risk-based testing that applies different levels of security analysis to different applications based on their specific characteristics, sensitivity, and criticality. High-risk applications receive comprehensive analysis while lower-risk applications receive streamlined testing, optimizing the balance between thoroughness and resource consumption.
Solution Approach 2:
The patent dynamically adjusts testing parameters such as test depth, analysis intensity, and resource allocation based on application-specific factors including sensitivity classification, criticality level, and risk profile. This allows the system to scale testing efforts appropriately rather than applying uniform comprehensive analysis to all applications.
3Reliability
If sensitive proprietary software is tested by external experts, then objective security assessment is obtained, but proprietary information security risks increase
Solution Approach 1:
The patent introduces a secure intermediary testing environment where external experts can perform objective security assessments without directly accessing the organization's internal proprietary systems. The testing is conducted in an isolated, controlled environment that prevents unauthorized data exfiltration while maintaining assessment objectivity.
Solution Approach 2:
The patent creates isolated copies of the software for external testing purposes, allowing objective security assessment without exposing the original proprietary systems. The test copies are prepared in a controlled manner and the testing process is monitored to ensure proprietary information security while maintaining assessment integrity.
Data Source
AI summary
At least a static analysis and a dynamic analysis to perform for a first software application are determined based, at least in part, on a profile of the first software application. The first software application is analyzed with the static analysis to generate static analysis results. The first software application is analyzed with dynamic analysis to generate dynamic analysis results. An assessment report is generated based on the static analysis results and the dynamic analysis results, wherein the assessment report indicates a security score of the first software application that is based, at least in part, on the static analysis results and the dynamic analysis results.


