Software Package Security Scanning via Preliminary Anti-Action

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software package deployment technologies are inefficient and unreliable in verifying software packages for security vulnerabilities and compatibility, relying on manual processes that are costly in terms of time and resources, and fail to ensure compliance with user requirements.

Innovation Solution

A system that determines suitable software packages based on user requests and experience levels, scans for security vulnerabilities, and remotely deploys or recalls packages to ensure security and compatibility, using a processor and memory to analyze and manage software packages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual verification processes are used for software package deployment, then deployment can be performed with existing technologies, but the process is costly in terms of time, processing, and memory resources

Engineering Contradiction:
Improvedeployment verification efficiencyVSAvoidverification time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary security scanning and vulnerability detection on software packages before deployment. The security module scans packages for known vulnerabilities, checks for malicious code, and verifies integrity signatures in advance, so that vulnerable packages are identified and blocked before they can compromise the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security module as an intermediary component between the package manager and the deployed software. This security module acts as a mediator that automatically scans, analyzes, and verifies packages, replacing manual verification processes and reducing both time and resource costs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If current manual verification technologies are used, then existing deployment processes can be maintained, but security vulnerabilities in software packages cannot be reliably detected

Engineering Contradiction:
Improvesecurity vulnerability detection reliabilityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification system is segmented into distinct functional modules: a security module for vulnerability scanning, a package manager for deployment operations, and an integrity verification module for signature checking. This segmentation allows each module to specialize in specific tasks, improving detection reliability while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security module serves as an intermediary that automatically detects security vulnerabilities through scanning and analysis, providing reliable security verification without requiring complex manual processes. It mediates between the package manager and the software environment, automatically filtering out vulnerable packages.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If software packages are deployed without security scanning, then deployment speed is maintained, but unauthorized access and security threats cannot be prevented

Engineering Contradiction:
Improveunauthorized access riskVSAvoiddeployment speed
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

Security scanning and vulnerability detection are performed as preliminary actions before deployment. The security module scans packages for known vulnerabilities, checks for malicious code patterns, and verifies integrity signatures in advance, ensuring that security checks are completed before packages can cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by proactively identifying and blocking security threats before they can affect the system. The security module detects vulnerable packages and prevents their deployment, countering potential unauthorized access and security breaches before they occur.

Inventive Principle:
Principle #9Preliminary anti-action

4Reliability

If comprehensive security scanning is performed on all software packages, then security vulnerabilities can be detected, but processing and memory resources are consumed

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidprocessing and memory resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security scanning process applies local quality by focusing verification efforts on specific critical areas: known vulnerability patterns, malicious code signatures, and integrity checkpoints. Rather than uniformly analyzing every byte of every package, the system concentrates processing power on high-risk areas, reducing overall resource consumption while maintaining detection reliability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters by adjusting scanning depth and intensity based on package characteristics. For example, packages from trusted repositories may receive lighter verification, while unknown sources undergo more rigorous scanning. This dynamic parameter adjustment optimizes resource usage while maintaining security effectiveness.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11526617B2Information security system for identifying security threats in deployed software package
Publication Date: 2022.12.13 BANK OF AMERICA CORP
  • US11526617B2 patent drawing
  • US11526617B2 patent drawing
  • US11526617B2 patent drawing

AI summary

A system for detecting security threats in deployed software packages receives a request from a user to access software packages to perform a particular task. The system selects particular software packages based on an experience level of the user in performing the particular task. The system deploys the particular software packages to a computing device associated with the user. The system monitors the deployed software packages to determine whether a security vulnerability is introduced to the computing device by the deployed software packages. In response to determining that the security vulnerability is introduced to the computing device by the deployed software packages, the system recalls the deployed software packages by remotely uninstalling the deployed software packages from the computing device.