Spacetime Graph for Continuous Code Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Secure by Design (SbD) tools and processes are manual, time-consuming, and inefficient, leading to security and compliance gaps in CI/CD environments due to the high frequency of material changes, which slows down software delivery and increases risk.
Innovation Solution
A system that continuously identifies material changes using Code Intelligence Analyzers, Developer Behavior Profilers, and Spacetime Graphs, with AI and machine learning to detect security and compliance issues, calculate risks, and prioritize changes, enabling adaptive code governance and automated workflows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual Secure by Design tools and processes are used for security and compliance reviews, then security assessment thoroughness is improved, but development speed and delivery efficiency deteriorate
Solution Approach 1:
The patent replaces manual mechanical review processes with automated AI-based analysis systems. The Code Intelligence Analyzers and machine learning models automatically perform security and compliance assessments on code commits, replacing the manual mechanical work of security architects while maintaining or improving assessment quality.
Solution Approach 2:
The system enables self-service security assessment where the code analysis system automatically identifies material changes, performs risk assessments, and generates reports without requiring manual intervention from security architects for every commit. The system serves itself by continuously learning from code patterns and automatically adapting its analysis.
2Reliability
If manual security reviews are performed on every material change, then security coverage is improved, but time consumption and process efficiency worsen
Solution Approach 1:
The patent applies partial action by focusing security analysis only on material changes rather than every code commit. The Code Intelligence Analyzers use machine learning to identify which changes are significant enough to warrant security review, performing partial analysis on selected commits rather than exhaustive analysis on all code changes, thereby reducing time consumption while maintaining security coverage.
Solution Approach 2:
The system performs preliminary security assessment automatically as part of the CI/CD pipeline before formal security reviews are needed. The automated analysis prepares risk assessments and identifies potential issues in advance, so when security architects do review code, the preliminary work has already been completed, reducing overall time consumption.
3Productivity
If frequent software releases are implemented to meet market requirements, then business growth and competitiveness are improved, but security and compliance gaps worsen
Solution Approach 1:
The patent implements continuous security analysis that operates throughout the entire software development lifecycle, from initial commits through deployment. The Code Intelligence Analyzers continuously monitor code changes in real-time, providing ongoing security assurance rather than periodic checks, ensuring security is maintained even as release frequency increases.
Solution Approach 2:
The system provides continuous feedback to developers and security architects about security risks in code commits. The automated analysis generates immediate feedback on potential security issues, allowing rapid correction before deployment. This feedback loop enables frequent releases while maintaining security standards through immediate identification and remediation of issues.
4Reliability
If developers manually notify DevSecOps about material changes, then security review completeness is improved, but developer time and operational efficiency worsen
Solution Approach 1:
The Code Intelligence Analyzers perform self-service by automatically detecting material changes in code commits without requiring developer notification. The system autonomously analyzes code repositories, identifies significant changes using machine learning, and triggers security reviews automatically, eliminating the need for developers to manually notify DevSecOps teams.
Solution Approach 2:
The system provides automated feedback to the development team about detected material changes and required security reviews. Instead of developers initiating notifications, the system monitors code changes and provides feedback about security implications, reversing the communication flow and simplifying developer workflow while maintaining review completeness.
Data Source
AI summary
A method and system for risk assessment of an application or infrastructure, includes: Code Intelligence Analyzers that scan historic code commits in code repositories of the application or infrastructure as well as real-time code commits; a Developer Behavior Profiler builds a behavior profile for each developer of the application, based, at least on the historic and real-time code commits and relevant issues in Issue Tracking Systems; and a Spacetime Graph, being a multidimensional graph detailing a current state of the application or infrastructure and a history of the code commits of the application or infrastructure, as determined by the Code Intelligence Analyzers and the Developer Behavior Profiler.


