Spacetime Graph for Continuous Code Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Secure by Design (SbD) tools and processes are manual, time-consuming, and inefficient, leading to security and compliance gaps in CI/CD environments due to the high frequency of material changes, which slows down software delivery and increases risk.

Innovation Solution

A system that continuously identifies material changes using Code Intelligence Analyzers, Developer Behavior Profilers, and Spacetime Graphs, with AI and machine learning to detect security and compliance issues, calculate risks, and prioritize changes, enabling adaptive code governance and automated workflows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual Secure by Design tools and processes are used for security and compliance reviews, then security assessment thoroughness is improved, but development speed and delivery efficiency deteriorate

Engineering Contradiction:
Improvesecurity assessment thoroughnessVSAvoiddevelopment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical review processes with automated AI-based analysis systems. The Code Intelligence Analyzers and machine learning models automatically perform security and compliance assessments on code commits, replacing the manual mechanical work of security architects while maintaining or improving assessment quality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service security assessment where the code analysis system automatically identifies material changes, performs risk assessments, and generates reports without requiring manual intervention from security architects for every commit. The system serves itself by continuously learning from code patterns and automatically adapting its analysis.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual security reviews are performed on every material change, then security coverage is improved, but time consumption and process efficiency worsen

Engineering Contradiction:
Improvesecurity coverageVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing security analysis only on material changes rather than every code commit. The Code Intelligence Analyzers use machine learning to identify which changes are significant enough to warrant security review, performing partial analysis on selected commits rather than exhaustive analysis on all code changes, thereby reducing time consumption while maintaining security coverage.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary security assessment automatically as part of the CI/CD pipeline before formal security reviews are needed. The automated analysis prepares risk assessments and identifies potential issues in advance, so when security architects do review code, the preliminary work has already been completed, reducing overall time consumption.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If frequent software releases are implemented to meet market requirements, then business growth and competitiveness are improved, but security and compliance gaps worsen

Engineering Contradiction:
Improvesoftware delivery frequencyVSAvoidsecurity and compliance assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements continuous security analysis that operates throughout the entire software development lifecycle, from initial commits through deployment. The Code Intelligence Analyzers continuously monitor code changes in real-time, providing ongoing security assurance rather than periodic checks, ensuring security is maintained even as release frequency increases.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system provides continuous feedback to developers and security architects about security risks in code commits. The automated analysis generates immediate feedback on potential security issues, allowing rapid correction before deployment. This feedback loop enables frequent releases while maintaining security standards through immediate identification and remediation of issues.

Inventive Principle:
Principle #23Feedback

4Reliability

If developers manually notify DevSecOps about material changes, then security review completeness is improved, but developer time and operational efficiency worsen

Engineering Contradiction:
Improvesecurity review completenessVSAvoiddeveloper workflow simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The Code Intelligence Analyzers perform self-service by automatically detecting material changes in code commits without requiring developer notification. The system autonomously analyzes code repositories, identifies significant changes using machine learning, and triggers security reviews automatically, eliminating the need for developers to manually notify DevSecOps teams.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides automated feedback to the development team about detected material changes and required security reviews. Instead of developers initiating notifications, the system monitors code changes and provides feedback about security implications, reversing the communication flow and simplifying developer workflow while maintaining review completeness.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11301356B2System, method, and process for continuously identifying material changes and calculating risk for applications and infrastructure
Publication Date: 2022.04.12 APIIRO LTD
  • US11301356B2 patent drawing
  • US11301356B2 patent drawing
  • US11301356B2 patent drawing

AI summary

A method and system for risk assessment of an application or infrastructure, includes: Code Intelligence Analyzers that scan historic code commits in code repositories of the application or infrastructure as well as real-time code commits; a Developer Behavior Profiler builds a behavior profile for each developer of the application, based, at least on the historic and real-time code commits and relevant issues in Issue Tracking Systems; and a Spacetime Graph, being a multidimensional graph detailing a current state of the application or infrastructure and a history of the code commits of the application or infrastructure, as determined by the Code Intelligence Analyzers and the Developer Behavior Profiler.