Trustware Security Risk Management for IT Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IT security techniques focus on securing individual software or hardware components independently, failing to assess and remediate security risks at a holistic level, particularly overlooking vulnerabilities in software applications that integrate multiple components, including external applications, and are ineffective in handling unknown or unversioned components.

Innovation Solution

A method and system that determine valid trustware components for security risk evaluation, correlate information across data repositories, generate a mapping list for test cases and environments, and trigger trustware security units for testing, sequencing and prioritizing test cases to cover all components, both individually and in integration, to identify and remediate security issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional techniques focus on securing individual software components independently, then the security of each component is improved, but the holistic security assessment of the entire IT system deteriorates

Engineering Contradiction:
Improvecomponent securityVSAvoidholistic security assessment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the IT system into distinct trustware components (software, hardware, firmware) and assesses each component's security independently through separate evaluation processes, while also evaluating their integrated security relationships. This segmentation allows for detailed component-level security analysis while maintaining the ability to assess holistic system security through defined interfaces and integration points.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If conventional techniques use data repositories of known vulnerabilities, then the detection of known issues is improved, but the detection of unknown or unversioned components deteriorates

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidhandling unknown components
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary identification and cataloging of all trustware components (software, hardware, firmware) before security assessment, including their versions, configurations, and relationships. This preliminary action enables the system to detect both known vulnerabilities through comparison with vulnerability databases and unknown components through comprehensive inventory and relationship mapping, ensuring no component is overlooked.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If conventional techniques focus on setting up environments for specific security testing activities, then the testing depth for specific components is improved, but the time and effort required deteriorates

Engineering Contradiction:
Improvetesting coverageVSAvoidenvironment provisioning time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent creates a universal security assessment framework that can evaluate multiple trustware components (software, hardware, firmware) and their integrations through a single standardized process. This multi-functional approach eliminates the need to provision separate testing environments for each component type, as the framework adapts to assess different component categories using common evaluation criteria and integrated test execution, significantly reducing setup time while maintaining comprehensive testing coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11675911B2System and method for managing security risk of information technology systems in an enterprise
Publication Date: 2023.06.13 WIPRO LTD
  • US11675911B2 patent drawing
  • US11675911B2 patent drawing
  • US11675911B2 patent drawing

AI summary

The disclosure relates to system and method for managing security risk of information technology (IT) systems in an enterprise. The method includes determining valid trustware components that need to be evaluated for security risk of an IT system within the enterprise; correlating information associated with each of the valid trustware components in a set of data repositories; generating a mapping list comprising the valid trustware components, test cases corresponding to each of the valid trustware components, and test environments corresponding to each of the valid trustware components based on the correlation; triggering trustware security units for testing the valid trustware components based on the mapping list; and identifying security issues associated with the valid trustware components based on the testing. The trustware security units are arranged in a sequential manner or a parallel manner to align with execution of the test cases corresponding to each of the valid trustware components.