IP Library Granted Patent US 10,706,156
Granted Patent B2
US 10,706,156 · App. 15/784,072 · Granted Jul 7, 2020

Security risk identification in a secure software lifecycle

Inventors: Nishchal Bhalla (Mississauga, CA); Rohit Kumar Sethi (Toronto, CA); Ramanan Sivaranjan (Toronto, CA); Ehsan Foroughi (Toronto, CA); Geoffrey Charles Whittington (Waterloo, CA)
G06F21/577G06F21/55G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,706,156
App. No.
15/784,072
Filed
Oct 13, 2017
Granted
Jul 7, 2020
Kind
B2
Art Unit
2432
USPC
726/25
Abstract

A system and method for security risk identification in a secure software lifecycle. A knowledge database has a plurality of security elements which are identified for a particular software application depending on software environment and prioritized in a task list. Code vulnerabilities are identified using code scanners, with security requirements updated based on identified vulnerabilities, lack of vulnerabilities for weaknesses covered by a code scanner, potential weaknesses not adequately covered by code scanners, and software environment changes.

Claims (43)

1. A method for identifying security risks in a software application, the method comprising:

identifying a software context relating to the environment of the software application; selecting a customized set of security requirements for development or maintenance of the software application based on the software context and specific to the software application being developed or maintained, the security requirements selected from a security knowledge database comprising security elements;

generating a prioritized task list comprising the customized set of selected security requirements, each of the security requirements comprising instructions to address the security requirement;

scanning code of the software application with at least one security assessment code scanner;

mapping any code vulnerabilities found by the at least one security assessment code scanner with at least one security requirement in the prioritized task list;

evaluating the ability of the security assessment code scanner to identify security risks particular to the software application under scrutiny based on the software context by identifying a likelihood of a false negative result of the code scanning;

indicating a confidence level of risk identification of at least one of the selected security requirements based on capability of the code scanner to verify a compliance state of the mapped security requirement and identifying vulnerabilities not identified by the at least one security assessment code scanner; and

updating any security requirements in the prioritized task list for which the at least one security assessment code scanner is incapable of verifying a compliance state to indicate an unverified compliance state.

2. The method of claim 1 , further comprising identifying at least one security requirement that is inadequately found by the at least one security assessment code scanner.

3. The method of claim 1 , further comprising:

validating that a security requirement has been remediated with the instructions to address the security requirement; and updating the task list.

4. The method of claim 1 , wherein the environment of the software application is one or more of a coding environment and a system environment.

5. The method of claim 1 , wherein the at least one security assessment code scanner is one or more of a static application security testing tool, dynamic application security testing tool, interactive application security testing scanners, runtime application security protection scanner, and an Application Vulnerability Correlation (AVC) tool.

6. The method of claim 1 , further comprising scanning code of the software application with a plurality of security assessment code scanners, each of the plurality of security assessment code scanners selected from one or more of a static application security testing tool, dynamic application security testing tool, interactive application security testing scanners, runtime application security protection scanner, and an Application Vulnerability Correlation (AVC) tool.

7. The method of claim 1 , further comprising:

identifying a new security requirement for the software application;

scanning the software code of the software application;

determining if the new security requirement is adequately identified by the code scanner;

prioritizing the new security requirement; and

updating the task list based on identification of the new security requirement.

8. The method of claim 1 , further comprising generating a standards report identifying each security requirement of the software application and how each security requirement has been met.

9. The method of claim 1 , wherein the database of security elements comprises regulatory elements.

10. The method of claim 1 , further comprising prioritizing the security requirements based on one or more of security risk and capability of the code scanner to identify a code vulnerability associated with a particular security requirement.

11. The method of claim 1 , further comprising regenerating the prioritized task list by updating at least one of the selected security requirements.

12. The method of claim 1 , wherein the code scanner identifies at least one software context relating to the environment of the software application.

13. A computing device comprising a processor and a memory coupled to the processor, wherein the processor is configured to execute programmed instructions stored in the memory to:

identify a software context relating to the environment of a software application;

select a customized set of security requirements for development or maintenance of the software application based on the software context and specific to the software application being developed or maintained, the security requirements selected from a security knowledge database comprising security elements;

generate a prioritized task list comprising the customized set of selected security requirements, each of the security requirements comprising instructions to address the security requirement;

scan code of the software application with at least one security assessment code scanner;

map any code vulnerabilities found by the at least one security assessment code scanner with at least one security requirement in the prioritized task list;

evaluate the ability of the security assessment code scanner to identify security risks particular to the software application under scrutiny based on the software context by identifying a likelihood of a false negative result of the code scan;

indicate a confidence level of risk identification of at least one of the selected security requirements based on capability of the code scanner to verify a compliance state of the mapped security requirement and identify vulnerabilities not identified by the at least one security assessment code scanner; and

update any security requirements in the prioritized task list for which the at least one security assessment code scanner is incapable of verifying a compliance state to indicate an unverified compliance state.

14. A non-transitory computer-readable storage medium having one or more instructions thereon for identifying software application vulnerabilities during a software lifecycle, the instructions when executed by a processor causing the processor to:

identify a software context relating to the environment of the software application;

select a customized set of security requirements for development or maintenance of the software application based on the software context and specific to the software application being developed or maintained, the security requirements selected from a database of security elements;

generate a prioritized task list comprising the customized set of selected security requirements, each of the security requirements comprising instructions to address the security requirement;

scan code of the software application with at least one security assessment code scanner;

map any code vulnerabilities found by the at least one security assessment code scanner with at least one security requirement in the prioritized task list;

evaluate the ability of the security assessment code scanner to identify security risks particular to the software application under scrutiny based on the software context by identifying a likelihood of a false negative result of the code scan;

indicate a confidence level of risk identification of at least one of the selected security requirements based on capability of the code scanner to verify a compliance state of the mapped security requirement and identify vulnerabilities not identified by the at least one security assessment code scanner; and

update any security requirements in the prioritized task list for which the at least one security assessment code scanner is incapable of verifying a compliance state to indicate an unverified compliance state.

Assignments (5)
MERGER AND CHANGE OF NAME Recorded Mar 15, 2022
From: 1230604 BC LTD.; SECURITY COMPASS TECHNOLOGIES LTD.
To: SECURITY COMPASS TECHNOLOGIES LTD.
Reel/Frame 059366/0972 →
SECURITY INTEREST Recorded Oct 29, 2020
From: 1230604 B.C. LTD.
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 054207/0838 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2020
From: SD ELEMENTS INC.
To: 1230604 BC LTD
Reel/Frame 052206/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2019
From: 2509757 ONTARIO INC.
To: SD ELEMENTS INC.
Reel/Frame 051050/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2019
From: BHALLA, NISHCHAL; SETHI, ROHIT KUMAR; SIVARANJAN, RAMANAN; FOROUGHI, EHSAN; WHITTINGTON, GEOFFREY CHARLES
To: 2509757 ONTARIO INC.
Reel/Frame 048760/0121 →
Continuity (1)
Related Publication 20190114435A1 · Apr 18, 2019
Cited By (4)
US 12,423,444 US 12,468,584 US 12,518,018 US 12,645,804