Multi-granular elastic trust labeling framework for software delivery
Systems and methods supporting discovery and quantification of vulnerabilities in software code are disclosed. The systems and methods provide functionality for using software code analysis and other types of tools to analyze the software code and determine whether it can be trusted. The software code tools may be able to discover various hidden issues in the software code and the outputs of such tools may be normalized to quantify the risk associated with vulnerabilities identified by the different tools. A labeling strategy is provided to label the software code to enable users to identify the best software among various available software options based on the label(s) and a set of criteria.
1 . A method for identifying and quantifying software vulnerabilities, the method comprising:
monitoring, by one or more processors, development of software code, wherein the monitoring includes:
obtaining, by the one or more processors, a copy of the software code at one or more phases of the software code development;
evaluating, by the one or more processors, the software code using one or more software analysis tools, wherein each software analysis tool of the one or more software analysis tools is configured to output tool specific information associated with vulnerabilities identified in the software code;
determining, by the one or more processors, criteria for quantifying vulnerabilities of the software code;
identifying, by the one or more processors, vulnerabilities of the software code;
determining, by the one or more processors, a fit between the software and the criteria based at least in part on the identified vulnerabilities,
wherein determining the fit between the software and the criteria comprises software solution recommendation using graphical representation that represents the fit of software to a plurality of criteria with respect to corresponding axes, wherein a horizontal axis of the graphical representation corresponds to a first criterion that represents an ideal software solution of the software solution recommendation and a vertical axis of the graphical representation corresponds to a second criterion that represents a negative ideal software solution of the software solution recommendation;
generating, by the one or more processors, at least one label quantifying the fit between the software and the criteria; and
outputting, by the one or more processors, the label generated for the software code.
2 . The method of claim 1 , further comprising generating a model associated with the criteria.
3 . The method of claim 1 , wherein the label comprises a data structure.
4 . The method of claim 3 , wherein the data structure comprises a barcode or a quick response code.
5 . The method of claim 1 , wherein the at least one label comprises a plurality of labels, each label corresponding to a different portion of a software development lifecycle for the software code.
6 . The method of claim 1 , wherein the vulnerabilities identified using the one or more software analysis tools are associated with different severity ratings.
7 . The method of claim 6 , further comprising normalizing a severity rating of the identified vulnerabilities identified using the one or more software analysis tools.
8 . A system comprising:
a memory; and
one or more processors configured to:
monitor development of software code, wherein the monitoring includes:
obtaining, by the one or more processors, a copy of the software code at one or more phases of the software code development;
evaluate the software code using one or more software analysis tools, wherein each software analysis tool of the one or more software analysis tools is configured to output tool specific information associated with vulnerabilities identified in the software code;
determine criteria for quantifying vulnerabilities of the software code;
identify vulnerabilities of the software code;
determine a fit between the software and the criteria based at least in part on the identified vulnerabilities,
wherein determining the fit between the software and the criteria comprises software solution recommendation using graphical representation that represents the fit of software to a plurality of criteria with respect to corresponding axes, wherein a horizontal axis of the graphical representation corresponds to a first criterion that represents an ideal software solution of the software solution recommendation and a vertical axis of the graphical representation corresponds to a second criterion that represents a negative ideal software solution of the software solution recommendation;
generate at least one label quantifying the fit between the software and the criteria; and
output the label generated for the software code.
9 . The system of claim 8 , further comprising generating a model associated with the criteria.
10 . The system of claim 8 , wherein the label comprises a data structure.
11 . The system of claim 10 , wherein the data structure comprises a barcode or a quick response code.
12 . The system of claim 8 , wherein the at least one label comprises a plurality of labels, each label corresponding to a different portion of a software development lifecycle for the software code.
13 . The system of claim 8 , wherein the vulnerabilities identified using the one or more software analysis tools are associated with different severity ratings.
14 . The system of claim 13 , further comprising normalizing a severity rating of the identified vulnerabilities identified using the one or more software analysis tools.
15 . A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
monitoring development of software code, wherein the monitoring includes:
obtaining a copy of the software code at one or more phases of the software code development;
evaluating the software code using one or more software analysis tools, wherein each software analysis tool of the one or more software analysis tools is configured to output tool specific information associated with vulnerabilities identified in the software code;
determining criteria for quantifying vulnerabilities of the software code;
identifying vulnerabilities of the software code;
determining a fit between the software and the criteria based at least in part on the identified vulnerabilities,
wherein determining the fit between the software and the criteria comprises software solution recommendation using graphical representation that represents the fit of software to a plurality of criteria with respect to corresponding axes, wherein a horizontal axis of the graphical representation corresponds to a first criterion that represents an ideal software solution of the software solution recommendation and a vertical axis of the graphical representation corresponds to a second criterion that represents a negative ideal software solution of the software solution recommendation;
generating at least one label quantifying the fit between the software and the criteria; and
outputting the label generated for the software code.
16 . The non-transitory computer-readable medium of claim 15 , the operations further comprising generating a model associated with the criteria.
17 . The non-transitory computer-readable storage medium of claim 15 , wherein the label comprises a data structure.
18 . The non-transitory computer-readable storage medium of claim 15 , wherein the at least one label comprises a plurality of labels, each label corresponding to a different portion of a software development lifecycle for the software code.
19 . The non-transitory computer-readable storage medium of claim 15 , wherein the vulnerabilities identified using the one or more software analysis tools are associated with different severity ratings, the operations further comprising normalizing a severity rating of the identified vulnerabilities identified using the one or more software analysis tools.
20 . The non-transitory computer-readable storage medium of claim 19 , the operations further comprising calculating, based at least in part on the normalized severity ratings of the identified vulnerabilities, a distance ratio with respect to the software code, a positive ideal solution, and a negative ideal solution, wherein the at least one label is based at least in part on the distance ratio.