IP Library › Granted Patent US 12,566,867
Granted Patent B1
US 12,566,867 · App. 19/259,636 · Granted Mar 3, 2026

Adaptive selection of security scanning in software deployments

Inventors: Murali Krishna Segu (Yamare, IN); Shobha Rani Jagathpal (Bengaluru, IN); Sachin Sundar (Bengaluru, IN); Vinay Prakash (Bengaluru, IN)
Assignee: Morgan Stanley Services Group Inc.
G06F21/577G06F21/54
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,566,867
App. No.
19/259,636
Granted
Mar 3, 2026
Kind
B1
Abstract

Systems and methods for adaptive selection of security scanning in software deployments are disclosed. An embodiment of the present invention is directed to dynamically modifying scope based on specific code changes, third party risks and/or architectural changes. By selectively prioritizing and sequencing the scans, an embodiment of the present invention integrates language framework, third-party risks and design changes into a unified security scan workflow that optimizes efficiency while maintaining strong robust coverage.

Claims (39)

1 . A computer-implemented system comprising:

a computer server comprising one or more processors;

a memory component that stores and manages software development data; and

non-transitory memory comprising instructions that, when executed by the one or more processors, cause the one or more processors to:

initiate, via a software development pipeline, an update in a software application during a software development cycle;

detect, via a change evaluation processor, a change in the software application between the update and a prior version wherein the change is assigned a corresponding change type;

perform, via a contextual awareness processor, a contextual analysis for the detected change based on a potential impact of the change on the software application;

determine, via a risk assessment processor, a risk assessment based on the contextual analysis for the detected change;

generate, via a demand generator, a scan demand plan that comprises a set of scan tools from a pool of scan tools, comprising at least two scan tools, in a predetermined order to adaptively address the risk assessment, wherein the scan demand plan is based at least in part on resource optimization and comprises a dynamic chain of scan tools where each scan tool in the predetermined order is conditionally triggered based on results of a preceding scan tool, and wherein an output of a first scan tool is used to narrow or focus tasks for a subsequent scan tool;

apply, via an integration interface, the set of scan tools according to the predetermined order wherein the integration interface receives the scan demand plan from the demand generator and initiates and activates the set of scan tools;

receive, via a communication network, a set of results from each of the set of scan tools;

correlate the set of results in a manner that generates a composite result of vulnerabilities;

provide, via a communication network, the composite result of vulnerabilities; and

based upon the composite result of vulnerabilities, automating a response thereto comprising implementing a set of actions to address the vulnerabilities.

2 . The computer-implemented system of claim 1 , wherein the corresponding change type comprises one of: code change, design change, technology stack change, deployment change and configuration change.

3 . The computer-implemented system of claim 1 , wherein the contextual analysis is configurable to a specific entity.

4 . The computer-implemented system of claim 1 , wherein the contextual analysis is based on one or more rankings comprising: application asset ranking, infrastructure ranking, and business key services ranking.

5 . The computer-implemented system of claim 1 , wherein the risk assessment is based on security risk.

6 . The computer-implemented system of claim 1 , wherein the pool of scan tools comprises a plurality of tools that perform: static application security testing, dynamic application security testing, mobile application security testing, API scanning, design validation, penetration testing and logging.

7 . The computer-implemented system of claim 1 , wherein the pool of scan tools is configurable and specific to an entity.

8 . The computer-implemented system of claim 1 , wherein the change is detected at a PR stage or at a release stage within a continuous integration/continuous development pipeline.

9 . A computer-implemented method, comprising the steps of:

initiating, via a software development pipeline, an update in a software application during a software development cycle;

detecting, via a change evaluation processor, a change in the software application between the update and a prior version wherein the change is assigned a corresponding change type;

performing, via a contextual awareness processor, a contextual analysis for the detected change based on a potential impact of the change on the software application;

determining, via a risk assessment processor, a risk assessment based on the contextual analysis for the detected change;

generating, via a demand generator, a scan demand plan that comprises a set of scan tools from a pool of scan tools, comprising at least two scan tools, in a predetermined order to adaptively address the risk assessment, wherein the scan demand plan is based at least in part on resource optimization and comprises a dynamic chain of scan tools where each scan tool in the predetermined order is conditionally triggered based on results of a preceding scan tool, and wherein an output of a first scan tool is used to narrow or focus tasks for a subsequent scan tool;

applying, via an integration interface, the set of scan tools according to the predetermined order wherein the integration interface receives the scan demand plan from the demand generator and initiates and activates the set of scan tools;

receiving, via a communication network, a set of results from each of the set of scan tools;

correlating the set of results in a manner that generates a composite result of vulnerabilities;

providing, via a communication network, the composite result of vulnerabilities; and

based upon the composite result of vulnerabilities, automating a response thereto comprising implementing a set of actions to address the vulnerabilities.

10 . The computer-implemented method of claim 9 , wherein the corresponding change type comprises one of: code change, design change, technology stack change, deployment change and configuration change.

11 . The computer-implemented method of claim 9 , wherein the contextual analysis is configurable to a specific entity.

12 . The computer-implemented method of claim 9 , wherein the contextual analysis is based on one or more rankings comprising: application asset ranking, infrastructure ranking, and business key services ranking.

13 . The computer-implemented method of claim 9 , wherein the risk assessment is based on security risk.

14 . The computer-implemented method of claim 9 , wherein the pool of scan tools comprises a plurality of tools that perform: static application security testing, dynamic application security testing, mobile application security testing, API scanning, design validation, penetration testing and logging.

15 . The computer-implemented method of claim 9 , wherein the pool of scan tools is configurable and specific to an entity.

16 . The computer-implemented method of claim 9 , wherein the change is detected at a PR stage or at a release stage within a continuous integration/continuous development pipeline.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2025
From: SEGU, MURALI KRISHNA; JAGATHPAL, SHOBHA RANI; SUNDAR, SACHIN; PRAKASH, VINAY
To: MORGAN STANLEY SERVICES GROUP INC.
Reel/Frame 071605/0417 →
References Cited (31)
US 8001603B1 · Kennedy · 2011 [cited by applicant]
US 8555391B1 · Demir · 2013 [cited by examiner]
US 10110622B2 · Boia et al. · 2018 [cited by applicant]
US 20110209215A1 · Kabbara · 2011 [cited by applicant]
US 20130246135A1 · Wang · 2013 [cited by examiner]
US 20160134650A1 · Farmer et al. · 2016 [cited by applicant]
US 20160330219A1 · Hasan · 2016 [cited by examiner]
US 20180137279A1 · Peyton, Jr. et al. · 2018 [cited by applicant]
US 20180293386A1 · Barouni Ebrahimi et al. · 2018 [cited by applicant]
US 20180351989A1 · Nazir · 2018 [cited by applicant]
US 20190109833A1 · Segu et al. · 2019 [cited by applicant]
US 20200242859A1 · Merg · 2020 [cited by examiner]
US 20200404502A1 · Trivellato · 2020 [cited by examiner]
US 20210029154A1 · Picard · 2021 [cited by examiner]
US 20220353287A1 · Lekies et al. · 2022 [cited by applicant]
US 20230015603A1 · Smith · 2023 [cited by applicant]
US 20230205891A1 · Yellapragada · 2023 [cited by examiner]
US 20230222051A1 · Priyanka · 2023 [cited by examiner]
US 20230267918A1 · Abid · 2023 [cited by examiner]
US 20230334145A1 · Venkataraman et al. · 2023 [cited by applicant]
US 20240119159A1 · Navarro-Dimm et al. · 2024 [cited by applicant]
US 20240193276A1 · Grover · 2024 [cited by examiner]
US 20240241962A1 · Rowell et al. · 2024 [cited by applicant]
US 20250028840A1 · Zhang et al. · 2025 [cited by applicant]
US 20250055869A1 · Barel et al. · 2025 [cited by applicant]
CN 106130980A · 2016 [cited by examiner]
CN 116881923A · 2023 [cited by examiner]
JP 2022141966A · 2022 [cited by applicant]
WO WO0193031A1 · 2001 [cited by examiner]
Malzahn, Drew, Zachary Birnbaum, and Cimone Wright-Hamor. “Automated vulnerability testing via executable attack graphs.” In 2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Secu… [cited by examiner]
Polónio, João, José Moura, and Rui Neto Marinheiro. “On the road to proactive vulnerability analysis and mitigation leveraged by software defined networks: a systematic review.” IEEE Access (2024). (Year: 2024). [cited by examiner]