IP Library › Granted Patent US 12,737,475
Granted Patent B2
US 12,737,475 · App. 18/340,550 · Granted Sep 15, 2026

Multi-granular elastic trust labeling framework for software delivery

Inventors: Kanchanjot Kaur Phokela (New Delhi, IN); Narendranath Sukhavasi (Nizamabad, IN); Kuntal Dey (Birbhum, IN); Kapil Singi (Bangalore, IN); Vikrant Kaulgud (Pune, IN); Adam Patten Burden (Tampa, FL)
Assignee: Accenture Global Solutions Limited
G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,475
App. No.
18/340,550
Granted
Sep 15, 2026
Kind
B2
Abstract

Systems and methods supporting discovery and quantification of vulnerabilities in software code are disclosed. The systems and methods provide functionality for using software code analysis and other types of tools to analyze the software code and determine whether it can be trusted. The software code tools may be able to discover various hidden issues in the software code and the outputs of such tools may be normalized to quantify the risk associated with vulnerabilities identified by the different tools. A labeling strategy is provided to label the software code to enable users to identify the best software among various available software options based on the label(s) and a set of criteria.

Claims (49)

1 . A method for identifying and quantifying software vulnerabilities, the method comprising:

monitoring, by one or more processors, development of software code, wherein the monitoring includes:

obtaining, by the one or more processors, a copy of the software code at one or more phases of the software code development;

evaluating, by the one or more processors, the software code using one or more software analysis tools, wherein each software analysis tool of the one or more software analysis tools is configured to output tool specific information associated with vulnerabilities identified in the software code;

determining, by the one or more processors, criteria for quantifying vulnerabilities of the software code;

identifying, by the one or more processors, vulnerabilities of the software code;

determining, by the one or more processors, a fit between the software and the criteria based at least in part on the identified vulnerabilities,

wherein determining the fit between the software and the criteria comprises software solution recommendation using graphical representation that represents the fit of software to a plurality of criteria with respect to corresponding axes, wherein a horizontal axis of the graphical representation corresponds to a first criterion that represents an ideal software solution of the software solution recommendation and a vertical axis of the graphical representation corresponds to a second criterion that represents a negative ideal software solution of the software solution recommendation;

generating, by the one or more processors, at least one label quantifying the fit between the software and the criteria; and

outputting, by the one or more processors, the label generated for the software code.

2 . The method of claim 1 , further comprising generating a model associated with the criteria.

3 . The method of claim 1 , wherein the label comprises a data structure.

4 . The method of claim 3 , wherein the data structure comprises a barcode or a quick response code.

5 . The method of claim 1 , wherein the at least one label comprises a plurality of labels, each label corresponding to a different portion of a software development lifecycle for the software code.

6 . The method of claim 1 , wherein the vulnerabilities identified using the one or more software analysis tools are associated with different severity ratings.

7 . The method of claim 6 , further comprising normalizing a severity rating of the identified vulnerabilities identified using the one or more software analysis tools.

8 . A system comprising:

a memory; and

one or more processors configured to:

monitor development of software code, wherein the monitoring includes:

obtaining, by the one or more processors, a copy of the software code at one or more phases of the software code development;

evaluate the software code using one or more software analysis tools, wherein each software analysis tool of the one or more software analysis tools is configured to output tool specific information associated with vulnerabilities identified in the software code;

determine criteria for quantifying vulnerabilities of the software code;

identify vulnerabilities of the software code;

determine a fit between the software and the criteria based at least in part on the identified vulnerabilities,

wherein determining the fit between the software and the criteria comprises software solution recommendation using graphical representation that represents the fit of software to a plurality of criteria with respect to corresponding axes, wherein a horizontal axis of the graphical representation corresponds to a first criterion that represents an ideal software solution of the software solution recommendation and a vertical axis of the graphical representation corresponds to a second criterion that represents a negative ideal software solution of the software solution recommendation;

generate at least one label quantifying the fit between the software and the criteria; and

output the label generated for the software code.

9 . The system of claim 8 , further comprising generating a model associated with the criteria.

10 . The system of claim 8 , wherein the label comprises a data structure.

11 . The system of claim 10 , wherein the data structure comprises a barcode or a quick response code.

12 . The system of claim 8 , wherein the at least one label comprises a plurality of labels, each label corresponding to a different portion of a software development lifecycle for the software code.

13 . The system of claim 8 , wherein the vulnerabilities identified using the one or more software analysis tools are associated with different severity ratings.

14 . The system of claim 13 , further comprising normalizing a severity rating of the identified vulnerabilities identified using the one or more software analysis tools.

15 . A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

monitoring development of software code, wherein the monitoring includes:

obtaining a copy of the software code at one or more phases of the software code development;

evaluating the software code using one or more software analysis tools, wherein each software analysis tool of the one or more software analysis tools is configured to output tool specific information associated with vulnerabilities identified in the software code;

determining criteria for quantifying vulnerabilities of the software code;

identifying vulnerabilities of the software code;

determining a fit between the software and the criteria based at least in part on the identified vulnerabilities,

wherein determining the fit between the software and the criteria comprises software solution recommendation using graphical representation that represents the fit of software to a plurality of criteria with respect to corresponding axes, wherein a horizontal axis of the graphical representation corresponds to a first criterion that represents an ideal software solution of the software solution recommendation and a vertical axis of the graphical representation corresponds to a second criterion that represents a negative ideal software solution of the software solution recommendation;

generating at least one label quantifying the fit between the software and the criteria; and

outputting the label generated for the software code.

16 . The non-transitory computer-readable medium of claim 15 , the operations further comprising generating a model associated with the criteria.

17 . The non-transitory computer-readable storage medium of claim 15 , wherein the label comprises a data structure.

18 . The non-transitory computer-readable storage medium of claim 15 , wherein the at least one label comprises a plurality of labels, each label corresponding to a different portion of a software development lifecycle for the software code.

19 . The non-transitory computer-readable storage medium of claim 15 , wherein the vulnerabilities identified using the one or more software analysis tools are associated with different severity ratings, the operations further comprising normalizing a severity rating of the identified vulnerabilities identified using the one or more software analysis tools.

20 . The non-transitory computer-readable storage medium of claim 19 , the operations further comprising calculating, based at least in part on the normalized severity ratings of the identified vulnerabilities, a distance ratio with respect to the software code, a positive ideal solution, and a negative ideal solution, wherein the at least one label is based at least in part on the distance ratio.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2024
From: PHOKELA, KANCHANJOT KAUR; SUKHAVASI, NARENDRANATH; DEY, KUNTAL; SINGI, KAPIL; KAULGUD, VIKRANT; BURDEN, ADAM PATTEN
To: ACCENTURE GLOBAL SOLUTIONS LIMITED
Reel/Frame 069240/0985 →
Priority Claims (1)
IN 202241036211 · Jun 23, 2022 · national
Continuity (1)
Related Publication 20230418952A1 · Dec 28, 2023
References Cited (25)
US 8392997B2 · Chen et al. · 2013 [cited by applicant]
US 9021584B2 · Zaitsev · 2015 [cited by applicant]
US 9965627B2 · Ray et al. · 2018 [cited by applicant]
US 9977905B2 · Li · 2018 [cited by applicant]
US 10721210B2 · Schiappa et al. · 2020 [cited by applicant]
US 10817604B1 · Kimball · 2020 [cited by examiner]
US 11080387B1 · Lattin · 2021 [cited by examiner]
US 11947946B1 · Rao · 2024 [cited by examiner]
US 20160248794A1 · Cam · 2016 [cited by examiner]
US 20190065032A1 · Lin · 2019 [cited by examiner]
US 20200285757A1 · Bhalla et al. · 2020 [cited by applicant]
US 20220108020A1 · Dang · 2022 [cited by examiner]
US 20230041068A1 · Starin · 2023 [cited by examiner]
US 20230367911A1 · Balber · 2023 [cited by examiner]
US 20240241963A1 · Wareus · 2024 [cited by examiner]
Sharma, R., Sibal, R., Sabharwal, S. (2019). Software Vulnerability Prioritization: A Comparative Study Using TOPSIS and VIKOR Techniques. In: Kapur, P., Klochkov, Y., Verma, A., Singh, G. (eds) System Performance and M… [cited by examiner]
Agarwal, M. et al., “Modeling Software Vulnerability Injection-Discovery Process Incorporating Time-Delay and VIKOR Based Ranking,” Reliability and Maintainability Assessment of Industrial Systems, Springer, Cham, 2022,… [cited by applicant]
Alsubaei, F. et al., “A framework for ranking IoMT solutions based on measuring security and privacy,” Proceedings of the Future Technologies Conference, Springer, Cham, 2018, pp. 205-224. [cited by applicant]
Baldini, G. et al., “Security certification and labelling in internet of things,” 2016 IEEE 3rd World Forum on Internet of Things (WF-IoT), IEEE, 2016, pp. 627-632. [cited by applicant]
Brucker, A. D. et al., “Modelling, validating, and ranking of secure service compositions,” Software: Practice and Experience, vol. 47, No. 12, 2017, pp. 1923-1943. [cited by applicant]
Gasiba, T. et al., “Ranking secure coding guidelines for software developer awareness training in the industry,” First International Computer Programming Education Conference (ICPEC 2020), Schloss Dagstuhl-Liebniz-Zentr… [cited by applicant]
Jimenez, M. et al., “The importance of accounting for real-world labelling when predicting software vulnerabilities,” Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Sympos… [cited by applicant]
Johnson, S. D. et al., “The impact of IoT security labelling on consumer product choice and willingness to pay,” PloS one, vol. 15, No. 1, 2020, 21 pages. [cited by applicant]
Wiseman, S. et al., “Adding security labelling to Windows NT,” Information Security Technical Report, vol. 3, No. 3, 1998, pp. 44-52. [cited by applicant]
Zoppi, T. et al., “Preseing the proper data to the crisis management operator: A relevance labelling strategy,” 2016 IEEE 17th International Symposium on High Assurance Systems Engineering (HASE), IEEE, 2016, pp. 228-23… [cited by applicant]