IP Library Granted Patent US 10,318,740
Granted Patent B2
US 10,318,740 · App. 15/326,991 · Granted Jun 11, 2019

Security risk scoring of an application

Inventors: Yaniv Toledano (Yehud, IL); Tomer Gershoni (Yehud, IL)
Assignee: ENTIT SOFTWARE LLC
G06F21/577G06F21/552G06F21/56G06F21/606G06F21/6209H04L63/06G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,318,740
App. No.
15/326,991
Granted
Jun 11, 2019
Kind
B2
Abstract

In one implementation, a system for risk scoring a software application includes a component score engine to calculate an impact component score and a likelihood component score for a security vulnerability during development of the software application based on a plurality of scored descriptions of security risk elements for the software application. In addition, the system includes a total risk score engine to calculate a total security risk score for the software product application on the impact component score and the likelihood component score for the security vulnerability of the software application. In addition, the system includes a risk characterization engine to assign a risk characterization to the software product based on where the total risk score falls within a predetermined scale.

Claims (33)

1. A system, comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

calculate an impact component score and a likelihood component score for a security vulnerability during development of a software product based on a plurality of scored descriptions of security risk elements for the software product, the impact component score representing a potential impact of exploitation of the security vulnerability, the likelihood component score including a probability of occurrence of the exploitation of the security vulnerability, wherein the plurality of scored descriptions comprise a first scored description of a reproducibility of the security vulnerability, and a second scored description of a level of control ceded and a corresponding amount of damage of an integrity of an entity associated with the software product incurred by the exploitation of the security vulnerability;

calculate a total security risk score for the software product based on the impact component score and the likelihood component score for the security vulnerability of the software product; and

assign a risk characterization to the software product based on where the total risk score falls within a predetermined scale.

2. The system of claim 1 , wherein the instructions are executable on the processor to calculate the total security risk score for the software product by multiplying the impact component score by the likelihood component score.

3. The system of claim 2 , wherein the impact component score is a sum of a plurality of weighted segment scores associated with an impact component.

4. The system of claim 2 , wherein the likelihood component score is an arithmetic mean of a plurality of segment scores associated with a likelihood component.

5. The system of claim 1 , wherein the plurality of scored descriptions further comprise a scored description of a skill level associated with the exploitation of the security vulnerability.

6. The system of claim 1 , wherein the plurality of scored descriptions further comprise a scored description of a tenant or user affected by the exploitation of the security vulnerability.

7. The system of claim 1 , wherein the plurality of scored descriptions further comprise a scored description of accessibility of an attack surface of the software product for the exploitation of the security vulnerability.

8. A non-transitory computer readable medium storing instructions executable by a processing resource to cause a computer to:

calculate an impact component score and a likelihood component score of a security vulnerability of a software application based on a plurality of scored segments of a comprehensive security coverage framework, the impact component score representing a potential impact of exploitation of the security vulnerability, the likelihood component score including a probability of occurrence of the exploitation of the security vulnerability, wherein the plurality of scored segments comprise a reconstructing segment scored based on a description of a reproducibility of the security vulnerability, and an impact potential segment scored based on a description of a level of control ceded and a corresponding amount of damage of an integrity of an entity associated with the software application incurred by the exploitation of the security vulnerability;

calculate a total security risk score for the software application based on the impact component score and the likelihood component score for the security vulnerability of the software application; and

display a risk characterization of the software application determined based on where the total security risk score lies within a predetermined scale.

9. The non-transitory computer readable medium of claim 8 , wherein the impact potential segment is scored based on a description of a type and a sensitivity of data that could be improperly accessed by exploiting the security vulnerability.

10. The non-transitory computer readable medium of claim 8 , wherein the impact potential segment is scored based on a description of an impact of an exploitation of the security vulnerability on availability of the software application.

11. The non-transitory computer readable medium of claim 8 , wherein the plurality of scored segments further comprise an attack vectors segment scored based on a description of a skill level associated with an exploitation of the security vulnerability of the software application.

12. The non-transitory computer readable medium of claim 8 , wherein the plurality of scored segments further comprise an attack vectors segment scored based on a description of a level of access to exploit the security vulnerability of the software application.

13. The non-transitory computer readable medium of claim 8 , wherein the plurality of scored segments further comprise a coverage spread segment scored based on a description of at least one of a tenant and a user affected by an exploitation of the security vulnerability of the software application.

14. The non-transitory computer readable medium of claim 8 , wherein the plurality of scored segments further comprise an identify and exploit segment scored based on a description of a level of skill to identify the security vulnerability and a level of accessibility associated with a vulnerable surface of the software application.

15. A method performed by a system comprising a hardware processor, the method, comprising:

calculating an impact potential segment score, a reconstructing segment score, and an identify and exploit segment score for an exploit of a security vulnerability of a software product based on corresponding scored descriptions of security risk elements, the impact potential segment score based on a description of a type and a sensitivity of data that could be improperly accessed by the exploit of the security vulnerability, the reconstructing segment score based on a description of a reproducibility of the security vulnerability, and the identify and exploit segment score based on a description of a level of skill to identify the security vulnerability and a level of accessibility associated with a vulnerable surface of the software product;

calculating a total security risk score for the software product based on the impact potential segment score, the reconstructing segment score, and the identify and exploit segment score;

assigning a risk characterization to the software product based on where the total security risk score falls with a predetermined scale; and

comparing the risk characterization for the software product to a historical risk characterization.

16. The method of claim 15 , wherein scoring the impact potential segment score includes identifying as the impact potential segment score a greatest score associated with a portion of scored descriptions describing a confidentiality impact security risk element, an integrity impact security risk element, and an availability impact security risk element.

17. The method of claim 15 , wherein scoring the identify and exploit segment score includes calculating an arithmetic mean of scores associated with a portion of scored descriptions describing an attack skill level risk element and an access vector risk element.

18. The method of claim 15 , further comprising calculating an attack vectors segment score based on a description of a skill level associated with the exploit of the security vulnerability,

wherein the total security risk score is calculated further based on the attack vectors segment score.

19. The method of claim 15 , further comprising calculating a coverage spread segment score based on a description of a tenant or user affected by the exploit of the security vulnerability,

wherein the total security risk score is calculated further based on the coverage spread segment score.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2017
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 042368/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2017
From: TOLEDANO, YANIV; GERSHONI, TOMER
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 042186/0665 →
Continuity (1)
Related Publication 20170213037A1 · Jul 27, 2017
Cited By (2)
US 12,197,590 US 12,592,869