首页> 外国专利> System and method for implementing application policies across development environments

System and method for implementing application policies across development environments

机译:在整个开发环境中实施应用程序策略的系统和方法

摘要

Method to facilitate a distributed analysis of the security and vulnerability of a software application, the method comprising: setting security policy parameters at the application level; distribute the policy settings at the application level to a policy sandbox; distribute portions of the application to a plurality of development sandboxes, each sandbox being configured to allow further development of the portion of the application distributed to it, where the plurality of development sandboxes: (i) corresponds to a Analysis ID; and (ii) comprises a first development sandbox, the first development sandbox corresponding to a first portion of the application; analyze, in at least one development sandbox, the corresponding portion of the application, in accordance with the application-level security policy parameters by accessing the policy sandbox, where the analysis of the first application portion comprises : (a) obtain first results of analysis of the development sandbox by analyzing in a first iteration at least the first portion of the application; (b) computing a first difference between the first development sandbox analysis results and the application analysis results that are associated with the analysis ID; (c) obtain a first assessment by evaluating the policy defect constraints based, at least in part, on the first difference; (d) if the evaluation fails: (A) obtain second development sandbox analysis results for the first development sandbox by analyzing the first portion of the application in a second iteration; (B) calculating a second difference between the second development sandbox analysis results and at least one between the application analysis results associated with the analysis ID and the first development sandbox analysis results; and (C) obtain a second assessment by evaluating the policy defect constraints based, at least in part, on the second difference; updating the policy sandbox with the analysis results of at least one of the plurality of development sandboxes; where updating comprises: (e) promoting, in the policy sandbox, the first development sandbox analysis results if the first evaluation completes successfully, or the second development sandbox analysis results if the second evaluation completes successfully.
机译:促进对软件应用程序的安全性和漏洞进行分布式分析的方法,该方法包括:在应用程序级别设置安全策略参数;将应用程序级别的策略设置分发到策略沙箱;将应用程序的部分分发到多个开发沙箱,每个沙箱配置为允许进一步开发分发给它的应用程序部分,其中多个开发沙箱:(i)对应于分析ID; (ii)包括第一开发沙箱,该第一开发沙箱对应于应用程序的第一部分;通过访问策略沙箱,根据应用级安全策略参数,在至少一个开发沙箱中分析应用的相应部分,其中,对第一应用部分的分析包括:(a)获得分析的第一结果通过在第一迭代中至少分析应用程序的第一部分来对开发沙箱进行分析; (b)计算第一开发沙箱分析结果与与分析ID相关联的应用分析结果之间的第一差异; (c)通过至少部分基于第一差异评估策略缺陷约束条件来获得第一评估; (d)如果评估失败:(A)通过在第二次迭代中分析应用程序的第一部分,获得第一开发沙箱的第二开发沙箱分析结果; (B)计算第二开发沙箱分析结果与与分析ID相关联的应用分析结果与第一开发沙箱分析结果中的至少一个之间的第二差; (C)通过至少部分地基于第二差异评估策略缺陷约束来获得第二评估;用多个开发沙箱中至少一个的分析结果更新策略沙箱;其中更新包括:(e)如果第一评估成功完成,则在策略沙箱中推广第一开发沙盒分析结果,或者如果第二评估成功,则提升第二开发沙盒分析结果。

著录项

  • 公开/公告号ES2767049T3

    专利类型

  • 公开/公告日2020-06-16

    原文格式PDF

  • 申请/专利权人 VERACODE INC.;

    申请/专利号ES14810074T

  • 发明设计人 CHESTNA PETER;

    申请日2014-11-19

  • 分类号G06F21/57;G06F11/36;G06F21/53;

  • 国家 ES

  • 入库时间 2022-08-21 11:15:21

获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号