首页> 外国专利> AUTOMATED SECURE SOFTWARE DEVELOPMENT MANAGEMENT, RISK ASSESSMENT, AND RISK REMEDIATION

AUTOMATED SECURE SOFTWARE DEVELOPMENT MANAGEMENT, RISK ASSESSMENT, AND RISK REMEDIATION

机译:自动化安全软件开发管理,风险评估和风险补救

摘要

Methods and apparatuses are described for automated secure software development management, risk assessment and risk remediation. A server generates security requirements for a software application under development based upon a plurality of technical attributes and a threat model. The server creates a first set of development tasks based upon the generated security requirements. The server scans source code to identify one or more security vulnerabilities and creates a second set of development tasks based upon the identified vulnerabilities. The server generates a security risk score based upon the generated security requirements and the identified vulnerabilities. The server deploys the software application under development to a production computing system upon determining that the security risk score satisfies a criterion. The server generates security findings based upon operation of the software application after being deployed to the production computing system, and creates a third set of development tasks based upon the findings.
机译:描述了用于自动化安全软件开发管理,风险评估和风险补救的方法和装置。服务器基于多个技术属性和威胁模型为正在开发的软件应用程序生成安全要求。服务器根据生成的安全性要求创建第一组开发任务。服务器扫描源代码以识别一个或多个安全漏洞,并根据识别出的漏洞创建第二组开发任务。服务器根据生成的安全要求和已识别的漏洞来生成安全风险评分。一旦确定安全风险评分满足标准,服务器就将开发中的软件应用程序部署到生产计算系统。服务器在部署到生产计算系统后,将根据软件应用程序的操作生成安全性发现,并根据发现来创建第三组开发任务。

著录项

  • 公开/公告号US2019205542A1

    专利类型

  • 公开/公告日2019-07-04

    原文格式PDF

  • 申请/专利权人 FMR LLC;

    申请/专利号US201715856618

  • 发明设计人 JASON KAO;BINGRONG HE;ERKANG ZHENG;

    申请日2017-12-28

  • 分类号G06F21/57;G06F8/70;G06F8/60;G06F8/10;G06F8/41;G06Q10/06;

  • 国家 US

  • 入库时间 2022-08-21 12:06:21

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号