首页> 外国专利> Prioritizing security findings in a SAST tool based on historical security analysis

Prioritizing security findings in a SAST tool based on historical security analysis

机译:根据历史安全性分析对SAST工具中的安全性结果进行优先级排序

摘要

A cloud-based static analysis security tool accessible by a set of application development environments is augmented to provide for anonymous knowledge sharing to facilitate reducing security vulnerabilities. To the end, a crowdsourcing platform and social network are associated with the application development environments. Access to the social network platform by users of the application development environments is enabled. The anonymous access enables users to post messages without exposing sensitive data associated with a particular application development environment. As the static analysis security tool is used, a knowledgebase of information regarding identified security findings, fix priorities, and so forth, is continuously updated. Social network content (e.g., in the form of analytics, workflow recommendations, and the like) is then published from the knowledgebase to provide users with security knowledge generated by the tool from the set of application development environments. The approach provides for secure and anonymous cross-organization information sharing based, for example, on analytics generated by an analytics platform.
机译:一组应用程序开发环境可访问的基于云的静态分析安全工具得到了增强,以提供匿名知识共享,从而有助于减少安全漏洞。最后,将众包平台和社交网络与应用程序开发环境相关联。应用程序开发环境的用户可以访问社交网络平台。匿名访问使用户可以发布消息,而不会暴露与特定应用程序开发环境相关的敏感数据。当使用静态分析安全工具时,有关已识别安全发现,修复优先级等信息的知识库将不断更新。然后,从知识库发布社交网络内容(例如,以分析,工作流程推荐等形式),以向用户提供由工具从应用程序开发环境集中生成的安全知识。该方法例如基于由分析平台生成的分析来提供安全且匿名的跨组织信息共享。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号