Security risk scoring of an application

US2017213037A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2017213037-A1
Application numberUS-201415326991-A
CountryUS
Kind codeA1
Filing dateJul 30, 2014
Priority dateJul 30, 2014
Publication dateJul 27, 2017
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In one implementation, a system for risk scoring a software application includes a component score engine to calculate an impact component score and a likelihood component score for a security vulnerability during development of the software application based on a plurality of scored descriptions of security risk elements for the software application. In addition, the system includes a total risk score engine to calculate a total security risk score for the software product application on the impact component score and the likelihood component score for the security vulnerability of the software application. In addition, the system includes a risk characterization engine to assign a risk characterization to the software product based on where the total risk score falls within a predetermined scale.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system, comprising: a component score engine to calculate an impact component score and a likelihood component score for a security vulnerability during development of a software application based on a plurality of scored descriptions of security risk elements for the software application; total risk score engine to calculate a total security risk score for the software product application on the impact component score and the likelihood component score for the security vulnerability of the software application; and a risk characterization engine to assign a risk characterization to the software product based on where the total risk score falls within a predetermined scale. 2 . The system of claim 1 , wherein the total risk score engine calculates a total security risk score for the software product by multiplying an impact component by a likelihood component. 3 . The system of claim 2 , wherein the impact component score is a sum of a plurality of weighted segment scores associated with the impact component. 4 . The system of claim 2 , wherein the likelihood component score is an arithmetic mean of a plurality of segment scores associated with the likelihood component. 5 . A non-transitory computer readable medium storing instructions executable by a processing resource to cause a computer to: calculate an impact component score and a likelihood component score of a security vulnerability of a software application based on a plurality of scored segments of a comprehensive security coverage framework; calculate a total security risk score for the software application based on the impact component score and the likelihood component score for the security risk of the software application; and display a risk characterization of the software application determined based on where the total security risk score lies within a predetermined scale. 6 . The non-transitory computer readable medium of claim 5 , wherein a scored segment of the plurality of scored segments is an impact potential segment, scored based on a description of a type and a sensitivity of data that could be improperly accessed by exploiting the security vulnerability. 7 . The non-transitory computer readable medium of claim 5 , wherein a scored segment of the plurality of scored segments is an impact potential segment, scored based on a description of a level of control ceded and a corresponding amount of integrity damage incurred by an exploitation of the security vulnerability. 8 . The non-transitory computer readable medium of claim 5 , wherein a scored segment of the plurality of scored segments is an impact potential segment, scored based on a description of an impact of an exploitation of the security vulnerability on availability of the software application. 9 . The non-transitory computer readable medium of claim 5 , wherein a scored segment of the plurality of scored segments is an attack vectors segment, scored based on a description of a skill level associated with an exploitation of the security vulnerability of the software product. 10 . The non-transitory computer readable medium of claim 5 , wherein a scored segment of the plurality of scored segments is an attack vectors segment, scored based on a description of a level of access to exploit the security vulnerability of the software application. 11 . The non-transitory computer readable medium of claim 5 , wherein a scored segment of the plurality of scored segments is a coverage spread segment, scored based on a description of at least one of a tenant and a user affected by an exploitation of the security vulnerability of the software application. 12 . The non-transitory computer readable medium of claim 5 , wherein a scored segment of the plurality of scored segments is an identify and exploit segment, scored based on a description. 13 . A method, comprising: calculating an impact potential segment score, a reconstructing segment score, an attack vectors segment score, a coverage spread segment score, and an identify and exploit segment score for an exploit of a security vulnerability of a software application based on corresponding scored descriptions of security risk elements; calculating a total security risk score for the software application based on the impact potential segment score, the reconstructing segment score, the attack vectors segment score, the coverage spread segment score, and the identify and exploit segment score; assigning a risk characterization to the software product based on where the total security risk score falls with a predetermined scale; and comparing the risk characterization for the software application to a historical risk characterization. 14 . The method of claim 13 , wherein scoring the impact potential segment score includes identifying as the impact potential segment score a greatest score associated with a portion of the scored descriptions describing a confidentiality impact security risk element, an integrity impact security risk element, and an availability impact security risk element. 15 . The method of claim 13 , wherein scoring the identify and exploit segment score includes calculating an arithmetic mean of scores associated with a portion of the scored descriptions describing an attack skill level risk element and an access vector risk element.

Assignees

Inventors

Classifications

  • Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

  • Test or assess software · CPC title

  • to a single file or object, e.g. in a secure envelope, encrypted and accessed using a key, or with access control rules appended to the object itself · CPC title

  • by securing the transmission between two devices or processes · CPC title

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2017213037A1 cover?
In one implementation, a system for risk scoring a software application includes a component score engine to calculate an impact component score and a likelihood component score for a security vulnerability during development of the software application based on a plurality of scored descriptions of security risk elements for the software application. In addition, the system includes a total ri…
Who is the assignee on this patent?
Hewlett Packard Entpr Dev Lp
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jul 27 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).