Assessing risk of software commits to prioritize verification resources

US9946633B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9946633-B2
Application numberUS-201514947216-A
CountryUS
Kind codeB2
Filing dateNov 20, 2015
Priority dateSep 29, 2015
Publication dateApr 17, 2018
Grant dateApr 17, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer-implemented method and system for assessing risk of a software program and software updates to a program to prioritize verification resources, which includes receiving code for a software product for a testing assessment. The code is analyzed according to a risk assessment criteria, and the risk assessment criteria includes risk assessment factors. The risk assessment factors for the code are weighted as part of the criteria. A risk assessment score of the code is determined based on the criteria. Testing resources are allocated in response to the risk assessment score.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for assessing risk of a software program and software updates to a program to prioritize verification resources, comprising: receiving software code for a software product for a testing assessment; analyzing the code according to a risk assessment criteria, the risk assessment criteria includes risk assessment factors; selecting the risk assessment factors from a group consisting of: a complexity of change; a previous history of change; a functional area of code and its quality history; and a quality of the coder; evaluating an additional risk assessment factor of the risk assessment factors, the additional risk assessment factor includes determining when the software code includes a link directed to external software with respect to the software code, the external software including a daemon in a common operating system for running the software code and the external software, or a piece of external software running remotely, the piece of external software being run remotely and including one or more endpoints; determining when a change occurs to the link or external software; weighting the risk assessment factors for the code as part of the criteria, wherein the link or the external software of the additional risk assessment factor is considered an increased risk, and the endpoints being assigned respective sub-weights in the weighting of the risk assessment factors; determining a risk assessment score of the code based on the criteria, before running the testing assessment of the software code; and allocating testing resources for the testing assessment of the software code in response to the risk assessment score. 2. The method of claim 1 , wherein the code is an update to the software application. 3. The method of claim 2 , wherein an overall risk assessment score is computed for multiple code updates. 4. The method of claim 1 , wherein the risk assessment factors include: authors, reviewers, reviewing quality, testing coverage, complexity, code usage, and rate of updates. 5. The method of claim 1 , further comprising: adjusting allocated testing resources in response to the risk assessment score. 6. The method of claim 1 , further comprising: increasing allocated testing resources in response to a higher risk assessment score. 7. The method of claim 1 , further comprising: decreasing allocated testing resources in response to a lower risk assessment score. 8. The method of claim 1 , further comprising: receiving multiple code updates for the software application; analyzing each of the multiple code updates according to the risk assessment criteria; weighting the risk assessment factors for each of the code updates as part of the criteria; determining an overall risk assessment score for the multiple code updates based on the criteria; and allocating testing resources in response to the overall risk assessment score. 9. The method of claim 1 , wherein the allocating testing resources include: determining a first risk assessment threshold for allocating functional testing resources; determining a second risk assessment threshold for allocating regression testing; and determining a third risk assessment threshold for integration testing. 10. The method of claim 1 , further comprising: selecting the risk assessment factors from an additional group consisting of: modeled cross-component software links; a quality and a type of code review for a code change; a quality of a review and a reviewer; a test case coverage and quality of the test case; a frequency of changes in a functional area; a rate of change of a frequency of changes over a time period; and a caller count of a commit including an amount of functions called by a program changed by a code change.

Assignees

Inventors

Classifications

  • Test management · CPC title

  • using software metrics · CPC title

  • Updates (security arrangements therefor G06F21/57) · CPC title

  • Software maintenance or management · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9946633B2 cover?
A computer-implemented method and system for assessing risk of a software program and software updates to a program to prioritize verification resources, which includes receiving code for a software product for a testing assessment. The code is analyzed according to a risk assessment criteria, and the risk assessment criteria includes risk assessment factors. The risk assessment factors for the…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F11/3672. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 17 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).