Invention Grant
- Patent Title: Automated secure software development management, risk assessment, and risk remediation
-
Application No.: US15856618Application Date: 2017-12-28
-
Publication No.: US10740469B2Publication Date: 2020-08-11
- Inventor: Erkang Zheng , Jason Kao , Bingrong He
- Applicant: FMR LLC
- Applicant Address: US MA Boston
- Assignee: FMR LLC
- Current Assignee: FMR LLC
- Current Assignee Address: US MA Boston
- Agency: Proskauer Rose LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; H04L29/06 ; G06F21/57 ; G06F8/70 ; G06F8/60 ; G06Q10/06 ; G06F8/41 ; G06F8/10

Abstract:
Methods and apparatuses are described for automated secure software development management, risk assessment and risk remediation. A server generates security requirements for a software application under development based upon a plurality of technical attributes and a threat model. The server creates a first set of development tasks based upon the generated security requirements. The server scans source code to identify one or more security vulnerabilities and creates a second set of development tasks based upon the identified vulnerabilities. The server generates a security risk score based upon the generated security requirements and the identified vulnerabilities. The server deploys the software application under development to a production computing system upon determining that the security risk score satisfies a criterion. The server generates security findings based upon operation of the software application after being deployed to the production computing system, and creates a third set of development tasks based upon the findings.
Public/Granted literature
- US20190205542A1 AUTOMATED SECURE SOFTWARE DEVELOPMENT MANAGEMENT, RISK ASSESSMENT, AND RISK REMEDIATION Public/Granted day:2019-07-04
Information query