Invention Grant
- Patent Title: Methods and systems for reducing false positive findings
-
Application No.: US16551563Application Date: 2019-08-26
-
Publication No.: US10929543B2Publication Date: 2021-02-23
- Inventor: Adam Youngberg , David Filbey , Kishore Prabakaran Fernando
- Applicant: Capital One Services, LLC
- Applicant Address: US VA McLean
- Assignee: Capital One Services, LLC
- Current Assignee: Capital One Services, LLC
- Current Assignee Address: US VA McLean
- Agency: Troutman Pepper Hamilton Sanders LLP
- Agent Christopher J. Forstner; John A. Morrissett
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F11/36 ; G06F21/56

Abstract:
A system for validating software security analysis findings includes a non-transitory computer readable medium and a processor. The non-transitory computer readable medium stores a source truth dataset including criteria for validating characteristics of findings. The processor receives a finding from a software security analysis tool that performs scan on application code. The processor identifies a characteristic from the finding. The processor selects a criterion from the non-transitory computer readable medium for validating the identified characteristic. The processor determines a validity score for the finding based on whether the selected criterion is met. The processor determines whether the finding is false positive by comparing the validity score to a predetermined validity threshold. If the finding is true positive, a graphical user interface displays the finding.
Information query