首页> 外国专利> METHODS AND SYSTEMS FOR REDUCING FALSE POSITIVE FINDINGS

METHODS AND SYSTEMS FOR REDUCING FALSE POSITIVE FINDINGS

机译:减少假阳性结果的方法和系统

摘要

A system for validating software security analysis findings includes a non-transitory computer readable medium and a processor. The non-transitory computer readable medium stores a source truth dataset including criteria for validating characteristics of findings. The processor receives a finding from a software security analysis tool that performs scan on application code. The processor identifies a characteristic from the finding. The processor selects a criterion from the non-transitory computer readable medium for validating the identified characteristic. The processor determines a validity score for the finding based on whether the selected criterion is met. The processor determines whether the finding is false positive by comparing the validity score to a predetermined validity threshold. If the finding is true positive, a graphical user interface displays the finding.
机译:用于验证软件安全性分析结果的系统包括非暂时性计算机可读介质和处理器。非暂时性计算机可读介质存储源真实数据集,该源真实数据集包括用于验证发现的特征的标准。处理器从软件安全分析工具接收对应用程序代码进行扫描的发现。处理器从发现中识别出特征。处理器从非暂时性计算机可读介质中选择标准以验证所标识的特征。处理器基于是否满足所选标准来确定发现的有效性分数。处理器通过将有效性得分与预定有效性阈值进行比较来确定发现是否为假阳性。如果结果为真阳性,则图形用户界面将显示结果。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号