ARTIFICIAL INTELLIGENCE BASED SECURITY REQUIREMENTS IDENTIFICATION AND TESTING

    公开(公告)号:US20240037243A1

    公开(公告)日:2024-02-01

    申请号:US17876425

    申请日:2022-07-28

    IPC分类号: G06F21/57 G06F40/279

    摘要: The proposed systems and methods apply natural language processing to identify implicit security requirements flowing from input text narratively describing desired features for a software project. These systems and methods can identify hidden security requirements that may not be readily apparent from the features described in the input text. For example, a story may include a feature of a return URL (Uniform Resource Locator), which is the URL for the website to which a user will be redirected. A security vulnerability that would not be obvious from this feature is that a user might be directed to an attacker controlled site instead of the originally intended site. A security requirement that could counteract this vulnerability would be to include the feature of verifying all redirects go to Whitelisted Sites. The proposed systems and methods provide a framework for automated security requirements analysis capable of identifying unstated security requirements early on in a software development lifecycle using artificial intelligence techniques.