CA2930833A1

A system and method for implementing application policies among development environments

Abstract

In a system for facilitating distributed security and vulnerability testing of a software application, each development sandbox in a set of sandboxes receives a portion of the entire application, and the received portion may be tested based on an application-level security policy to obtain a pass/fail result. The portion of the application corresponding to a certain sandbox may be modified and rescanned (i.e., retested) until the modifications, i.e., development achieves functional and quality requirements, and a pass result is obtained. Thereafter, the scan results are promoted to a policy sandbox, where a compliance result for the entire software application can be obtained based on, at least in part, the promoted results. Other sandboxes may also perform their respective pass/fail testing using the promoted results, thus minimizing the need for synchronizing the code changes in different sandboxes before testing for security policy in any sandbox and/or during application-level scanning.

CA2930833A1, drawing sheet 1
Sheet 1 of 8

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

23 claims: 3 independent, 20 dependent

  1. 1
    CA 02930833 2016-05-16 WO 2015/077331 PCT/US2014/066400 What is claimed is:1. A method for facilitating distributed security and vulnerability testing of a software application, the method comprising: establishing application-level security policy parameters;distributing the application-level policy parameters to a policy sandbox;distributing portions of the application to a plurality of development sandboxes, each sandbox configured to permit further development of the portion of the application distributed thereto;testing in at least one sandbox the corresponding portion of the application, pursuant to the application-level security policy parameters via access to the policy sandbox;and updating the policy sandbox with test results from at least one of the plurality of development sandboxes.
  2. 11
    A system for facilitating distributed security and vulnerability testing of a software application, the system comprising:a memory comprising at least a portion of application-level security policy parameters;and a first processor coupled to the memory and configured to: provide a first development sandbox adapted to: (i) receive a first portion of the entire application, and (ii) at least one of compute and receive application test results, the first development sandbox permitting further development of the first portion of the application received therein;test the first portion of the application pursuant to at least a portion of the application-level security policy parameters, to obtain first sandbox test results;and update a policy sandbox with the first sandbox test results.
  3. 22
    An article of manufacture, comprising a non-transitory machine-readable medium storing instructions that, when executed by a machine comprising a memory and a processor in electronic communication with the memory, configure:the memory to store at least a portion of application-level security policy parameters;and the processor, for facilitating distributed security and vulnerability testing of a software application, to: provide a first development sandbox adapted to: (i) receive a first portion of the entire application, and (ii) at least one of compute and receive application test results, the first development sandbox permitting further development of the first portion of the application received therein;test the first portion of the application pursuant to at least a portion of the application-level security policy parameters, to obtain first sandbox test results;and CA 02930833 2016-05-16 WO 2015/077331 PCT/US2014/066400 update a policy sandbox with the first sandbox test results.