The Software Security-by-Design (SSD) platform provides novel solutions for monitoring and optimizing the security of IoT software, during the overall software development lifecycle (SDLC). In particular, with respect to the Requirements and Design phases, the SSD platform assists software engineers in properly defining security requirements through novel security requirements specification, verification, and validation mechanisms that are based on natural language processing. It also provides an expert-based methodology for evaluating the extent to which an IoT software adheres to its originally imposed security requirements. As far as the Implementation and Testing phases are concerned, the SSD platform provides AI-based solutions for predicting the existence of vulnerabilities in the source code of the analyzed software and for providing high-level security metrics. Finally, it enables the broader validation of the security of an IoT software by considering the security analysis results produced by the aforementioned mechanisms, and the compliance of the software to relevant security standards. This validation can be used as the basis for future certification activities.
Addressing target audiences and expressing needs
- Collaboration
- Other type of Investment
Expanding to more markets / Finding potential customers
Commercial exploitation of the SSD platform in the form of a spin-off company
Bussiness partners – SMEs, Entrepreneurs, and Large Coorporations
- Research and Technology Organisations
- Academia/ Universities
- Private Investors
R&D, Technology and Innovation aspects
Currently, the SSD platform is in beta version, being validated in a real-world setting through dedicated use cases. Feedback from actual users of the SSD platform has been gathered and improvements will be applied based on this feedback in the next 6 months.
The SSD platform is a compilation of individual microservices that can be easily deployed as independent Docker Containers. Dedicated guides and instruction manuals have been prepared to further facilitate the deployment process. The SSD platform can operate both as an on-premise and as a cloud-based solution, eliminating in that way constraints that could restrain scalability.
The SSD platform is implemented as independent software-based modules (i.e., microservices), which can be easily deployed and used. The various features of the SSD platform utilize functionalities provided by open-source tools and frameworks, which are openly accessible to the broader public, enabling the potential replication of the proposed functionality and the reproduction of its results. The core features of the platform have been described in detail in a number of deliverables that are publicly available, further enhancing the transparency of the proposed solutions and allowing replication.
The SSD could follow a licensing scheme, in which all the modules of the platform could be installed locally on the premises of their users who would be responsible for their operation and maintenance, as well as a hybrid scheme, in which some of the modules (i.e., those that process security-sensitive information – e.g., source code) could be deployed locally and the rest could be hosted on the cloud. Hence, the microservice-oriented architecture of the SSD platform provides flexibility with respect to its deployment, as it can be hosted in a distributed manner.
The SSD platform aims at reducing the effort required for building secure IoT software, along with the overhead that is incurred by the adoption of security best practices and techniques during the software development lifecycle. In particular, it enables the users to define the security requirements in natural language (i.e., pure text) and the platform automatically turns them into formal descriptions, evaluates their correctness, and recommends improvements, tasks that would require a lot of manual effort by the engineers. In addition to this, the SSD platform provides mechanisms for automatically detecting vulnerabilities in software and for highlighting more abstract issues that the analyzed software may be prone to, as well as potentially vulnerable components. This enables the better prioritization of the testing and fortification efforts and the better allocation of the limited test resources.

