METHOD AND
SYSTEM TO ESTIMATE RISK FOR A
SOFTWARE APPLICATION DUE TO
QUANTUM THREAT Conventional risk
estimation techniques perform dynamic analysis of application or 5 use models which require training data. Present disclosure provides method and
system to estimate risk for a
software application due to
quantum threat by
static analysis. A set of records pertaining to the application is received and parsed to obtain application, crypto and platform parameters. In addition,
list of
quantum vulnerable algorithms, number of Qubits required to break a cryptographic
algorithm used by the application 10 and a current
Qubit number are also received. Then, value of
Quantum Day is determined based on the current
Qubit number and the number of Qubits required to break the cryptographic
algorithm used by the application. Further, SOD (Severity, Occurrence, Detection) scores are calculated for each parameter, and they are multiplied to determine Risk
Priority Number (RPN) for each parameter. Finally, RPNs 15 of all parameters are summed up to estimate overall risk of the application. [To be published with FIG. 3] 20 25 28 36 49 22 D ec 2 02 5 2 0 2 5 2 8 3 6 4 9 2 2 D e c 2 0 2 5 2 / 5 2 / 5 1. Populate Rules Rules and detection Recommendation APIsrepository
System Code parser PQC 2.Code Repo Host Risk 4.
List of APIs App Analyzer to be replaced, Code Modified Code Replacer App Testing 6. After testing is successful PQC App FIG. 2 20 25 28 36 49 22 D ec 2 02 5 D e c 2 0 2 5 R u l e s a n d d e t e c t i o n R e c o m m e n d a t i o n 2 0 2 5 2 8 3 6 4 9 2 2 A P I s P Q C H o s t A p p F I G . 2