Installer Package Information Aggregation for Security Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are unable to fully assess the changes an installer package makes to their computer prior to installation, and there is a risk of inadvertently installing malicious software when installing software applications.
Innovation Solution
A computer-implemented method that detects an installation and provides the user with information about the installer package, including its components and changes, by communicating with an information server that aggregates data from multiple endpoints, allowing the user to make informed decisions before proceeding with the installation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If installer package information is not provided to users prior to installation, then the installation process remains simple and quick, but users cannot assess the changes or risks associated with the installation
Solution Approach 1:
The system performs preliminary actions by gathering installer package information from multiple sources (vendor websites, security databases, user feedback) and storing it in a database before the user actually installs the software. This allows the information to be ready and available when the user needs to make an informed decision, without delaying the installation process itself.
Solution Approach 2:
An intermediary system (the information server and database) is introduced between the installer package and the user. This intermediary collects, processes, and presents installer package information in a user-friendly format, allowing users to assess risks without directly interacting with the raw installer data or delaying the installation process.
2Reliability
If installer package information is collected from multiple endpoints and aggregated, then comprehensive security information becomes available, but the system complexity increases
Solution Approach 1:
The system segments the information gathering function into independent components distributed across multiple endpoints. Each endpoint independently collects installer package information from local sources, and these segmented data pieces are then aggregated at the information server to form a comprehensive security assessment.
Solution Approach 2:
The system enables self-service by allowing each endpoint to automatically contribute its own installer package information to the collective database without requiring manual configuration or centralized management. The distributed nature of the system allows each node to serve itself while contributing to the overall security information pool.
3Object-affected harmful factors
If users are presented with detailed installer package information prior to installation, then user awareness and safety improve, but the installation time increases
Solution Approach 1:
The system applies partial action by presenting only the most relevant installer package information to users (such as security risks, required system changes, and vendor reputation) rather than displaying all available data. This selective presentation approach maintains user awareness while minimizing the time required to review information before installation.
Data Source
AI summary
Installer package information is presented to a user in response to an attempted installation of an application on an endpoint. The attempted installation is detected and the installer package is identified to an information server. The installer package may be identified using a hash key or other unique identifier. In response, the information server provides to the endpoint information associated with the identified installer package based on information received from a plurality of other endpoints. The endpoint may also provide installation and application information related to the installer package to the information server. In one embodiment, when the information server obtains more than the threshold amount of information for an installer package, the information server may analyze the information and provide the analysis to requesting endpoints. The analysis may include the risk or performance impact of the installer package, or the category or functionality of the application.


