Software Risk Evaluation System for Unlicensed Software Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software management tools are inadequate for actively evaluating and controlling software risks on computer systems, as they cannot analyze or manage risks of unlicensed or cracked software, leading to potential security threats.
Innovation Solution
A software risk evaluation system that scans computer systems for installed software, obtains a risk management file, sets and adjusts risk levels based on software asset management data, and generates a risk evaluation report to help administrators identify and mitigate potential risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If software management tools only search for existing software names on a management list, then the tools can find known problems, but they cannot analyze and control risks of unlisted software such as unlicensed or cracked software
Solution Approach 1:
The system performs preliminary scanning of computer systems to obtain software installation lists before risk evaluation is needed. It pre-establishes a software risk management file with risk levels for different software, allowing proactive identification of high-risk software rather than waiting for problems to occur. This preliminary action enables the system to detect unlisted software and assess its risk level in advance.
Solution Approach 2:
The patent introduces a software risk management file as an intermediary data structure that bridges the gap between simple software inventory and comprehensive risk analysis. This file contains software names, versions, and pre-assigned risk levels, serving as a reference that enables the system to evaluate risks of both listed and unlisted software. The intermediary file allows the system to extend its detection capability beyond the original management list.
2Reliability
If software administrators manually audit installed software, then they can identify compliance issues, but it creates a heavy burden and is too late when risks occur
Solution Approach 1:
The system enables self-service automated risk evaluation by scanning computer systems and automatically comparing installed software against the software risk management file. The system independently identifies high-risk software, generates risk evaluation reports, and provides recommendations without requiring manual administrator intervention for each audit. This automation maintains high reliability in compliance assurance while eliminating the time loss associated with manual processes.
Solution Approach 2:
The system implements continuous feedback loops where risk evaluation results are automatically generated and fed back to administrators. The system monitors software installations, evaluates risks, and provides ongoing feedback through reports that highlight compliance issues and high-risk software. This continuous feedback mechanism ensures timely detection and response to risks without requiring periodic manual audits.
3Reliability
If the system evaluates risk levels for all software, then comprehensive risk control is achieved, but the complexity of risk management increases
Solution Approach 1:
The system applies local quality by assigning different risk levels to different software based on their specific characteristics. Instead of treating all software uniformly, the system evaluates each software individually and assigns appropriate risk levels from the software risk management file. High-risk software receives more attention and stricter controls, while low-risk software requires minimal intervention. This differentiated approach achieves comprehensive risk control without uniformly increasing system complexity across all software.
Solution Approach 2:
The system manages complexity by changing the parameter of risk level assignment dynamically. The software risk management file contains pre-defined risk levels that can be adjusted based on software characteristics, organizational policies, and risk tolerance. The system modifies risk level parameters automatically based on scan results and organizational requirements, allowing flexible risk control without hardcoding complex management rules for every software scenario.
Data Source
AI summary
A software risk evaluation system and method thereof are provided. The software risk evaluation system includes a computer system and a server. The computer system executes a software risk evaluation program to perform the steps of: scanning the computer system to obtain a software installation list of software installed on the computer system; obtaining a software risk management file from the server; setting a risk level for each software on the software installation list according to the software risk management file; adjusting the risk level of each software on the software installation list according to software asset management data and the software risk management file; and generating a software risk evaluation report according to the adjusted risk level of each software on the software installation list.


