Software Risk Evaluation System for Unlicensed Software Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software management tools are inadequate for actively evaluating and controlling software risks on computer systems, as they cannot analyze or manage risks of unlicensed or cracked software, leading to potential security threats.

Innovation Solution

A software risk evaluation system that scans computer systems for installed software, obtains a risk management file, sets and adjusts risk levels based on software asset management data, and generates a risk evaluation report to help administrators identify and mitigate potential risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If software management tools only search for existing software names on a management list, then the tools can find known problems, but they cannot analyze and control risks of unlisted software such as unlicensed or cracked software

Engineering Contradiction:
Improvesoftware risk detection capabilityVSAvoidsoftware management coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary scanning of computer systems to obtain software installation lists before risk evaluation is needed. It pre-establishes a software risk management file with risk levels for different software, allowing proactive identification of high-risk software rather than waiting for problems to occur. This preliminary action enables the system to detect unlisted software and assess its risk level in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a software risk management file as an intermediary data structure that bridges the gap between simple software inventory and comprehensive risk analysis. This file contains software names, versions, and pre-assigned risk levels, serving as a reference that enables the system to evaluate risks of both listed and unlisted software. The intermediary file allows the system to extend its detection capability beyond the original management list.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software administrators manually audit installed software, then they can identify compliance issues, but it creates a heavy burden and is too late when risks occur

Engineering Contradiction:
Improvesoftware compliance assuranceVSAvoidrisk response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automated risk evaluation by scanning computer systems and automatically comparing installed software against the software risk management file. The system independently identifies high-risk software, generates risk evaluation reports, and provides recommendations without requiring manual administrator intervention for each audit. This automation maintains high reliability in compliance assurance while eliminating the time loss associated with manual processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where risk evaluation results are automatically generated and fed back to administrators. The system monitors software installations, evaluates risks, and provides ongoing feedback through reports that highlight compliance issues and high-risk software. This continuous feedback mechanism ensures timely detection and response to risks without requiring periodic manual audits.

Inventive Principle:
Principle #23Feedback

3Reliability

If the system evaluates risk levels for all software, then comprehensive risk control is achieved, but the complexity of risk management increases

Engineering Contradiction:
Improvesoftware risk controlVSAvoidrisk management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by assigning different risk levels to different software based on their specific characteristics. Instead of treating all software uniformly, the system evaluates each software individually and assigns appropriate risk levels from the software risk management file. High-risk software receives more attention and stricter controls, while low-risk software requires minimal intervention. This differentiated approach achieves comprehensive risk control without uniformly increasing system complexity across all software.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system manages complexity by changing the parameter of risk level assignment dynamically. The software risk management file contains pre-defined risk levels that can be adjusted based on software characteristics, organizational policies, and risk tolerance. The system modifies risk level parameters automatically based on scan results and organizational requirements, allowing flexible risk control without hardcoding complex management rules for every software scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10614209B2Software risk evaluation system and method thereof
Publication Date: 2020.04.07 QUANTA COMPUTER INC
  • US10614209B2 patent drawing
  • US10614209B2 patent drawing
  • US10614209B2 patent drawing

AI summary

A software risk evaluation system and method thereof are provided. The software risk evaluation system includes a computer system and a server. The computer system executes a software risk evaluation program to perform the steps of: scanning the computer system to obtain a software installation list of software installed on the computer system; obtaining a software risk management file from the server; setting a risk level for each software on the software installation list according to the software risk management file; adjusting the risk level of each software on the software installation list according to software asset management data and the software risk management file; and generating a software risk evaluation report according to the adjusted risk level of each software on the software installation list.