Software Risk Management via Segmented COTS Component Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IT infrastructures face challenges in estimating and managing security risks across multiple Commercial-Off-The-Shelf (COTS) software components, particularly due to unavailability of source code, outdated versions, and lack of support, leading to increased security vulnerabilities and risk exposure.

Innovation Solution

A risk management device computes security risk factors for software components, identifies components with high risk, activates compensating controls where available, and dynamically deploys continuous monitoring tools for components without available controls, to mitigate risks and monitor security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security risk estimation is performed for each COTS software component, then security risk management capability is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity risk managementVSAvoidrisk management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the software ensemble into individual COTS software components, assigning unique identifiers to each component. This segmentation enables targeted risk estimation at the component level rather than treating the entire software ensemble as a single unit, improving security risk management capability while managing complexity through modular assessment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary risk management device that acts as a mediator between the COTS software components and the enterprise stakeholders. This intermediary automatically collects component information, performs risk estimations, and presents aggregated results, reducing the complexity burden on both the components and the stakeholders while maintaining comprehensive security oversight

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If continuous monitoring tools are deployed for all high-risk software components, then security detection capability is improved, but resource consumption and operational complexity increase

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by deploying continuous monitoring tools selectively based on the specific risk factors and characteristics of each software component. Instead of uniform monitoring across all components, the system tailors monitoring intensity and type to the local risk profile of each component, improving detection capability where needed while reducing unnecessary complexity elsewhere

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by monitoring only the subset of high-risk software components that exceed predefined risk thresholds, rather than monitoring all components equally. This selective approach achieves sufficient security detection capability for the most critical components while avoiding the resource consumption and complexity associated with comprehensive monitoring of every component

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If compensating controls are activated for software components with available controls, then security risk mitigation is improved, but system complexity and control overhead increase

Engineering Contradiction:
Improvesecurity risk mitigationVSAvoidcontrol system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables self-service by designing the risk management system to automatically identify software components requiring compensating controls, select appropriate control mechanisms, and activate them without manual intervention. This automation reduces control overhead and simplifies the system by eliminating the need for manual assessment and implementation of compensating controls for each component

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10402570B2Method and device for software risk management within information technology (IT) infrastructure
Publication Date: 2019.09.03 WIPRO LTD
  • US10402570B2 patent drawing
  • US10402570B2 patent drawing
  • US10402570B2 patent drawing

AI summary

This disclosure relates to a method and device for software risk management within an IT infrastructure. The method includes computing security risk factors for a plurality of software components based on available executables for the plurality of software components. A set of software components are identified from the plurality of components, such that, a security risk factor for each of the set of software components is greater than a predefined threshold. Thereafter, a compensating control is activated for at least one of the set of software components, when a compensating control mechanism is available for each of the at least one software component and the compensating control mechanism satisfies control criteria. The method includes dynamically deploying at least one continuous monitoring tool satisfying monitoring criteria, to monitor each of at least one remaining software component, for which compensating control mechanism is not available, for a predefined duration.