Software Risk Management via Segmented COTS Component Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IT infrastructures face challenges in estimating and managing security risks across multiple Commercial-Off-The-Shelf (COTS) software components, particularly due to unavailability of source code, outdated versions, and lack of support, leading to increased security vulnerabilities and risk exposure.
Innovation Solution
A risk management device computes security risk factors for software components, identifies components with high risk, activates compensating controls where available, and dynamically deploys continuous monitoring tools for components without available controls, to mitigate risks and monitor security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security risk estimation is performed for each COTS software component, then security risk management capability is improved, but system complexity and computational overhead increase
Solution Approach 1:
The patent segments the software ensemble into individual COTS software components, assigning unique identifiers to each component. This segmentation enables targeted risk estimation at the component level rather than treating the entire software ensemble as a single unit, improving security risk management capability while managing complexity through modular assessment
Solution Approach 2:
The patent introduces an intermediary risk management device that acts as a mediator between the COTS software components and the enterprise stakeholders. This intermediary automatically collects component information, performs risk estimations, and presents aggregated results, reducing the complexity burden on both the components and the stakeholders while maintaining comprehensive security oversight
2Measurement precision
If continuous monitoring tools are deployed for all high-risk software components, then security detection capability is improved, but resource consumption and operational complexity increase
Solution Approach 1:
The patent applies local quality by deploying continuous monitoring tools selectively based on the specific risk factors and characteristics of each software component. Instead of uniform monitoring across all components, the system tailors monitoring intensity and type to the local risk profile of each component, improving detection capability where needed while reducing unnecessary complexity elsewhere
Solution Approach 2:
The patent implements partial action by monitoring only the subset of high-risk software components that exceed predefined risk thresholds, rather than monitoring all components equally. This selective approach achieves sufficient security detection capability for the most critical components while avoiding the resource consumption and complexity associated with comprehensive monitoring of every component
3Reliability
If compensating controls are activated for software components with available controls, then security risk mitigation is improved, but system complexity and control overhead increase
Solution Approach 1:
The patent enables self-service by designing the risk management system to automatically identify software components requiring compensating controls, select appropriate control mechanisms, and activate them without manual intervention. This automation reduces control overhead and simplifies the system by eliminating the need for manual assessment and implementation of compensating controls for each component
Data Source
AI summary
This disclosure relates to a method and device for software risk management within an IT infrastructure. The method includes computing security risk factors for a plurality of software components based on available executables for the plurality of software components. A set of software components are identified from the plurality of components, such that, a security risk factor for each of the set of software components is greater than a predefined threshold. Thereafter, a compensating control is activated for at least one of the set of software components, when a compensating control mechanism is available for each of the at least one software component and the compensating control mechanism satisfies control criteria. The method includes dynamically deploying at least one continuous monitoring tool satisfying monitoring criteria, to monitor each of at least one remaining software component, for which compensating control mechanism is not available, for a predefined duration.


