首页> 外国专利> METHOD AND DEVICE FOR SOFTWARE RISK MANAGEMENT WITHIN INFORMATION TECHNOLOGY (IT) INFRASTRUCTURE

METHOD AND DEVICE FOR SOFTWARE RISK MANAGEMENT WITHIN INFORMATION TECHNOLOGY (IT) INFRASTRUCTURE

机译:信息技术(IT)基础架构内软件风险管理的方法和设备

摘要

This disclosure relates to a method and device for software risk management within an IT infrastructure. The method includes computing security risk factors for a plurality of software components based on available executables for the plurality of software components. A set of software components are identified from the plurality of components, such that, a security risk factor for each of the set of software components is greater than a predefined threshold. Thereafter, a compensating control is activated for at least one of the set of software components, when a compensating control mechanism is available for each of the at least one software component and the compensating control mechanism satisfies control criteria. The method includes dynamically deploying at least one continuous monitoring tool satisfying monitoring criteria, to monitor each of at least one remaining software component, for which compensating control mechanism is not available, for a predefined duration.
机译:本公开涉及用于IT基础设施内的软件风险管理的方法和设备。该方法包括基于用于多个软件组件的可用可执行文件来计算用于多个软件组件的安全风险因子。从多个组件中识别出一组软件组件,使得该组软件组件中的每一个的安全风险因子大于预定阈值。此后,当补偿控制机构可用于至少一个软件组件中的每一个并且补偿控制机构满足控制标准时,针对一组软件组件中的至少一个激活补偿控制。该方法包括动态地部署至少一个满足监视标准的连续监视工具,以在预定的持续时间内监视至少一个剩余软件组件中的每个组件,对于该组件,补偿控制机制不可用。

著录项

  • 公开/公告号US2018260572A1

    专利类型

  • 公开/公告日2018-09-13

    原文格式PDF

  • 申请/专利权人 WIPRO LIMITED;

    申请/专利号US201715452850

  • 发明设计人 SOURAV SAM BHATTACHARYA;

    申请日2017-03-08

  • 分类号G06F21/57;

  • 国家 US

  • 入库时间 2022-08-21 13:02:07

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号