SOFTWARE LIBRARY UPGRADES USING RISK ANALYSES
卷宗概要
发明人
NISAN HAIMOV; BORIS SHPILYUCK; IGOR DUBROVSKY; MAXIM BALIN
IPC 分类
CPC 分类
Methods and systems for managing software libraries in a deployment are disclosed. The software libraries may be managed by using risk analyses to weigh a level of risk for an upgrade plan. The upgrade plan may be used to rectify a vulnerability in a software library of the software libraries. The risk analyses may include (i) performing a security scan of the software library to find the vulnerability; (ii) performing the security scan of available software libraries that have rectified the vulnerability; and (iii) defining parameters that weight risk with using the solution against the risk presented by the vulnerability. Based on the parameters, the software library may be upgraded. The risk analyses may further include testing functionality to ensure that functionality is maintained even if the software library is upgraded.
原文(中文)
Methods and systems for managing software libraries in a deployment are disclosed. The software libraries may be managed by using risk analyses to weigh a level of risk for an upgrade plan. The upgrade plan may be used to rectify a vulnerability in a software library of the software libraries. The risk analyses may include (i) performing a security scan of the software library to find the vulnerability; (ii) performing the security scan of available software libraries that have rectified the vulnerability; and (iii) defining parameters that weight risk with using the solution against the risk presented by the vulnerability. Based on the parameters, the software library may be upgraded. The risk analyses may further include testing functionality to ensure that functionality is maintained even if the software library is upgraded.