Home > Ask the Security Experts > Security Management Questions & Answers > How to prevent software piracy
Ask The Security Expert: Questions & Answers
EMAIL THIS

How to prevent software piracy

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 24 December 2007
What methods should an organization implement to prevent software piracy?

>
EXPERT RESPONSE
Software publishers have several options to protect their intellectual property from thieves. Unfortunately, none of them are foolproof and all risk negatively affecting the user experience.

The most widely used method is the license key; code that is built into an application to require a valid key to unlock the software. This key can be distributed via packaging or some other online mechanism. There are a variety of tool kits available to allow corporations to easily build this capability into their products. Just search the Web for "software licensing toolkits" and you'll be busy for a few days wading through options.

Some shopping cart providers, such as Digital River Inc., include these kinds of licensing capabilities, offering an end-to-end method for everything from hosting a store, to distributing software, to managing licensing keys (so you don't have to). But be ready to part with a percentage of your sales for that privilege.

If organizations are worried about someone stealing their source code, then they need to look into a code-theft and antipiracy package. This is a nascent market, with players like V.I. Laboratories Inc., Arxan Technologies Inc. and Aladdin Knowledge Systems Inc., which actually encrypts the source code within an application so it can't be reverse engineered or stolen in any other way. These products tend to be pretty pricey (since it's an early market) and they aren't mainstream.

When dealing with Web applications, corporations should think about running PHP code using a tool like Zend Technologies Inc.'s Zend Guard, which provides a run-time environment to compile Web applications and thus shield the source code from the browsers.

For more information:

  • Security management expert Mike Rothman breaks down the topic of Web security, highlighting certain important areas.
  • Michael Cobb examines if Web application security vendor mergers present better opportunities for buyers.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    What is the GISP certification and how does it compare to the CISSP certification?
    Would QSAs normally write up a PCI DSS report on compliance (ROC) and submit it to all issuing card brands?
    How can gap analysis be applied to the security system development life cycle?
    When should an enterprise consider low-cost security appliances vs. a bigger do-everything appliance?
    What are some tips on protecting my security budget in a tight economy?
    What value do research firms provide to enterprises that subscribe to their services?
    What certificate offers the best ROI for an IT project manager?
    Which is the biggest threat to data: Insider activity or outsider activity?
    What role does information security play in enterprise fraud-prevention activities?
    What is the difference between an SAS 70 data center and a Tier III data center?

    Web Application Security (Also see Web Access Control)
    What are the basics of a Web browser exploit?
    Symantec to acquire MessageLabs for SaaS model
    Clickjacking details released after attack proof-of-concept emerges
    Billy Hoffman on AJAX security and browser attacks
    Data risks take shine off Google Chrome
    Verizon breach study identifies industry specific threats
    IronPort feature detects exploited websites
    PCI DSS 1.2 clarifies wireless, antivirus use
    MySpace, Facebook ignoring basic principles of security
    Positive changes coming to ModSecurity

    Enterprise Data Protection
    Seagate hardware-based disk encryption could gain traction
    Workstation hard drive encryption: Overdue or overkill?
    Symantec melds DLP, archiving into information risk management
    Encryption no longer an optional technology
    Oracle DBAs cite lack of security measures
    IBM offers hardware-based encryption for x servers
    Crypto landmark Bletchley Park in danger of closing
    Product Review: Workshare Protect Premium 6.0
    How to avoid DLP implementation pitfalls
    Quiz: Data loss prevention

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    anonymous Web surfing  (SearchSecurity.com)
    buffer overflow  (SearchSecurity.com)
    cache cramming  (SearchSecurity.com)
    cookie poisoning  (SearchSecurity.com)
    dictionary attack  (SearchSecurity.com)
    distributed denial-of-service attack  (SearchSecurity.com)
    JavaScript hijacking  (SearchSecurity.com)
    National Computer Security Center  (SearchSecurity.com)
    threat modeling  (SearchSecurity.com)
    trigraph  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts