computer program
Let an agent handle programs by function, version, platform, licence, security and provenance, and never help create or deploy malicious software.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify
Researched by: Claude
Purpose and description
Let an agent handle programs by function, version, platform, licence, security and provenance, and never help create or deploy malicious software.
A set of instructions that a computer can execute to perform tasks, from applications and utilities to games, virtual instruments and malicious software such as ransomware.
What it is for: Making computers do useful work.
It can be install and run it; update and patch it; license it; audit its security.
Distinguishing features
Executable instructions
Versioned and licensed
Security depends on provenance and updates
Malware is software used to harm
What it looks like
Files, app icons and interfaces; source code in text.
How it is recognised
Name, version and publisher
Code signatures and checksums
Malware disguises itself as legitimate software
Related models
runs on - platform
is licensed under - rights
uses - security
is a kind of - creative and technical work
In practice
Families and kinds
applications
system software
games
virtual instruments and plug-ins
cloud services and apps
malware such as ransomware
Identifiers
package name and version semantic version identifies releases
CPE name cpe:2.3 string vulnerability databases
hash SHA-256 file integrity
Standards and regulation
EU Cyber Resilience Act
Copyright and software licences
Computer misuse law
Failure modes and hazards
Vulnerabilities and exploits
Malware and ransomware
Supply chain attacks
Licence violations
Also called
+527
Where this came from
wikidata · CC0 1.0
Drafted structure
Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.
Identity Which program.
Identity includes version.
Name and version
Release.
Release
Name and version.
- Which program and version is it? provenance
- Who publishes it? provenance
Integrity
Signatures and hashes.
Integrity
Integrity checks.
- Is the download signed, and does the hash match? boundary
- Is the source official? provenance
Function What it does.
Function decides use.
Purpose
Features.
Purpose
What it does.
- What does the program do? definition
- On which platforms does it run? definition
Data use
Permissions and privacy.
Data
Data handling.
- What data does it collect? boundary
- What permissions does it need? boundary
Security Vulnerabilities and malware.
Security must be maintained.
Vulnerabilities
Known issues.
Vulnerabilities
Known vulnerabilities.
- Are there known vulnerabilities in this version? provenance
- Is a patch available? action
Malware
Harmful software.
Malware
Malware limits.
- Is the request about creating or deploying malware? boundary
- How should the agent respond, for example with defensive guidance? action
Licensing Rights.
Licences govern use.
Licence
Terms.
Licence
Licence terms.
- Under which licence is it distributed? provenance
- What does the licence allow? boundary
Support
Maintenance.
Support
Support status.
- Is the program still supported? boundary
- When does support end? measurement
What the second pass must settle
- Should software types be separate entries?
- How should versions and vulnerabilities be linked?
- How should agents refuse malware requests consistently?