Piracy Alerts for ISVs
Monitor and Track Piracy with GuardIT
ISVs lose an estimated 33% of revenue to piracy on average. Moreover, in today’s challenging economic climate, customers are more likely than ever before to underpay for software licenses. Understanding what this means for your specific business and software product requires close monitoring of all uses of your software – whether licensed or unauthorized. This business intelligence is key to shaping your anti-piracy strategy and recovering lost revenue.
Arxan’s business intelligence solution, which is comprised of our software security product, GuardIT and professional services, allows you to gather and analyze real-time piracy intelligence from the field. Data that can be gathered includes:
- Who is abusing your software: whether under licensed customers or end users of counterfeit copies
- Where they are located, geographically and by IP address
- How they have subverted your license management or node locking layer
How it Works
Easy Insertion
Remote notify is a standard reaction provided by GuardIT, and can be triggered when tampering is detected, application debugging is detected, or when code authentication fails. The remote notify reaction is specified and configured via an XML configuration file or via GuardIT’s rich graphic user interface. It is embedded into the application by GuardIT in an automated, post-compilation protection process.
Real Time Reporting
Honest customers never see remote notification in action. However, when compromises are detected, the remote notify reaction executes. Arxan’s professional services can be configured to gather and transmit a variety of data, including:
- Identifiers for the user’s identity and network address
- Geographic characteristics about the user’s physical location
- Forensics information including the application hash (to identify strain of hacked binary), type of compromise and area of binary that is compromised
When a remote notification is triggered on the end user’s system, this data is gathered and composed into an optionally encrypted message that is sent back to a specified IP address or addresses. The packet is camouflaged within normal internet traffic to protect it from being blocked by application firewalls or port scanners.
Data Analysis and Revenue Recovery
Leveraging Arxan’s professional services to remote notify messages, out of the box can be received in one of two ways:
- Collated into a log file on the ISV’s server or Arxan’s piracy monitoring server for subsequent analysis
- Received by a gateway script which runs on the ISV’s server or a cloud computing platform such as Amazon Web Services or Force.com, with automated aggregation into SalesForce.com or other CRM system
Incoming remote notify data enables revenue recovery in three ways:
- Provides actionable leads to your sales team for potential new software sales, and allows them to reach out and fully monetize under-licensed customers.
- Provides accurate piracy metric information to your product management team, to enable creation and evaluation of a business-appropriate anti-piracy strategy
- Provides forensic information that can be forwarded to law enforcement agencies for appropriate action.
GuardIT for Alerting – Core Features
Robust Implementation. Unprotected phone home routines can be easily disabled or bypassed. More severely, they can be tampered to craft packets with malformed strings. This can enable a server-side compromise and potential theft of your CRM credentials and all related data – a severe enterprise level compromise with very high breach management costs. GuardIT’s remote notify feature is part of a deep, layered defense mechanism. GuardIT intelligence gathering is robust in the field and very difficult to spoof, alter or disable, ensuring reliable operation and return on your investment in intelligence gathering.
Easy Integration with Application. Remote notify is a standard user-defined reaction within GuardIT. It is enabled via an easy point-click interface, and inserted automatically in a post-compilation protection process.
Easy Integration with Backend. GuardIT allows easy integration with leading CRM solutions such as SalesForce.com®, and easy customization for integration with a backend system of your choice. The backend gateway may be hosted by the ISV directly, or can be implemented with a cloud platform such as Amazon® Web Services.
Secure cross-platform support. GuardIT supports a broad range of applications, all of which can be instrumented to report back business intelligence data.
- C/C++, .NET and Java applications
- Desktop, embedded and server applications on Windows and Linux
- 32-bit applications and 64-bit applications

Call Us: (301) 968-4290


