IP Library Granted Patent US 12688299
Granted Patent B2
US 12688299 · App. 18/442,564 · Granted Jul 21, 2026

Software bill of materials risk assessment based on vulnerability and remediation history

Inventors: Ted Hulick (Pearland, TX); Thomas Szigeti (Vancouver, CA); David J. Zacks (Vancouver, CA)
Assignee: CISCO TECHNOLOGY, INC.
G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12688299
App. No.
18/442,564
Granted
Jul 21, 2026
Kind
B2
Abstract

A method, computer system, and computer program product are provided for analyzing software applications for risk. Data is obtained indicating one or more components of an application and historical data relating to one or more previous versions of the application. The historical data is analyzed to identify one or more vulnerabilities present in the one or more previous versions of the application. A software bill of materials is generated for the application based on the one or more components of the application, wherein the software bill of materials includes risk metadata descriptive of the one or more vulnerabilities of the application. The risk metadata associated with the software bill of materials is analyzed to determine a risk score for the application.

Claims (43)

1 . A computer-implemented method comprising:

obtaining data indicating one or more components of an application and historical data relating to one or more previous versions of the application;

analyzing the historical data to identify one or more vulnerabilities present in the one or more previous versions of the application;

generating a software bill of materials for the application based on the one or more components of the application, wherein the software bill of materials includes risk metadata descriptive of the one or more vulnerabilities of the application; and

analyzing the risk metadata associated with the software bill of materials to determine a risk score for the application.

2 . The computer-implemented method of claim 1 , further comprising:

in response to determining that the risk score of the application satisfies a risk threshold, performing one or more of: automatically notifying a user that the application satisfies the risk threshold, and automatically installing the application at a computing device.

3 . The computer-implemented method of claim 1 , wherein the risk metadata includes one or more of: a count of the one or more vulnerabilities, a severity of the one or more vulnerabilities, a time between identifying and remediating the one or more vulnerabilities, a number of developers assigned to remediating past or present vulnerabilities in the application, and an open-source or closed-source status of the application.

4 . The computer-implemented method of claim 1 , further comprising:

presenting via a user interface the risk score of the application.

5 . The computer-implemented method of claim 4 , wherein the user interface further includes a plurality of applications and corresponding risk scores for each of the plurality of applications.

6 . The computer-implemented method of claim 5 , wherein the plurality of applications are ranked according to the risk score of each application.

7 . The computer-implemented method of claim 6 , further comprising:

selecting for installation a particular application of the plurality of applications based on the risk score of each application.

8 . The computer-implemented method of claim 1 , wherein the one or more vulnerabilities are identified in a common vulnerabilities and exposures listing.

9 . A system comprising:

one or more computer processors;

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors, the program instructions comprising instructions to:

obtain data indicating one or more components of an application and historical data relating to one or more previous versions of the application;

analyze the historical data to identify one or more vulnerabilities present in the one or more previous versions of the application;

generate a software bill of materials for the application based on the one or more components of the application, wherein the software bill of materials includes risk metadata descriptive of the one or more vulnerabilities of the application; and

analyze the risk metadata associated with the software bill of materials to determine a risk score for the application.

10 . The system of claim 9 , wherein the program instructions further comprise instructions to:

in response to determining that the risk score of the application satisfies a risk threshold, perform one or more of: automatically notifying a user that the application satisfies the risk threshold, and automatically installing the application at a computing device.

11 . The system of claim 9 , wherein the risk metadata includes one or more of: a count of the one or more vulnerabilities, a severity of the one or more vulnerabilities, a time between identifying and remediating the one or more vulnerabilities, a number of developers assigned to remediating past or present vulnerabilities in the application, and an open-source or closed-source status of the application.

12 . The system of claim 9 , wherein the program instructions further comprise instructions to:

present via a user interface the risk score of the application.

13 . The system of claim 12 , wherein the user interface further includes a plurality of applications and corresponding risk scores for each of the plurality of applications.

14 . The system of claim 13 , wherein the plurality of applications are ranked according to the risk score of each application.

15 . The system of claim 14 , wherein the program instructions further comprise instructions to:

select for installation a particular application of the plurality of applications based on the risk score of each application.

16 . The system of claim 9 , wherein the one or more vulnerabilities are identified in a common vulnerabilities and exposures listing.

17 . One or more non-transitory computer readable storage media having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to perform operations including:

obtaining data indicating one or more components of an application and historical data relating to one or more previous versions of the application;

analyzing the historical data to identify one or more vulnerabilities present in the one or more previous versions of the application;

generating a software bill of materials for the application based on the one or more components of the application, wherein the software bill of materials includes risk metadata descriptive of the one or more vulnerabilities of the application; and

analyzing the risk metadata associated with the software bill of materials to determine a risk score for the application.

18 . The one or more non-transitory computer readable storage media of claim 17 , wherein the program instructions further cause the computer to:

in response to determining that the risk score of the application satisfies a risk threshold, perform one or more of: automatically notifying a user that the application satisfies the risk threshold, and automatically installing the application at a computing device.

19 . The one or more non-transitory computer readable storage media of claim 17 , wherein the risk metadata includes one or more of: a count of the one or more vulnerabilities, a severity of the one or more vulnerabilities, a time between identifying and remediating the one or more vulnerabilities, a number of developers assigned to remediating past or present vulnerabilities in the application, and an open-source or closed-source status of the application.

20 . The one or more non-transitory computer readable storage media of claim 17 , wherein the program instructions further comprise instructions to:

present via a user interface the risk score of the application.