IP Library Granted Patent US 12,430,445
Granted Patent B2
US 12,430,445 · App. 18/307,409 · Granted Sep 30, 2025

Dynamic security service extension based on software bill of materials

Inventors: Robert Edgar Barton (Richmond, CA); Thomas Szigeti (Vancouver, CA); David John Zacks (Vancouver, CA)
Assignee: Cisco Technology, Inc.
G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,430,445
App. No.
18/307,409
Granted
Sep 30, 2025
Kind
B2
Abstract

Techniques are described herein for dynamic service extension to provide risk mitigation upon detecting a threat. In embodiments, such techniques may be performed by a service provider platform and may comprise receiving information about a security threat, identifying one or more components susceptible to the security threat, determining, based on a software bill of materials, at least one data flow that includes a point of delivery (pod) associated with the one or more components, identifying at least one additional service determined to mitigate the security threat, and implementing the at least one additional service in relation to the at least one data flow.

Claims (37)

1. A method comprising:

receiving, at a service provider platform, information about a security threat;

identifying, by the service provider platform, one or more components susceptible to the security threat;

determining, by the service provider platform based on a software bill of materials, at least one data flow that includes a point of delivery (pod) associated with the one or more components;

identifying, by the service provider platform, at least one additional service determined to mitigate the security threat; and

implementing, by the service provider platform, the at least one additional service in relation to the at least one data flow.

2. The method of claim 1 , wherein the information about the security threat is received from a third-party vulnerability management application.

3. The method of claim 1 , wherein the security threat comprises at least one of a software virus or software exploit.

4. The method of claim 1 , further comprising accessing the software bill of materials on a computing device that is separate from the service provider platform.

5. The method of claim 1 , wherein the software bill of materials is accessed on at least one blockchain ledger stored in relation to one or more components.

6. The method of claim 1 , wherein the at least one additional service is implemented via at least one new pod inserted into the at least one data flow, and wherein a portion of the at least one data flow is redirected to the at least one new pod.

7. The method of claim 6 , wherein the at least one additional service comprises multiple additional services, and the at least one new pod comprises multiple separate pods, each of the multiple separate pods corresponding to a respective additional service of the multiple additional services.

8. The method of claim 1 , wherein the at least one additional service is implemented via a sidecar container.

9. The method of claim 8 , wherein the sidecar container is included within a new pod, the new pod being an enhanced version of the pod associated with the one or more components.

10. A service provider computing device comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the service provider computing device to perform operations comprising:

receiving information about a security threat;

identifying one or more components susceptible to the security threat;

determining, based on a software bill of materials, at least one data flow that includes a point of delivery (pod) associated with the one or more components;

identifying at least one additional service determined to mitigate the security threat; and

implementing the at least one additional service in relation to the at least one data flow.

11. The service provider computing device of claim 10 , wherein the at least one additional service is implemented via at least one new pod inserted into the at least one data flow, and wherein a portion of the at least one data flow is redirected to the at least one new pod.

12. The service provider computing device of claim 11 , wherein the at least one additional service comprises multiple additional services, and the at least one new pod comprises multiple separate pods, each of the multiple separate pods corresponding to a respective additional service of the multiple additional services.

13. The service provider computing device of claim 10 , wherein the at least one additional service is implemented via a sidecar container.

14. The service provider computing device of claim 13 , wherein the sidecar container is included within a new pod, the new pod being an enhanced version of the pod associated with the one or more components.

15. The service provider computing device of claim 14 , wherein the pod associated with the one or more components is shut down after the new pod is implemented.

16. The service provider computing device of claim 10 , wherein the at least one additional service comprises a virus scanning application.

17. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving information about a security threat;

identifying one or more components susceptible to the security threat;

determining, based on a software bill of materials, at least one data flow that includes a point of delivery (pod) associated with the one or more components;

identifying at least one additional service determined to mitigate the security threat; and

implementing the at least one additional service in relation to the at least one data flow.

18. The one or more non-transitory computer-readable media of claim 17 , wherein the information about the security threat is received from a third-party vulnerability management application.

19. The one or more non-transitory computer-readable media of claim 17 , wherein the security threat comprises at least one of a software virus or software exploit.

20. The one or more non-transitory computer-readable media of claim 17 , wherein the software bill of materials is accessed on at least one blockchain ledger stored in relation to one or more components.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2023
From: BARTON, ROBERT EDGAR; SZIGETI, THOMAS; ZACKS, DAVID JOHN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063450/0249 →
Continuity (1)
Related Publication 20240362336A1 · Oct 31, 2024
References Cited (21)
US 11507672B1 · Pagnozzi · 2022 [cited by examiner]
US 11528147B2 · Madisetti · 2022 [cited by examiner]
US 11861015B1 · Reguly · 2024 [cited by examiner]
US 20140123207A1 · Agarwal et al. · 2014 [cited by applicant]
US 20150236917A1 · Anderson et al. · 2015 [cited by applicant]
US 20160080399A1 · Harris · 2016 [cited by examiner]
US 20170251013A1 · Kirti · 2017 [cited by examiner]
US 20180077195A1 · Gathala et al. · 2018 [cited by applicant]
US 20200128046A1 · Schaefer et al. · 2020 [cited by applicant]
US 20200201620A1 · Beard · 2020 [cited by examiner]
US 20200296136A1 · Liu et al. · 2020 [cited by applicant]
US 20210029151A1 · Brooks · 2021 [cited by examiner]
US 20220083652A1 · Ransford et al. · 2022 [cited by applicant]
US 20220164729A1 · Fields · 2022 [cited by examiner]
US 20230058477A1 · Jiang et al. · 2023 [cited by applicant]
US 20230177435A1 · Sailer · 2023 [cited by examiner]
CN 112153049A · 2020 [cited by applicant]
WO WO2020227266A1 · 2020 [cited by applicant]
Office Action for U.S. Appl. No. 18/318,182, dated Jan. 24, 2025, 18 pages. [cited by applicant]
Ibryam, et al., “Kubernetes Patterns Reusable Elements for Designing Cloud-Native Applications”, retreived on Jun. 30, 2021 at URL:https://www.redhat.com/cms/managed-files/cm-oreilly-kubernetes-patterns-ebook-fl9824-201… [cited by applicant]
PCT Search Report and Written Opinion mailed Feb. 2, 2024 for PCT Application No. PCT/US24/26543, 38 pages. [cited by applicant]