IP Library Granted Patent US 12,547,731
Granted Patent B2
US 12,547,731 · App. 18/419,812 · Granted Feb 10, 2026

Risk mitigation techniques based on software bill of materials

Inventors: Chockalingam Ramiah (Cary, NC); John William Garrett (Apex, NC); Arvind Vasudev Chari (New York, NY)
G06F21/577G06F8/65G06Q10/0875G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,731
App. No.
18/419,812
Granted
Feb 10, 2026
Kind
B2
Abstract

Techniques are described herein for reducing a risk exposure related to a software application. The techniques may comprise receiving an indication of a software application, identifying a number of components associated with that software application as well as a number of vulnerability scores corresponding to the number of components, determining, based on the number of vulnerability scores, a risk score associated with the software application, and identifying one or more updates associated with the number of components and determining a change to the risk score associated with those one or more updates. In embodiments, the techniques may further comprise receiving an indication of a threshold risk score and determining at least one of the one or more updates that, when applied to at least one of the number of components, is determined to lower the risk score to below the threshold risk score.

Claims (48)

1 . A method comprising:

receiving an indication of a software application;

identifying a number of components associated with the software application and a number of vulnerability scores corresponding to the number of components, wherein an individual vulnerability score of the number of vulnerability scores represents a susceptibility of an individual component of the number of components to a detected threat;

determining a first risk score associated with the software application as a function of the number of vulnerability scores corresponding to the number of components and a number of times that each component of the number of components is implemented in the software application;

determining a maximum risk score associated with the software application;

upon determining that the first risk score is greater than the maximum risk score:

identifying one or more updates associated with the number of components;

determining, for individual updates of the one or more updates, an impact to be attributed to the individual update:

selecting a subset of the one or more updates calculated to result in reduction of the first risk score to a second risk score upon implementation, an amount of the reduction corresponding to an aggregate impact associated with the subset of the one or more updates; and

upon determining that the second risk score is less than the maximum risk score, causing the subset of the one or more updates to be implemented by providing instructions to an application provider to implement the subset with respect to the software application.

2 . The method of claim 1 , wherein the number of components associated with the software application are identified via a software bill of materials (SBOM) associated with the software application.

3 . The method of claim 1 , wherein the one or more updates associated with the number of components comprises at least one of a patch or version update for a component of the number of components.

4 . The method of claim 1 , wherein causing the subset of the one or more updates to be implemented further comprises providing instructions to a developer associated with the software application.

5 . The method of claim 1 , wherein the indication of the software application is received in a request to access the software application received from a computing device.

6 . The method of claim 5 , wherein the maximum risk score is determined based on policy data associated with an organization to which the computing device belongs.

7 . The method of claim 6 , further comprising denying the request to access the software application upon determining that the first risk score is greater than the maximum risk score.

8 . The method of claim 6 , further comprising:

receiving a second request to access the software application from the computing device subsequent to the one or more updates having been implemented; and

upon determining that the second risk score is not greater than the maximum risk score, granting the second request to access the software application.

9 . A computing device comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the computing device to perform operations comprising:

receiving an indication of a software application;

identifying a number of components associated with the software application and a number of vulnerability scores corresponding to the number of components, wherein an individual vulnerability score of the number of vulnerability scores represents a susceptibility of an individual component of the number of components to a detected threat;

determining a first risk score associated with the software application as a function of the number of vulnerability scores corresponding to the number of components and a number of times that each component of the number of components is implemented in the software application;

determining a threshold risk score associated with the software application;

upon determining that the first risk score is greater than the threshold risk score:

identifying one or more updates associated with the number of components;

determining, for individual updates of the one or more updates, an impact to be attributed to the individual update;

selecting a subset of the one or more updates calculated to result in reduction of the first risk score to a second risk score upon implementation, an amount of the reduction corresponding to an aggregate impact associated with the subset of the one or more updates; and

upon determining that the second risk score is less than the threshold risk score, causing the subset of the one or more updates to be implemented by providing instructions to an application provider to implement the subset with respect to the software application.

10 . The computing device of claim 9 , wherein the application provider comprises a server computer implemented within a network.

11 . The computing device of claim 10 , wherein the software application is hosted by the application provider, and wherein the application provider is configured to provide one or more software services accessible over the network.

12 . The computing device of claim 11 , wherein the number of components associated with the software application are identified via a software bill of materials (SBOM) maintained by the application provider.

13 . The computing device of claim 9 , wherein the threshold risk score value is associated with an organization, and upon determining the first risk score is above the threshold risk score value, the operations further comprise:

providing information about the one or more updates to an entity associated with the organization.

14 . The computing device of claim 13 , wherein the threshold risk score value is obtained from policy data maintained in relation to the organization.

15 . One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving an indication of a risk score threshold;

receiving an indication of a software application;

identifying a number of components associated with the software application and a number of vulnerability scores corresponding to the number of components, wherein an individual vulnerability score of the number of vulnerability scores represents a susceptibility of an individual component of the number of components to a detected threat; and

determining a first risk score associated with the software application as a function of the number of vulnerability scores corresponding to the number of components and a number of times that each component of the number of components is implemented in the software application;

upon determining that the risk score associated with the software application is above the risk score threshold:

identifying a set of updates associated with the number of components;

determining, for individual updates of the set of updates, an impact to be attributed to the individual update;

selecting a subset of the set of updates to result in a change from the first risk score to a second risk score upon implementation, the subset of the set updates selected based on a calculation that the implementation will result in the second risk score being below the risk score threshold; and

causing the subset of the set of updates to be implemented by providing instructions to an application provider to implement the subset with respect to the software application.

16 . The one or more non-transitory computer-readable media of claim 15 , wherein updates in the set of updates are ordered based on an amount of the change to the risk score attributed to a respective update of the set of updates.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2024
From: RAMIAH, CHOCKALINGAM; GARRETT, JOHN WILLIAM; CHARI, ARVIND VASUDEV
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066212/0170 →
Continuity (1)
Related Publication 20250238520A1 · Jul 24, 2025
References Cited (17)
US 9952961B2 · Atyam · 2018 [cited by examiner]
US 10484429B1 · Fawcett · 2019 [cited by examiner]
US 12008357B2 · Masis · 2024 [cited by examiner]
US 12393700B1 · Apostolopoulos · 2025 [cited by examiner]
US 20180150639A1 · Abramovsky · 2018 [cited by examiner]
US 20210075814A1 · Bulut · 2021 [cited by applicant]
US 20210157905A1 · Musseau · 2021 [cited by examiner]
US 20210232995A1 · Zhang · 2021 [cited by applicant]
US 20210273968A1 · Shaieb · 2021 [cited by examiner]
US 20220129561A1 · Shivanna · 2022 [cited by examiner]
US 20230208869A1 · Bisht · 2023 [cited by applicant]
US 20230269272A1 · Dambrot · 2023 [cited by applicant]
US 20230315491A1 · Brdiczka · 2023 [cited by examiner]
US 20240195830A1 · Jayaraman · 2024 [cited by examiner]
US 20250147864A1 · Bastien · 2025 [cited by examiner]
US 20250173441A1 · McNally · 2025 [cited by examiner]
Daigle, et al., “Reference Architecture for Generative AI Based on Large Language Models (LLMs)”, Lenovo Press, Dec. 15, 2023, Form No. LP1798, 57 Pages. Retrieved from: https://lenovopress.lenovo.com/lp1798-reference-a… [cited by applicant]