IP Library Granted Patent US 12,645,568
Granted Patent B2
US 12,645,568 · App. 18/635,541 · Granted Jun 2, 2026

Software bill-of-materials via stack sampling

Inventors: Eran Segal (Ganei Tikva, IL); Moshe Siman Tov Bustan (Holon, IL); Pavel Furman (Netanya, IL); Idan Bartura (Herzliya, IL); Aviv Mussinger (Tel Aviv, IL)
Assignee: Kodem Security Ltd.
G06F11/3636G06F11/302G06F11/3037G06F11/3644G06Q10/0875
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,568
App. No.
18/635,541
Filed
Apr 15, 2024
Granted
Jun 2, 2026
Kind
B2
Art Unit
3627
USPC
705/29
Abstract

A system of determining a software bill-of-materials (RBOM) of an operating environment, the system comprising a processing circuitry configured to: a) access a memory space of a first process executing in the operating environment; b) for one or more threads of the first process: read contents of one or more memory location of a thread stack associated with the respective thread, determine whether a contained value of a respective memory location is a code section execution address, and responsive to the contained value of the respective memory location of the thread stack being a code section execution address: i) determine, based on the memory space of the first process and/or an executable file associated with the first process, a code section identifier associated with the code section, and ii) add the code section identifier associated with the code section to the RBOM.

Claims (34)

1 . A system of determining a software bill-of-materials (RBOM) of an operating environment, the system comprising a processing circuitry configured to:

a. access a memory space of a first process executing in the operating environment;

b. for one or more threads of the first process:

i. read contents of one or more memory location of a thread stack associated with the respective thread,

ii. determine whether a contained value of a respective memory location is a code section execution address, and

iii. responsive to the contained value of the respective memory location of the thread stack being a code section execution address:

a) determine, based on the memory space of the first process and/or an executable file associated with the first process, a code section identifier associated with a code section including the code section execution address, and

b) add the code section identifier associated with the code section to the RBOM.

2 . The system of claim 1 , wherein the processing circuitry is further configured to perform the determining the code section identifier based on one or more of:

a. a symbol table of the executable file;

b. a debug section of the executable file;

c. a program database associated with the executable file and

d. an abstract syntax tree derivative of one or more source code files associated with the executable file.

3 . The system of claim 1 , wherein the processing circuitry is further configured to:

e. repeat a.-b. for one or more additional processes executing in the operating environment.

4 . The system of claim 3 , wherein the processing circuitry is further configured to:

f. responsive to an event, repeat a.-d. for one or more additional iterations.

5 . The system of claim 4 , wherein the event is an expiration of a delay.

6 . A processing circuitry-based method of determining a software bill-of-materials (RBOM) of an operating environment, the method comprising:

a. accessing a memory space of a first process executing in the operating environment;

b. for one or more threads of the first process:

i. reading contents of one or more memory locations of a thread stack associated with the respective thread,

ii. determining whether a contained value of a respective memory location is a code section execution address, and

iii. responsive to the contained value of the respective memory location of the thread stack being a code section execution address:

a) determining, based on the memory space of the first process and/or an executable file associated with the first process, a code section identifier associated with a code section including the code section execution address, and

b) adding the code section identifier associated with the code section to the RBOM.

7 . A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processing circuitry to perform a method of determining a software bill-of-materials (RBOM) of an operating environment, the method comprising:

a. accessing a memory space of a first process executing in the operating environment;

b. for one or more threads of the first process:

i. reading contents of one or more memory locations of a thread stack associated with the respective thread,

ii. determining whether a contained value of a respective memory location is a code section execution address, and

iii. responsive to the contained value of the respective memory location of the thread stack being a code section execution address:

a) determining, based on the memory space of the first process and/or an executable file associated with the first process, a code section identifier associated with a code section including the code section execution address, and

b) adding the code section identifier associated with the code section to the RBOM.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2025
From: SEGAL, ERAN; SIMAN TOV BUSTAN, MOSHE; FURMAN, PAVEL; BARTURA, IDAN; MUSSINGER, AVIV
To: KODEM SECURITY LTD.
Reel/Frame 073185/0483 →
Continuity (2)
Continuation 18635419 · Apr 15, 2024
Related Publication 20250322355A1 · Oct 16, 2025
References Cited (21)
US 7716647B2 · Loh · 2010 [cited by examiner]
US 8478948B2 · Panchenko · 2013 [cited by examiner]
US 11550903B1 · Epstein · 2023 [cited by applicant]
US 11989572B2 · Furman · 2024 [cited by examiner]
US 20050138013A1 · Walker · 2005 [cited by examiner]
US 20050210454A1 · DeWitt, Jr. et al. · 2005 [cited by applicant]
US 20060036579A1 · Byrd et al. · 2006 [cited by applicant]
US 20060294355A1 · Zimmer · 2006 [cited by examiner]
US 20130246451A1 · Kaiser · 2013 [cited by examiner]
US 20160357958A1 · Guidry · 2016 [cited by applicant]
US 20190303815A1 · Li · 2019 [cited by examiner]
US 20230040382A1 · Tokura et al. · 2023 [cited by applicant]
US 20230044935A1 · Madineni et al. · 2023 [cited by applicant]
US 20230367880A1 · Sudhakar · 2023 [cited by examiner]
US 20240020140A1 · Furman · 2024 [cited by examiner]
EP 3009935A1 · 2016 [cited by applicant]
EclEmma 3.1.9, Java Code Coverage for Eclipse, pp. 1-2, downloaded from https://www.jacoco.org (Jul. 10, 2024). [cited by applicant]
Memory Analyzer (MAT), Eclipse Memory Analyzer Open Source Project_The Eclipse Foundation, pp. 1-2, downloaded from http://www.eclipse.org/ (Jul. 10, 2024). [cited by applicant]
GitHub—volatilityfoundation/volatility: An advanced memory forensics framework, pp. 1-12, downloaded from https://github.com/volatilityfoundation/volatility (Jul. 10, 2024). [cited by applicant]
Off-CPU Analysis, pp. 1-14, downloaded from https://www.brendangregg.com/offcpuanalysis.html (Jul. 10, 2024). [cited by applicant]
Arash Shahkar, On Matching Binary to Source Code, The Department of Concordia Institute for Information Systems Engineering, pp. 1-99 (2016). [cited by applicant]