IP Library › Granted Patent US 12,511,404
Granted Patent B1
US 12,511,404 · App. 19/191,033 · Granted Dec 30, 2025

Remediating vulnerabilities using software update management platform with integrated threat intelligence

Inventors: John Morello (Baton Rouge, LA); Ben Bernstein (New York, NY); Dima Stopel (Herzliya, IL)
Assignee: MINIMUS LTD
G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,511,404
App. No.
19/191,033
Filed
Apr 28, 2025
Granted
Dec 30, 2025
Kind
B1
Examiner
LE, KHOI V
Art Unit
2436
USPC
726/22
Abstract

A system and method for vulnerability remediation. A method includes identifying a vulnerable software package among a plurality of software packages based on cybersecurity data indicating a vulnerability; identifying at least one vulnerable software image of a plurality of software images by determining that the at least one vulnerable software image contains the vulnerable software package based on a plurality of files, wherein each of the plurality of software images is built based on a corresponding file of the plurality of files, wherein each file of the plurality of files includes a set of instructions for combining a subset of the plurality of software packages in order to build the corresponding software image of the plurality of software images; and performing at least one remediation action with respect to the at least one vulnerable software image.

Claims (39)

1 . A method for vulnerability remediation, comprising:

generating a plurality of software packages, wherein each software package of the plurality of software packages is generated using a respective set of code;

building a plurality of software images based on a plurality of files, wherein each of the plurality of software images is built based on a corresponding file of the plurality of files, wherein each file of the plurality of files includes a set of instructions for combining a subset of the plurality of software packages in order to build the corresponding software image of the plurality of software images;

storing the plurality of software images in a repository;

identifying a vulnerable software package among the plurality of software packages based on cybersecurity data indicating a vulnerability;

identifying at least one vulnerable software image of the plurality of software images by determining that the at least one vulnerable software image contains the vulnerable software package based on the plurality of files; and

performing at least one remediation action with respect to the at least one vulnerable software image.

2 . The method of claim 1 , wherein performing the at least one remediation action includes modifying a deployment of at least a portion of the at least one vulnerable software image.

3 . The method of claim 2 , wherein performing the at least one remediation action includes pulling a deployment of at least a portion of the at least one vulnerable software image.

4 . The method of claim 2 , wherein performing the at least one remediation action includes redeploying at least a portion of the at least one vulnerable software image.

5 . The method of claim 2 , wherein performing the at least one remediation action includes rebuilding at least a portion of the at least one vulnerable software image based on the plurality of files.

6 . The method of claim 2 , wherein the at least one vulnerable software image is a plurality of vulnerable software images, further comprising:

determining a subset of the plurality of vulnerable software images to be remediated based on a vulnerability status of each of the plurality of vulnerable software images, wherein the deployment of the determined subset of the plurality of vulnerable software images is modified.

7 . The method of claim 6 , wherein the vulnerability status of each of the plurality of vulnerable software images indicates whether the vulnerable software image contains a vulnerability that is actively being exploited, wherein the determined subset of the plurality of vulnerable software images is at least one vulnerable software image of the plurality of software images which contains a vulnerability that is actively being exploited.

8 . The method of claim 1 , wherein each software package is a unit of code defined with respect to at least one function.

9 . A non-transitory computer-readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

generating a plurality of software packages, wherein each software package of the plurality of software packages is generated using a respective set of code;

building a plurality of software images based on a plurality of files, wherein each of the plurality of software images is built based on a corresponding file of the plurality of files, wherein each file of the plurality of files includes a set of instructions for combining a subset of the plurality of software packages in order to build the corresponding software image of the plurality of software images;

storing the plurality of software images in a repository;

identifying a vulnerable software package among the plurality of software packages based on cybersecurity data indicating a vulnerability;

identifying at least one vulnerable software image of the plurality of software images by determining that the at least one vulnerable software image contains the vulnerable software package based on the plurality of files; and

performing at least one remediation action with respect to the at least one vulnerable software image.

10 . A system for vulnerability remediation, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

generate a plurality of software packages, wherein each software package of the plurality of software packages is generated using a respective set of code;

build a plurality of software images based on a plurality of files, wherein each of the plurality of software images is built based on a corresponding file of the plurality of files, wherein each file of the plurality of files includes a set of instructions for combining a subset of the plurality of software packages in order to build the corresponding software image of the plurality of software images;

store the plurality of software images in a repository;

identify a vulnerable software package among the plurality of software packages based on cybersecurity data indicating a vulnerability;

identify at least one vulnerable software image of the plurality of software images by determining that the at least one vulnerable software image contains the vulnerable software package based on the plurality of files; and

perform at least one remediation action with respect to the at least one vulnerable software image.

11 . The system of claim 10 , wherein performing the at least one remediation action includes modifying a deployment of at least a portion of the at least one vulnerable software image.

12 . The system of claim 11 , wherein performing the at least one remediation action includes pulling a deployment of at least a portion of the at least one vulnerable software image.

13 . The system of claim 11 , wherein performing the at least one remediation action includes redeploying at least a portion of the at least one vulnerable software image.

14 . The system of claim 11 , wherein performing the at least one remediation action includes rebuilding at least a portion of the at least one vulnerable software image based on the plurality of files.

15 . The system of claim 11 , wherein the at least one vulnerable software image is a plurality of vulnerable software images, wherein the system is further configured to:

determine a subset of the plurality of vulnerable software images to be remediated based on a vulnerability status of each of the plurality of vulnerable software images, wherein the deployment of the determined subset of the plurality of vulnerable software images is modified.

16 . The system of claim 15 , wherein the vulnerability status of each of the plurality of vulnerable software images indicates whether the vulnerable software image contains a vulnerability that is actively being exploited, wherein the determined subset of the plurality of vulnerable software images is at least one vulnerable software image of the plurality of software images which contains a vulnerability that is actively being exploited.

17 . The system of claim 10 , wherein each software package is a unit of code defined with respect to at least one function.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2026
From: MINIMUS LTD
To: ECHO SOFTWARE LTD.
Reel/Frame 075796/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2025
From: MORELLO, JOHN; BERNSTEIN, BEN; STOPEL, DIMA
To: MINIMUS LTD
Reel/Frame 070962/0731 →
Continuity (2)
Provisional Application 63734282 · Dec 16, 2024
Provisional Application 63720901 · Nov 15, 2024
References Cited (40)
US 9959104B2 · Chen et al. · 2018 [cited by applicant]
US 9983891B1 · Christensen · 2018 [cited by applicant]
US 10505830B2 · Mishalov et al. · 2019 [cited by applicant]
US 10885378B2 · Li et al. · 2021 [cited by applicant]
US 11062022B1 · Kalamkar · 2021 [cited by examiner]
US 11182140B2 · Riek et al. · 2021 [cited by applicant]
US 11599348B2 · Goldmann et al. · 2023 [cited by applicant]
US 11669362B2 · Singh et al. · 2023 [cited by applicant]
US 11972333B1 · Horesh et al. · 2024 [cited by applicant]
US 12095806B1 · Nemtsov · 2024 [cited by examiner]
US 12099414B2 · Mitkar et al. · 2024 [cited by applicant]
US 12242994B1 · Aggarwal et al. · 2025 [cited by applicant]
US 12267345B1 · Erlingsson · 2025 [cited by examiner]
US 20110225574A1 · Khalidi et al. · 2011 [cited by applicant]
US 20120110333A1 · Lukkarila et al. · 2012 [cited by applicant]
US 20120324446A1 · Fries et al. · 2012 [cited by applicant]
US 20150365437A1 · Bell, Jr. · 2015 [cited by examiner]
US 20170147813A1 · McPherson et al. · 2017 [cited by applicant]
US 20190347127A1 · Coady et al. · 2019 [cited by applicant]
US 20200159536A1 · Saidi · 2020 [cited by applicant]
US 20200213357A1 · Levin et al. · 2020 [cited by applicant]
US 20200285504A1 · Siegmund · 2020 [cited by applicant]
US 20200326931A1 · Nadgowda et al. · 2020 [cited by applicant]
US 20210157623A1 · Chandrashekar et al. · 2021 [cited by applicant]
US 20210208916A1 · Wang et al. · 2021 [cited by applicant]
US 20210255840A1 · Novy · 2021 [cited by applicant]
US 20210319109A1 · Weng et al. · 2021 [cited by applicant]
US 20220147378A1 · Tarasov et al. · 2022 [cited by applicant]
US 20220166626A1 · Madisetti et al. · 2022 [cited by applicant]
US 20230168986A1 · Larkin · 2023 [cited by examiner]
US 20240069883A1 · Griffin et al. · 2024 [cited by applicant]
US 20240103833A1 · Shemer et al. · 2024 [cited by applicant]
US 20240134967A1 · Yaron et al. · 2024 [cited by applicant]
US 20240411674A1 · Zmigrod et al. · 2024 [cited by applicant]
US 20250004741A1 · Hubik · 2025 [cited by applicant]
US 20250123819A1 · Khemka et al. · 2025 [cited by applicant]
US 20250156535A1 · Keller et al. · 2025 [cited by applicant]
CN 111522628A · 2020 [cited by applicant]
“Announcing ‘Yum + RPM for Containerized Applications’—Nulecule & Atomic App,” Red Hat Blog (Jun. 23, 2015) (available at https://www.redhat.com/en/blog/announcing-yum-rpm-containerized-applications-nulecule-atomic-app)… [cited by applicant]
Ian Gorton et al.; Components in the Pipeline; IEEE; pp. 34-40; retrieved on Jul. 18, 2025 (Year: 2025). [cited by applicant]
Cited By (1)
US 12,724,904