IP Library › Granted Patent US 12,664,289
Granted Patent B1
US 12,664,289 · App. 19/409,701 · Granted Jun 23, 2026

Precomputing reachability to identify exploitable vulnerabilities

Inventors: Feross Hassan Aboukhadijeh (San Francisco, CA); Benjamin Barslev Nielsen (Aarhus, DK); Mikola Christopher Lysenko (Midland, MI); Martin Torp (Aarhus, DK)
Assignee: Socket, Inc.
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,664,289
App. No.
19/409,701
Filed
Dec 4, 2025
Granted
Jun 23, 2026
Kind
B1
Art Unit
2497
USPC
726/25
Abstract

Systems and methods are disclosed herein for determining reachability of vulnerable code. In some embodiments, a tool receives an alert of a vulnerability within an application, and determines a set of dependent packages by referencing a knowledge graph. For each vulnerable node of the dependency chain having the vulnerability, the tool identifies a set of node pairs having a direct link between an upstream node and the vulnerable node, determines whether the vulnerable node is reachable by each upstream node of the set of upstream nodes, and annotates links for unreachable nodes. For upstream nodes that are able to reach the vulnerable node, the tool iteratively determines whether a respective further upstream node is able to reach respective ones of their respective directly connected downstream nodes. The tool generates a pruned dependency chain by determining a boundary of the dependency chain, separating reachable vulnerable nodes from unreachable vulnerable nodes.

Claims (49)

1 . A method comprising:

receiving an alert of a vulnerability within an application;

determining, for the application, a set of dependent packages by referencing a knowledge graph storing a dependency chain for the application having a node for each package within the dependency chain;

for each vulnerable node of the dependency chain having the vulnerability:

identifying a set of node pairs having a direct link between an upstream node and the vulnerable node;

determining whether the vulnerable node is reachable by each upstream node of the set of upstream nodes; and

responsive to determining that the vulnerable node is not reachable by a respective upstream node, annotating its respective direct link as unreachable;

for upstream nodes that are able to reach the vulnerable node, iteratively determining whether a respective further upstream node is able to reach respective ones of their respective directly connected downstream nodes;

generating a pruned dependency chain for the application by determining a boundary of the dependency chain, the boundary separating reachable vulnerable nodes from unreachable vulnerable nodes; and

analyzing reachable dependencies of the application for the vulnerability using the pruned dependency chain.

2 . The method of claim 1 , wherein determining whether a given downstream node is reachable by a given upstream node having a direct link with the given downstream node comprises determining whether the upstream node executes code referencing the downstream node.

3 . The method of claim 1 , further comprising pre-computing the reachable dependencies responsive to a request.

4 . The method of claim 3 , wherein the request comprises receiving a request to scan the application for vulnerabilities.

5 . The method of claim 3 , wherein the request comprises detecting a Common Vulnerabilities and Exposures (CVE) alert that is associated with the vulnerability.

6 . The method of claim 1 , further comprising storing the reachable dependencies as a reachable dependency graph in a cache.

7 . The method of claim 6 , wherein, responsive to a future request to scan the application for vulnerabilities, the reachable dependency graph is retrieved and used to scan the pruned dependency chain without performing a redetermination of reachability.

8 . A non-transitory computer-readable medium comprising memory with instructions encoded thereon, the instructions, when executed by one or more processors, causing the one or more processors to perform operations, the instructions comprising instructions to:

receive an alert of a vulnerability within an application;

determine, for the application, a set of dependent packages by referencing a knowledge graph storing a dependency chain for the application having a node for each package within the dependency chain;

for each vulnerable node of the dependency chain having the vulnerability:

identify a set of node pairs having a direct link between an upstream node and the vulnerable node;

determine whether the vulnerable node is reachable by each upstream node of the set of upstream nodes; and

responsive to determining that the vulnerable node is not reachable by a respective upstream node, annotate its respective direct link as unreachable;

for upstream nodes that are able to reach the vulnerable node, iteratively determine whether a respective further upstream node is able to reach respective ones of their respective directly connected downstream nodes;

generate a pruned dependency chain for the application by determining a boundary of the dependency chain, the boundary separating reachable vulnerable nodes from unreachable vulnerable nodes; and

analyze reachable dependencies of the application for the vulnerability using the pruned dependency chain.

9 . The non-transitory computer-readable medium of claim 8 , wherein the instructions to determine whether a given downstream node is reachable by a given upstream node having a direct link with the given downstream node comprise instructions to determine whether the upstream node executes code referencing the downstream node.

10 . The non-transitory computer-readable medium of claim 8 , the instructions further comprising instructions to pre-compute the reachable dependencies responsive to a request.

11 . The non-transitory computer-readable medium of claim 10 , wherein the request comprises receiving a request to scan the application for vulnerabilities.

12 . The non-transitory computer-readable medium of claim 10 , wherein the request comprises detecting a Common Vulnerabilities and Exposures (CVE) alert that is associated with the vulnerability.

13 . The non-transitory computer-readable medium of claim 8 , the instructions further comprising instructions to store the reachable dependencies as a reachable dependency graph in a cache.

14 . The non-transitory computer-readable medium of claim 13 , wherein, responsive to a future request to scan the application for vulnerabilities, the reachable dependency graph is retrieved and used to scan the pruned dependency chain without performing a redetermination of reachability.

15 . A system comprising:

memory with instructions encoded thereon; and

one or more processors that, when executing the instructions, are caused to perform operations comprising:

receiving an alert of a vulnerability within an application;

determining, for the application, a set of dependent packages by referencing a knowledge graph storing a dependency chain for the application having a node for each package within the dependency chain;

for each vulnerable node of the dependency chain having the vulnerability:

identifying a set of node pairs having a direct link between an upstream node and the vulnerable node;

determining whether the vulnerable node is reachable by each upstream node of the set of upstream nodes; and

responsive to determining that the vulnerable node is not reachable by a respective upstream node, annotating its respective direct link as unreachable;

for upstream nodes that are able to reach the vulnerable node, iteratively determining whether a respective further upstream node is able to reach respective ones of their respective directly connected downstream nodes;

generating a pruned dependency chain for the application by determining a boundary of the dependency chain, the boundary separating reachable vulnerable nodes from unreachable vulnerable nodes; and

analyzing reachable dependencies of the application for the vulnerability using the pruned dependency chain.

16 . The system of claim 15 , wherein determining whether a given downstream node is reachable by a given upstream node having a direct link with the given downstream node comprises determining whether the upstream node executes code referencing the downstream node.

17 . The system of claim 15 , the operations further comprising pre-computing the reachable dependencies responsive to a request.

18 . The system of claim 17 , wherein the request comprises receiving a request to scan the application for vulnerabilities.

19 . The system of claim 17 , wherein the request comprises detecting a Common Vulnerabilities and Exposures (CVE) alert that is associated with the vulnerability.

20 . The system of claim 19 , the operations further comprising storing the reachable dependencies as a reachable dependency graph in a cache.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2026
From: ABOUKHADIJEH, FEROSS HASSAN; NIELSEN, BENJAMIN BARSLEV; LYSENKO, MIKOLA CHRISTOPHER; TORP, MARTIN
To: SOCKET, INC.
Reel/Frame 073638/0548 →
Continuity (3)
Provisional Application 63884017 · Sep 18, 2025
Provisional Application 63869804 · Aug 25, 2025
Provisional Application 63818506 · Jun 5, 2025
References Cited (63)
US 10282550B1 · Sheridan et al. · 2019 [cited by applicant]
US 11599636B1 · Pilli · 2023 [cited by applicant]
US 11770398B1 · Erlingsson et al. · 2023 [cited by applicant]
US 11893120B1 · Jennings · 2024 [cited by applicant]
US 11934533B2 · Golan et al. · 2024 [cited by applicant]
US 11973784B1 · Erlingsson et al. · 2024 [cited by applicant]
US 12058160B1 · Erlingsson et al. · 2024 [cited by applicant]
US 12095796B1 · Godefroid et al. · 2024 [cited by applicant]
US 12267345B1 · Erlingsson et al. · 2025 [cited by applicant]
US 12314394B2 · Aboukhadijeh et al. · 2025 [cited by applicant]
US 12348545B1 · Parikh et al. · 2025 [cited by applicant]
US 12355626B1 · Varakantam et al. · 2025 [cited by applicant]
US 12363156B1 · Thompson et al. · 2025 [cited by applicant]
US 12418555B1 · Skarphedinsson et al. · 2025 [cited by applicant]
US 12489771B1 · Erlingsson et al. · 2025 [cited by applicant]
US 12495052B1 · Godefroid et al. · 2025 [cited by applicant]
US 20050091542A1 · Banzhof · 2005 [cited by applicant]
US 20130167241A1 · Siman · 2013 [cited by applicant]
US 20140173737A1 · Toback et al. · 2014 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by applicant]
US 20190238593A1 · Larmuseau et al. · 2019 [cited by applicant]
US 20200242254A1 · Velur et al. · 2020 [cited by applicant]
US 20210021644A1 · Crabtree et al. · 2021 [cited by applicant]
US 20210319108A1 · Segal · 2021 [cited by examiner]
US 20220210202A1 · Crabtree et al. · 2022 [cited by applicant]
US 20220222351A1 · Levin et al. · 2022 [cited by applicant]
US 20220318396A1 · Deng · 2022 [cited by examiner]
US 20220405397A1 · Golan et al. · 2022 [cited by applicant]
US 20230009127A1 · Boyer · 2023 [cited by applicant]
US 20230164158A1 · Fellows et al. · 2023 [cited by applicant]
US 20230185921A1 · Karas et al. · 2023 [cited by applicant]
US 20230289448A1 · Kashani et al. · 2023 [cited by applicant]
US 20240111512A1 · Liu et al. · 2024 [cited by applicant]
US 20240411886A1 · Sun et al. · 2024 [cited by applicant]
US 20240414190A1 · Lal et al. · 2024 [cited by applicant]
US 20240427902A1 · Achleitner et al. · 2024 [cited by applicant]
US 20250030725A1 · Fellows et al. · 2025 [cited by applicant]
US 20250039196A1 · Crabtree et al. · 2025 [cited by applicant]
US 20250063063A1 · Tishbi et al. · 2025 [cited by applicant]
US 20250117486A1 · Pickman et al. · 2025 [cited by applicant]
US 20250147755A1 · Muenzel · 2025 [cited by examiner]
US 20250173443A1 · Ganz et al. · 2025 [cited by applicant]
US 20250175456A1 · Crabtree et al. · 2025 [cited by applicant]
US 20250233884A1 · Sherr et al. · 2025 [cited by applicant]
US 20250238519A1 · Tayouri · 2025 [cited by examiner]
US 20250247413A1 · Sharma et al. · 2025 [cited by applicant]
US 20250247414A1 · Baragaba et al. · 2025 [cited by applicant]
US 20250258951A1 · Thompson · 2025 [cited by applicant]
US 20250265336A1 · Mckey et al. · 2025 [cited by applicant]
US 20250284820A1 · Achleitner et al. · 2025 [cited by applicant]
US 20250310367A1 · Du et al. · 2025 [cited by applicant]
US 20250384142A1 · Meszaros et al. · 2025 [cited by applicant]
US 20260050935A1 · Jeff · 2026 [cited by applicant]
AU 2002360844A1 · 2003 [cited by applicant]
CN 118051918A · 2024 [cited by applicant]
CN 117763559B · 2025 [cited by applicant]
CN 119397543B · 2025 [cited by applicant]
Andrade, Roberto et al. Adaptive Abstraction with AI for Managing Software Antipatterns Throughout the Software Lifecycle. : 2025 IEEE/ACM International Workshop on Designing Software (Designing), https://ieeexplore.iee… [cited by applicant]
Ben-Nun et al., “Neural Code Comprehension: A Learnable Representation of Code Semantics”, arXiv:1806.07336v3, 2018 (Year: 2018). [cited by applicant]
Lin, Guanjun et al. Software Vulnerability Detection Using Deep Neural Networks: A Survey. Proceedings of the IEEE, vol. 108, Issue: 10. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9108283 (Year: 2020). [cited by applicant]
United States Office Action, U.S. Appl. No. 19/408,233, Feb. 17, 2026, nine pages. [cited by applicant]
Wang et al., “PatchRNN: A Deep Learning-Based System for Security Patch Identification”, arXiv:2108.03358v2, 2023 (Year: 2023). [cited by applicant]
Watson, Anne et al. Detecting Software Code Vulnerabilities Using 2D Convolutional Neural Networks with Program Slicing Feature Maps. 2022 IEEE Applied Imagery Pattern Recognition Workshop (AIPR). https://ieeexplore.iee… [cited by applicant]
Cited By (2)
US 12,724,903 US 12,730,904