IP Library › Granted Patent US 12,197,586
Granted Patent B2
US 12,197,586 · App. 17/745,695 · Granted Jan 14, 2025

Systems and processes for facilitating edits to software bill of materials

Inventors: Frank Joseph Bussell (Issaquah, WA); Henry James Lyons (Seattle, WA); Nicholas Allan Schwerzler (Sammamish, WA); Sencer Nuri Yeralan (Seattle, WA); Dale Russel Rolf (Renton, WA); Minh Trong Tran (Bellevue, WA); David John Janson (Kirkland, WA); Thomas George Yaryan (Seattle, WA); Ian James McCarty (Sammamish, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,586
App. No.
17/745,695
Filed
May 16, 2022
Granted
Jan 14, 2025
Kind
B2
Art Unit
2446
USPC
726/25
Abstract

Systems are provided for generating, modifying and using SBOMs for facilitating risk assessment and threat mitigation for corresponding programs, and particularly for large programming builds. The creation and modification of the SBOMs includes processes for omitting declarations referenced in chunk SBOMs of program chunks incorporated into a final programming build associated with a build SBOM, but which are not actually utilized by the final programming build, as well as processes for adding new declarations for code segments that are not declared in the related chunk SBOMs, even though the code segments are utilized by the final programming build. Systems are also configured to use SBOMs in combination with configuration restriction records to assess and resolve threat events in a manner that can prevent unnecessary remedial actions for threat events that appear to be relevant to one or more files or dependencies incorporated into a program.

Claims (46)

1. A method for facilitating edits to an SBOM (software bill of materials), the SBOM including file declarations for files that are incorporated into a corresponding program associated with the SBOM, and dependency declarations associated with one or more of the files, the method comprising:

identifying a program that includes a plurality of files;

identifying the SBOM, which corresponds to the program and which includes file declarations for at least some of the files that are incorporated into the program, as well as dependency declarations associated with one or more of the files;

parsing the program to identify a plurality of code segments contained in the plurality of files;

searching one or more repositories of open-source code that is not referenced in the file declarations of the SBOM for any undeclared code segments determined to be within a predetermined threshold of similarity to one or more of the identified plurality of code segments contained in the plurality of files;

for at least one undeclared code segment determined to be within the predetermined threshold of similarity to the one or more identified plurality of code segments, generating a new declaration associated with the at least one undeclared code segment to be added to the SBOM to indicate at least author or source information for the at least one undeclared code segment which is at least partially incorporated into the program; and

generating a modified SBOM by adding the new declaration to the SBOM.

2. The method of claim 1 , wherein adding the new declaration to the SBOM includes:

appending the new declaration to the SBOM;

generating a new identifier for the modified SBOM; and

creating or amending a digital record in an index that associates the new strong-identifier with the program.

3. The method of claim 2 , wherein the method includes amending an existing record in the index that associates a previous identifier of the SBOM with the program.

4. The method of claim 3 , wherein amending the existing record includes adding the new identifier for the modified SBOM to the existing record along with the previous identifier of the SBOM, so that the SBOM and the modified SBOM are both associated with the program by the index.

5. The method of claim 1 , wherein the new declaration comprises an identification of a reference file that is not directly incorporated into the program, but which preceded the program, and which contains the undeclared code segment.

6. The method of claim 1 , wherein the new declaration comprises an identification of the undeclared code segment as a dependency that is relied upon by the one or more of the identified plurality of code segments.

7. The method of claim 1 , wherein the new declaration comprises an identification of a dependency that is relied upon by the undeclared code segment.

8. The method of claim 1 , wherein the method further includes, prior to parsing the program, verifying the program based at least in part on an analysis of an identifier.

9. The method of claim 1 , the method further comprising generating a notification for one or more entities that have installed or acquired the program prior to the new declaration being added to the SBOM, the notification including the modified SBOM.

10. The method of claim 1 , wherein the method further includes generating the SBOM during a build of the program and wherein the generating the modified SBOM occurs prior to deployment of the program to one or more end-users.

11. The method of claim 1 , wherein adding the new declaration to the SBOM includes creating a new SBOM with the new declaration, the new SBOM comprising the modified SBOM and including the new declaration along with a reference to an identifier of the SBOM.

12. A computing system comprising:

one or more hardware processors; and

one or more storage devices having stored computer-executable instructions that are executable by the one more hardware processors for configuring the computing system to perform the following:

identify a program that includes a plurality of files;

identify an SBOM (software bill of materials), which corresponds to the program and which includes file declarations for at least some of the files that are incorporated into the program, as well as dependency declarations associated with one or more of the files;

parse the program to identify a plurality of code segments contained in the plurality of files;

search one or more repositories of open-source code that is not referenced in the file declarations of the SBOM for any undeclared code segments determined to be within a predetermined threshold of similarity to one or more of the identified plurality of code segments contained in the plurality of files;

for at least one undeclared code segment determined to be within the predetermined threshold of similarity to the one or more identified plurality of code segments, generate a new declaration associated with the at least one undeclared code segment to be added to the SBOM to indicate at least author or source information for the at least one undeclared code segment which is at least partially incorporated into the program; and

generate a modified SBOM by adding the new declaration to the SBOM.

13. The computing system of claim 12 , wherein adding the new declaration to the SBOM includes:

appending the new declaration to the SBOM;

generating a new identifier for the modified SBOM; and

creating or amending a digital record in an index that associates the new identifier with the program.

14. The computing system of claim 13 , wherein the computer-executable instructions are further executable for configuring the computing system to amend an existing record in the index that associates a previous identifier of the SBOM with the program.

15. The computing system of claim 12 , wherein the new declaration comprises an identification of a dependency that is relied upon by the undeclared code segment.

16. The computing system of claim 12 , wherein the new declaration comprises an identification of a reference file that is not directly incorporated into the program, but which preceded the program, and which contains the undeclared code segment.

17. The computing system of claim 12 , wherein the computer-executable instructions are further executable for configuring the computing system to generate a notification for one or more entities that have installed or acquired the program prior to the new declaration being added to the SBOM, the notification including the modified SBOM.

18. The computing system of claim 12 , wherein the computer-executable instructions are further executable for configuring the computing system to generate the SBOM during a build of the program and wherein the generating the modified SBOM occurs prior to deployment of the program to one or more end-users.

19. The computing system of claim 12 , wherein adding the new declaration to the SBOM includes creating a new SBOM with the new declaration, the new SBOM comprising the modified SBOM and including the new declaration along with a reference to an identifier of the SBOM.

20. A computer program product comprising one or more storage devices having stored computer-executable instructions that are executable by one more hardware processors of a computing system for configuring the computing system to:

identify a program that includes a plurality of files;

identify an SBOM (software bill of materials), which corresponds to the program and which includes file declarations for at least some of the files that are incorporated into the program, as well as dependency declarations associated with one or more of the files;

parse the program to identify a plurality of code segments contained in the plurality of files;

search one or more repositories of open-source code that is not referenced in the file declarations of the SBOM for any undeclared code segments determined to be within a predetermined threshold of similarity to one or more of the identified plurality of code segments contained in the plurality of files;

for at least one undeclared code segment determined to be within the predetermined threshold of similarity to the one or more identified plurality of code segments, generate a new declaration associated with the at least one undeclared code segment to be added to the SBOM to indicate at least author or source information for the at least one undeclared code segment which is at least partially incorporated into the program; and

generate a modified SBOM by adding the new declaration to the SBOM.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2022
From: BUSSELL, FRANK JOSEPH; LYONS, HENRY JAMES; SCHWERZLER, NICHOLAS ALLAN; YERALAN, SENCER NURI; ROLF, DALE RUSSEL; TRAN, MINH TRONG; JANSON, DAVID JOHN; YARYAN, THOMAS GEORGE; MCCARTY, IAN JAMES
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 059923/0611 →
Continuity (1)
Related Publication 20230367882A1 · Nov 16, 2023
References Cited (38)
US 6202070B1 · Nguyen · 2001 [cited by applicant]
US 8498982B1 · Cope · 2013 [cited by examiner]
US 20150379262A1 · Islam · 2015 [cited by applicant]
US 20160117160A1 · Parthasarathy · 2016 [cited by applicant]
US 20160117161A1 · Parthasarathy · 2016 [cited by examiner]
US 20180136941A1 · Kulick · 2018 [cited by applicant]
US 20190018967A1 · Ramasamy · 2019 [cited by examiner]
US 20190370471A1 · Petratos · 2019 [cited by applicant]
US 20200201620A1 · Beard · 2020 [cited by applicant]
US 20200389496A1 · Xuan · 2020 [cited by applicant]
US 20210021644A1 · Crabtree · 2021 [cited by applicant]
US 20220083652A1 · Ransford · 2022 [cited by applicant]
US 20220398324A1 · Bosch · 2022 [cited by applicant]
US 20230072264A1 · Coccia · 2023 [cited by applicant]
US 20230208880A1 · Schutt · 2023 [cited by applicant]
US 20230244791A1 · Jadhav · 2023 [cited by applicant]
US 20230359744A1 · Duggan · 2023 [cited by applicant]
US 20230367883A1 · Bussell · 2023 [cited by applicant]
The Software Package Data Exchange® (SPDX®) Specification Version 2.3 (Year: 2022). [cited by examiner]
“SBOM at a Glance”, Retrieved From: https://ntia.gov/sites/default/files/publications/sbom_at_a_glance_apr2021_0.pdf, Apr. 27, 2021, 3 Pages. [cited by applicant]
Haas, et al., “Is Static Analysis Able to Identify Unnecessary Source Code?”, In Journal of ACM Transactions on Software Engineering and Methodology, vol. 29, Issue 1, Jan. 30, 2020, 23 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US23/015726”, Mailed Date: Jun. 16, 2023, 11 Pages. (MS# 411132-WO-PCT). [cited by applicant]
Ponta, et al., “The Used, The Bloated, and The Vulnerable: Reducing The Attack Surface of an Industrial Application”, In Proceedings of IEEE International Conference on Software Maintenance and Evolution, Sep. 27, 2021,… [cited by applicant]
Vázquez, et al., “Slimming Javascript Applications: An Approach for removing unused Functions from Javascript Libraries”, In Journal of Information and Software Technology, vol. 107, Mar. 2019, 18-29 pp. [cited by applicant]
“8 File information section”, Retrieved from: https://spdx.github.io/spdx-spec/file-information/, Retrieved Date: Oct. 28, 2021, 17 Pages. [cited by applicant]
“Batch”, Retrieved from: https://web.archive.org/web/20220310075028/https://azure.microsoft.com/en-us/services/batch/, Mar. 10, 2022, 12 pages. [cited by applicant]
“CBOR Object Signing and Encryption (COSE)”, Retrieved from: https://www.iana.org/assignments/cose/cose. xhtml#header-parameters, Jan. 11, 2017, 15 Pages. [cited by applicant]
“The Software Package Data Exchange® (SPDX®) Specification Version 2.2.1”, Retrieved from: https://spdx.github.io/spdx-spec/, Dec. 10, 2021, 1 Page. [cited by applicant]
Bormann, et al., “Concise Binary Object Representation (CBOR)”, Retrieved from: https://datatracker.ietf.org/doc/rfc7049/, Oct. 2013, 46 Pages. [cited by applicant]
Hudek, et al., “DISM Overview”, Retrieved from: https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/what-is-dism?view=windows-11, Dec. 15, 2021, 4 Pages. [cited by applicant]
Schaad, J., “CBOR Object Signing and Encryption (COSE)”, Retrieved from: https://www.rfc-editor.org/rfc/pdfrfc/rfc8152.txt.pdf, Jul. 2017, 121 Pages. [cited by applicant]
Schaad, Jim, “CBOR Object Signing and Encryption (COSE): Structures and Process”, Retrieved from: https://datatracker.ietf.org/doc/draft-ietf-cose-rfc8152bis-struct/15/, Feb. 1, 2021, 59 Pages. [cited by applicant]
Steele, et al., “DID Specification Registries”, Retrieved from: https://w3c.github.io/did-spec-registries/, Mar. 1, 2022, 46 Pages. [cited by applicant]
Non-Final Office Action mailed on Feb. 26, 2024, in U.S. Appl. No. 17/745,698, (MS# 411856-US01) 30 pages. [cited by applicant]
U.S. Appl. No. 17/745,689, filed May 16, 2022. [cited by applicant]
U.S. Appl. No. 17/745,698, filed May 16, 2022. [cited by applicant]
Final Office Action mailed on Sep. 6, 2024, in U.S. Appl. No. 17/745,698, 42 pages. [cited by applicant]
Non-Final Office Action mailed on Aug. 23, 2024, in U.S. Appl. No. 17/745,689, 17 pages. [cited by applicant]