IP Library › Granted Patent US 12,536,276
Granted Patent B1
US 12,536,276 · App. 19/233,602 · Granted Jan 27, 2026

Techniques for securing software components through security packages defined in software image recipes

Inventors: John Morello (Baton Rouge, LA); Ben Bernstein (New York, NY); Dima Stopel (Herzliya, IL)
Assignee: MINIMUS LTD
G06F21/54G06F21/62G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,276
App. No.
19/233,602
Granted
Jan 27, 2026
Kind
B1
Abstract

A system and method for software image management. A method includes generating a plurality of software packages including a plurality of units of code, wherein each software package is generated using a respective unit of code of the plurality of units of code, wherein the plurality of software packages includes a security package, wherein the respective unit of code for the security package configures a processing circuitry to perform at least one cybersecurity function when executed by the processing circuitry; and building a software image based on the plurality of software packages by executing a set of instructions of a file, wherein the set of instructions causes the plurality of software packages to be combined in order to build the software image when executed.

Claims (46)

1 . A method for software image management, comprising:

generating a plurality of software packages including a plurality of units of code, wherein each software package of the plurality of software packages is generated using a respective unit of code of the plurality of units of code, wherein the plurality of software packages includes a first security package, wherein the respective unit of code for the security package configures a processing circuitry to perform at least one cybersecurity function when executed by the processing circuitry; and

building a software image based on the plurality of software packages by executing a set of instructions of a file, wherein the set of instructions causes the plurality of software packages to be combined in order to build the software image when executed, wherein the software image is executed to deploy a software component in a computing environment;

ingesting cybersecurity data from the computing environment in which the software component is deployed;

identifying a cybersecurity threat based on the ingested cybersecurity data, wherein the cybersecurity threat is identified with respect to at least one threat vector; and

rebuilding the software image, wherein rebuilding the software image includes adding a second security package, wherein the second security package is designed to secure the software image against the cybersecurity threat, wherein the second security package is further designed to secure the software image against the at least one threat vector.

2 . The method of claim 1 , further comprising:

rebuilding the software image using an updated version of at least one unit of code of the plurality of units of code.

3 . The method of claim 2 , further comprising:

monitoring for changes to the plurality of units of code; and

identifying an update based on the monitoring, wherein the update includes a change in the at least one unit of code, wherein the updated version of the at least one unit of code is based on the update.

4 . The method of claim 2 , further comprising:

identifying a type of cybersecurity threat with respect to the software image, wherein the updated version of the at least one unit of code used to rebuild the software image is secured against the type of cybersecurity threat.

5 . The method of claim 1 , further comprising:

generating the file using a generative artificial intelligence (genAI) model by prompting the genAI model using a prompt including text identifying the plurality of packages.

6 . The method of claim 5 , further comprising:

providing the genAI model access to at least one tool by prompting the genAI model using a prompt including text describing how to use the at least one tool, wherein the genAI model access the at least one tool in order to obtain the plurality of units of code.

7 . The method of claim 1 , further comprising:

executing the software image in order to cause deployment of a software component in a computing environment.

8 . A non-transitory computer-readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

generating a plurality of software packages including a plurality of units of code, wherein each software package of the plurality of software packages is generated using a respective unit of code of the plurality of units of code, wherein the plurality of software packages includes a first security package, wherein the respective unit of code for the security package configures a processing circuitry to perform at least one cybersecurity function when executed by the processing circuitry; and

building a software image based on the plurality of software packages by executing a set of instructions of a file, wherein the set of instructions causes the plurality of software packages to be combined in order to build the software image when executed, wherein the software image is executed to deploy a software component in a computing environment;

ingesting cybersecurity data from the computing environment in which the software component is deployed;

identifying a cybersecurity threat based on the ingested cybersecurity data, wherein the cybersecurity threat is identified with respect to at least one threat vector; and

rebuilding the software image, wherein rebuilding the software image includes adding a second security package, wherein the second security package is designed to secure the software image against the cybersecurity threat, wherein the second security package is further designed to secure the software image against the at least one threat vector.

9 . A system for software image management, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

generate a plurality of software packages including a plurality of units of code, wherein each software package of the plurality of software packages is generated using a respective unit of code of the plurality of units of code, wherein the plurality of software packages includes a first security package, wherein the respective unit of code for the security package configures a processing circuitry to perform at least one cybersecurity function when executed by the processing circuitry; and

build a software image based on the plurality of software packages by executing a set of instructions of a file, wherein the set of instructions causes the plurality of software packages to be combined in order to build the software image when executed, wherein the software image is executed to deploy a software component in a computing environment;

ingest cybersecurity data from the computing environment in which the software component is deployed;

identify a cybersecurity threat based on the ingested cybersecurity data, wherein the cybersecurity threat is identified with respect to at least one threat vector; and

rebuild the software image, wherein rebuilding the software image includes adding a second security package, wherein the second security package is designed to secure the software image against the cybersecurity threat, wherein the second security package is further designed to secure the software image against the at least one threat vector.

10 . The system of claim 9 , wherein the system is further configured to:

rebuild the software image using an updated version of at least one unit of code of the plurality of units of code.

11 . The system of claim 10 , wherein the system is further configured to:

monitor for changes to the plurality of units of code; and

identify an update based on the monitoring, wherein the update includes a change in the at least one unit of code, wherein the updated version of the at least one unit of code is based on the update.

12 . The system of claim 10 , wherein the system is further configured to:

identify a type of cybersecurity threat with respect to the software image, wherein the updated version of the at least one unit of code used to rebuild the software image is secured against the type of cybersecurity threat.

13 . The system of claim 9 , wherein the system is further configured to:

generate the file using a generative artificial intelligence (genAI) model by prompting the genAI model using a prompt including text identifying the plurality of packages.

14 . The system of claim 13 , wherein the system is further configured to:

provide the genAI model access to at least one tool by prompting the genAI model using a prompt including text describing how to use the at least one tool, wherein the genAI model access the at least one tool in order to obtain the plurality of units of code.

15 . The system of claim 9 , wherein the system is further configured to:

execute the software image in order to cause deployment of a software component in a computing environment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2026
From: MINIMUS LTD
To: ECHO SOFTWARE LTD.
Reel/Frame 075796/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2025
From: MORELLO, JOHN; BERNSTEIN, BEN; STOPEL, DIMA
To: MINIMUS LTD
Reel/Frame 071376/0236 →
References Cited (40)
US 9959104B2 · Chen et al. · 2018 [cited by applicant]
US 9983891B1 · Christensen · 2018 [cited by applicant]
US 10505830B2 · Mishalov et al. · 2019 [cited by applicant]
US 10885378B2 · Li et al. · 2021 [cited by applicant]
US 11062022B1 · Kalamkar et al. · 2021 [cited by applicant]
US 11182140B2 · Riek et al. · 2021 [cited by applicant]
US 11599348B2 · Goldmann et al. · 2023 [cited by applicant]
US 11669362B2 · Singh et al. · 2023 [cited by applicant]
US 11972333B1 · Horesh et al. · 2024 [cited by applicant]
US 12095806B1 · Nemtsov et al. · 2024 [cited by applicant]
US 12099414B2 · Mitkar et al. · 2024 [cited by applicant]
US 12242994B1 · Aggarwal · 2025 [cited by examiner]
US 12267345B1 · Erlingsson et al. · 2025 [cited by applicant]
US 20110225574A1 · Khalidi et al. · 2011 [cited by applicant]
US 20120110333A1 · Lukkarila et al. · 2012 [cited by applicant]
US 20120324446A1 · Fries et al. · 2012 [cited by applicant]
US 20150365437A1 · Bell, Jr. et al. · 2015 [cited by applicant]
US 20170147813A1 · McPherson et al. · 2017 [cited by applicant]
US 20190347127A1 · Coady et al. · 2019 [cited by applicant]
US 20200159536A1 · Saidi · 2020 [cited by applicant]
US 20200213357A1 · Levin · 2020 [cited by examiner]
US 20200285504A1 · Siegmund · 2020 [cited by applicant]
US 20200326931A1 · Nadgowda et al. · 2020 [cited by applicant]
US 20210157623A1 · Chandrashekar et al. · 2021 [cited by applicant]
US 20210208916A1 · Wang et al. · 2021 [cited by applicant]
US 20210255840A1 · Novy · 2021 [cited by applicant]
US 20210319109A1 · Weng et al. · 2021 [cited by applicant]
US 20220147378A1 · Tarasov et al. · 2022 [cited by applicant]
US 20220166626A1 · Madisetti et al. · 2022 [cited by applicant]
US 20230168986A1 · Larkin et al. · 2023 [cited by applicant]
US 20240069883A1 · Griffin · 2024 [cited by examiner]
US 20240103833A1 · Shemer et al. · 2024 [cited by applicant]
US 20240134967A1 · Yaron et al. · 2024 [cited by applicant]
US 20240411674A1 · Zmigrod et al. · 2024 [cited by applicant]
US 20250004741A1 · Hubik · 2025 [cited by applicant]
US 20250123819A1 · Khemka et al. · 2025 [cited by applicant]
US 20250156535A1 · Keller et al. · 2025 [cited by applicant]
CN 111522628A · 2020 [cited by applicant]
“Announcing ‘Yum + RPM for Containerized Applications’—Nulecule & Atomic App,” Red Hat Blog (Jun. 23, 2015) (available at https://www.redhat.com/en/blog/announcing-yum-rpm-containerized-applications-nulecule-atomic-app)… [cited by applicant]
Ian Gorton et al.; Components in the Pipeline; IEEE; pp. 34-40; retrieved on Jul. 18, 2025 (Year: 2025). [cited by applicant]