IP Library › Granted Patent US 12,554,862
Granted Patent B2
US 12,554,862 · App. 18/737,485 · Granted Feb 17, 2026

Integrated security analysis data structure and method for multi-container software projects

Inventors: Apoorva Dubey (Castro Valley, CA); Chen Lin (Beijing, CN)
Assignee: Schlumberger Technology Corporation
G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,554,862
App. No.
18/737,485
Filed
Jun 7, 2024
Granted
Feb 17, 2026
Kind
B2
Examiner
LI, MENG
Art Unit
2437
USPC
726/25
Abstract

An integrated security analysis data structure and a method for multi-container software projects. A data repository storing containers and a software bill of materials (SBOM) is queried. The SBOM includes first data describing the containers and second data describing software images in the containers. The software images include corresponding components. The SBOM further includes metadata about the containers, the software images, and the one or more corresponding components. A dependency graph, showing dependencies among the software images, of the software images is built automatically. Usage data describing usage of the containers as deployed in an enterprise system is retrieved automatically. The SBOM, the dependency graph, and the usage data are transformed into a SBOM data structure. The SBOM data structure includes a searchable data object that is searchable by: the containers, the software images, the one or more corresponding components of the software images, the metadata, and the usage data.

Claims (95)

1 . A method comprising:

generating, by querying a data repository storing a plurality of containers, a software bill of materials (SBOM), wherein:

the SBOM comprises first data describing the plurality of containers,

the SBOM comprises second data describing a plurality of software images contained in the plurality of containers, each of the plurality of software images comprising one or more corresponding components, and

the SBOM further comprises metadata about the plurality of containers, the plurality of software images, and the one or more corresponding components;

building, automatically, a dependency graph of the plurality of software images, wherein the dependency graph shows dependencies among the plurality of software images;

retrieving, automatically, usage data describing usage of the plurality of containers as deployed in an enterprise system; and

transforming the SBOM, the dependency graph, and the usage data into a SBOM data structure, wherein the SBOM data structure comprises a searchable data object that is searchable by: the plurality of containers, the plurality of software images, the one or more corresponding components of the plurality of software images, the metadata, and the usage data.

2 . The method of claim 1 , further comprising:

storing the SBOM data structure in a non-transitory computer readable storage medium.

3 . The method of claim 1 , wherein the SBOM data structure maps component usage, application deployment, and vulnerability information together.

4 . The method of claim 1 , further comprising:

detecting a cyber vulnerability in a component of the enterprise system, the component being among the one or more corresponding components for one or more of the plurality of software images;

querying the SBOM data structure to determine a particular software image, in the plurality of software images, that includes the component; and

remediating the component in the particular software image to generate a remediated software image.

5 . The method of claim 4 , further comprising:

generating a revised SBOM data structure by repeating generating, building, retrieving, and transforming using the remediated software image; and

storing the revised SBOM data structure in a non-transitory computer readable storage medium.

6 . The method of claim 4 , wherein remediating comprises at least one of:

updating a library in the particular software image;

updating an open-source executable file in the particular software image;

replacing the component with a revised component;

removing the component from the particular software image; and

replacing the particular software image with a new software image.

7 . The method of claim 1 , further comprising:

detecting a cyber vulnerability in a component of the enterprise system, the component being among the one or more corresponding components for one or more of the plurality of software images;

querying the SBOM data structure to determine a particular software image, in the plurality of software images, that includes the component; and

transmitting a notification to a user device the particular software image contains the component.

8 . The method of claim 1 , further comprising:

receiving an updated component;

querying the SBOM data structure to determine a particular software image, in the plurality of software images, that includes an old component, that is older than the updated component, which corresponds to the updated component; and

updating the particular software image using the updated component.

9 . A non-transitory computer readable storage medium storing program code, which when executed by a processor, performs a computer-implemented algorithm comprising:

generating, by querying a data repository storing a plurality of containers, a software bill of materials (SBOM), wherein:

the SBOM comprises first data describing the plurality of containers,

the SBOM comprises second data describing a plurality of software images contained in the plurality of containers, each of the plurality of software images comprising one or more corresponding components, and

the SBOM further comprises metadata regarding the plurality of containers, the plurality of software images, and the one or more corresponding components;

building, automatically, a dependency graph of the plurality of software images, wherein the dependency graph shows dependencies among the plurality of software images;

retrieving, automatically, usage data describing usage of the plurality of containers as deployed in an enterprise system;

transforming the SBOM, the dependency graph, and the usage data into a SBOM data structure, wherein the SBOM data structure comprises a searchable data object that is searchable by: the plurality of containers, the plurality of software images, the one or more corresponding components of the plurality of software images, the metadata, and the usage data; and

storing the SBOM data structure in the non-transitory computer readable storage medium.

10 . The non-transitory computer readable storage medium of claim 9 , wherein the computer-implemented algorithm further comprises:

detecting a cyber vulnerability in a component of the enterprise system, the component being among the one or more corresponding components for one or more of the plurality of software images;

querying the SBOM data structure to determine a particular software image, in the plurality of software images, that includes the component; and

remediating the component in the particular software image to generate a remediated software image.

11 . The non-transitory computer readable storage medium of claim 10 , wherein the computer-implemented algorithm further comprises:

generating a revised SBOM data structure by repeating generating, building, retrieving, and transforming using the remediated software image; and

storing the revised SBOM data structure in the non-transitory computer readable storage medium.

12 . The non-transitory computer readable storage medium of claim 10 , wherein, in the computer-implemented algorithm, remediating comprises at least one of:

updating a library in the particular software image;

updating an open-source executable file in the particular software image;

replacing the component with a revised component;

removing the component from the particular software image; and

replacing the particular software image with a new software image.

13 . The non-transitory computer readable storage medium of claim 9 , wherein the computer-implemented algorithm further comprises:

detecting a cyber vulnerability in a component of the enterprise system, the component being among the one or more corresponding components for one or more of the plurality of software images;

querying the SBOM data structure to determine a particular software image, in the plurality of software images, that includes the component; and

transmitting a notification to a user device the particular software image contains the component.

14 . The non-transitory computer readable storage medium of claim 9 , wherein the computer-implemented algorithm further comprises:

receiving an updated component;

querying the SBOM data structure to determine a particular software image, in the plurality of software images, that includes an old component, that is older than the updated component, which corresponds to the updated component; and

updating the particular software image using the updated component.

15 . A system comprising:

a processor;

a data repository in communication with the processor and storing:

a plurality of containers containing a plurality of software images, wherein each of the plurality of software images comprises one or more corresponding components,

a software bill of materials (SBOM) comprising:

first data describing the plurality of containers,

second data describing the plurality of software images contained in the plurality of containers, and

metadata regarding the plurality of containers, the plurality of software images, and the one or more corresponding components,

a dependency graph of the plurality of software images, wherein the dependency graph shows dependencies among the plurality of software images,

usage data describing usage of the plurality of containers as deployed in an enterprise system, and

a SBOM data structure comprising a searchable data object that is searchable by: the plurality of containers, the plurality of software images, the one or more corresponding components of the plurality of software images, the metadata, and the usage data;

a dependency graph generator programmed, when executed by the processor, to build the dependency graph;

a query engine programmed, when executed by the processor, to retrieve the usage data; and

a data structure generator programmed, when executed by the processor, to transform the SBOM, the dependency graph, and the usage data into the SBOM data structure.

16 . The system of claim 15 , further comprising:

a software vulnerability detector programmed, when executed by the processor, to:

detect a cyber vulnerability in a component of the one or more corresponding components;

query the SBOM data structure to determine a particular software image, in the plurality of software images, that includes the component; and

remediate the component in the particular software image to generate a remediated software image.

17 . The system of claim 16 , wherein the data structure generator is further programmed, when executed by the processor, to:

generate a revised SBOM data structure by repeating generating, building, retrieving, and transforming using the remediated software image; and

store the revised SBOM data structure in the data repository.

18 . The system of claim 15 , further comprising:

a software vulnerability detector programmed, when executed by the processor, to:

detect a cyber vulnerability in a component of the one or more corresponding components;

query the SBOM data structure to determine a particular software image, in the plurality of software images, that includes the component; and

transmit a notification to a user device the particular software image contains the component.

19 . The system of claim 15 , further comprising:

an update engine programmed, when executed by the processor, to:

receive an updated component;

query the SBOM data structure to determine a particular software image, in the plurality of software images, that includes an old component, that is older than the updated component, which corresponds to the updated component; and

update the particular software image using the updated component.

20 . The system of claim 15 , wherein the SBOM data structure maps component usage, application deployment, and vulnerability information together.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2024
From: DUBEY, APOORVA; LIN, CHEN
To: SCHLUMBERGER TECHNOLOGY CORPORATION
Reel/Frame 067666/0675 →
Continuity (2)
Provisional Application 63507157 · Jun 9, 2023
Related Publication 20240411895A1 · Dec 12, 2024
References Cited (10)
US 11507672B1 · Pagnozzi · 2022 [cited by examiner]
US 20190294780A1 · Melamed · 2019 [cited by examiner]
US 20240022609A1 · Smith · 2024 [cited by examiner]
US 20240169062A1 · Lee · 2024 [cited by examiner]
US 20240176888A1 · Sahar-Kaneti · 2024 [cited by examiner]
US 20240289745A1 · Larkin · 2024 [cited by examiner]
US 20240330474A1 · Plunk · 2024 [cited by examiner]
US 20240338459A1 · Lukas · 2024 [cited by examiner]
US 20250175456A1 · Crabtree · 2025 [cited by examiner]
Anchore. Software Bill of Materials (SBOM) Management. SBOM Management Solutions. Available at: https://anchore.com/sbom/. [cited by applicant]