IP Library › Granted Patent US 12,724,903
Granted Patent B1
US 12,724,903 · App. 19/447,313 · Granted Sep 1, 2026

Vulnerability analysis using pre-computed reachability information for software components

Inventors: Anand Ashok Sawant (Davis, CA); Georgios Gousios (Delft, NL); Varun Badhwar (Palo Alto, CA)
Assignee: Endor Labs Inc
G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,724,903
App. No.
19/447,313
Granted
Sep 1, 2026
Kind
B1
Abstract

Techniques are disclosed for performing vulnerability analysis based on pre-computed reachability information of software components. A system may obtain a first software component, perform call-path tracing from functions of the first software component to at least one function of a second software component to identify functions that are reachable via at least one call path originating in the first software component as reachable functions, and compute, in association with the first software component, a pre-computed reachable dataset comprising the reachable functions. The system may obtain a project dependency listing that identifies software components including the first software component to be used by a software project and generate a vulnerability report based at least in part on the pre-computed reachable dataset, the vulnerability report identifying functions of the reachable functions of the first software component that are vulnerable.

Claims (52)

1 . A computer-implemented method comprising:

obtaining a first software component for reachability analysis;

performing call-path tracing from functions of the first software component to at least one function of a second software component to identify functions that are reachable via at least one call path originating in the first software component as reachable functions of the first software component, the reachable functions of the first software component including the at least one function of the second software component;

computing, in association with the first software component, a pre-computed reachable dataset comprising the reachable functions of the first software component;

obtaining a project dependency listing that identifies a plurality of software components used by a software project, the plurality of software components including the first software component; and

generating a vulnerability report for the software project based at least in part on the pre-computed reachable dataset of the first software component, the vulnerability report identifying one or more functions of the reachable functions of the first software component that are vulnerable as vulnerable functions.

2 . The computer-implemented method of claim 1 , wherein generating the vulnerability report for the software project further comprises retrieving, from a vulnerability database, specific vulnerability details for the reachable functions of the first software component.

3 . The computer-implemented method of claim 1 , wherein the performing the call-path tracing and computing the pre-computed reachable dataset are performed separately for a plurality of different versions of the first software component to compute, for the plurality of different versions, distinct pre-computed reachable datasets.

4 . The computer-implemented method of claim 1 , wherein performing the call-path tracing continues, from the second software component, to at least one dependent software component of the second software component and the vulnerability report excludes vulnerable functions of the at least one dependent software component that are not reachable via call paths originating in the first software component.

5 . The computer-implemented method of claim 1 , wherein performing the call-path tracing continues, from the second software component, to at least one dependent software component of the second software component and comprises locating potential entry points in direct dependencies of the first software component and calculating reachability from these entry points.

6 . The computer-implemented method of claim 5 , wherein performing the call-path tracing from functions of the first software component comprises, when call paths within a private dependency of the first software component are unavailable, flattening direct dependencies of the private dependency by treating entry points of direct dependencies of the private dependency as additional entry points for the call-path tracing.

7 . The computer-implemented method of claim 1 , further comprising:

building, based on the call-path tracing, a graph of reachable calls that spans a network of interconnected software components by tracing calls that propagate between the interconnected software components, the building comprising:

adding directly accessible calls of the first software component that are accessible when invoking the first software component to the graph; and

linking, in the graph, transitively accessible calls in the interconnected software components to the directly accessible calls;

wherein the network of interconnected software components includes the first software component and the second software component;

wherein the transitively accessible calls are calls that are directly or indirectly invoked by directly accessible calls of the first software component; and

wherein the call-path tracing is based at least in part on the graph of reachable calls.

8 . The computer-implemented method of claim 1 , further comprising:

populating a database of vulnerable functions with descriptions of security vulnerabilities for functions of a network of interconnected software components that includes the first software component and the second software component,

wherein:

populating the database comprises creating records for functions that are included in a list of common vulnerabilities and exposures (CVE) records and annotating the records with additional information about vulnerabilities found in the functions; and

the performing the call-path tracing is based at least in part on the database of vulnerable functions.

9 . The computer-implemented method of claim 1 , wherein:

the performing the call-path tracing and the computing the pre-computed reachable dataset are performed, prior to the obtaining the project dependency listing, for software components of a plurality of different software components to store respective pre-computed reachable datasets in association with individual software components of the plurality of different software components.

10 . The computer-implemented method of claim 1 , wherein the call-path tracing is performed using static analysis of source code, bytecode, or binary artifacts.

11 . The computer-implemented method of claim 1 , wherein the first software component is a library.

12 . A system comprising:

at least one processor; and

a non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the system to:

obtain a first software component for reachability analysis;

perform call-path tracing from functions of the first software component to at least one function of a second software component to identify, as reachable functions of the first software component, functions that are reachable via at least one call path originating in the first software component, the reachable functions of the first software component including the at least one function of the second software component;

compute, in association with the first software component, a pre-computed reachable dataset comprising the reachable functions of the first software component;

obtain a project dependency listing that identifies a plurality of software components used by a software project, the plurality of software components including the first software component; and

generate a vulnerability report for the software project based at least in part on the pre-computed reachable dataset of the first software component, the vulnerability report identifying vulnerable functions of the reachable functions of the first software component that are vulnerable.

13 . The system of claim 12 , wherein generating the vulnerability report for the software project further comprises retrieving specific vulnerability details for the reachable functions of the first software component from a vulnerability database.

14 . The system of claim 12 , wherein obtaining the first software component, performing the call-path tracing, and computing the pre-computed reachable dataset are performed separately for a plurality of different versions of the first software component to compute distinct pre-computed reachable datasets for the plurality of different versions.

15 . The system of claim 12 , wherein performing the call-path tracing continues, from the second software component, to at least one dependent software component of the second software component and the vulnerability report excludes vulnerable functions of the at least one dependent software component that are not reachable via call paths originating in the first software component.

16 . The system of claim 12 , wherein performing the call-path tracing continues, from the second software component, to at least one dependent software component of the second software component and comprises locating potential entry points in direct dependencies of the first software component and calculating reachability from these entry points.

17 . The system of claim 16 , wherein performing the call-path tracing from functions of the first software component comprises, when call paths within a private dependency of the first software component are unavailable, flattening direct dependencies of the private dependency by treating entry points of direct dependencies of the private dependency as additional entry points for the call-path tracing.

18 . The system of claim 12 , wherein the instructions further cause the system to:

build, based on the call-path tracing, a graph of reachable calls that spans a network of interconnected software components by tracing calls that propagate between the interconnected software components, the building comprising:

adding directly accessible calls of the first software component that are accessible when invoking the first software component to the graph; and

linking, in the graph, transitively accessible calls in the interconnected software components to the directly accessible calls;

wherein the network of interconnected software components includes the first software component and the second software component;

wherein the transitively accessible calls are calls that are directly or indirectly invoked by directly accessible calls of the first software component; and

wherein the call-path tracing is based at least in part on the graph of reachable calls.

19 . The system of claim 12 , wherein the instructions further cause the system to:

populate a database of vulnerable functions with descriptions of security vulnerabilities for functions of a network of interconnected software components that includes the first software component and the second software component, wherein populating the database comprises creating records for functions that are included in a list of common vulnerabilities and exposures (CVE) records and annotating the records with additional information about vulnerabilities found in the functions; and

wherein the performing the call-path tracing is based at least in part on the database of vulnerable functions.

20 . The system of claim 12 , wherein:

the performing the call-path tracing and the computing the pre-computed reachable dataset are performed, prior to the obtaining the project dependency listing, for software components of a plurality of different software components to store respective pre-computed reachable datasets in association with individual software components of the plurality of different software components.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2026
From: SAWANT, ANAND ASHOK; GOUSIOS, GEORGIOS; BADHWAR, VARUN
To: ENDOR LABS INC
Reel/Frame 073621/0910 →
Continuity (1)
Provisional Application 63943446 · Dec 17, 2025
References Cited (12)
US 6513133B1 · Campbell · 2003 [cited by examiner]
US 9189365B2 · Frazier · 2015 [cited by examiner]
US 9811434B1 · Wagner · 2017 [cited by examiner]
US 9998562B1 · Peterson · 2018 [cited by examiner]
US 11487854B2 · Kwak · 2022 [cited by examiner]
US 12659345B1 · Aboukhadijeh et al. · 2026 [cited by applicant]
US 12664289B1 · Aboukhadijeh et al. · 2026 [cited by applicant]
US 20070234300A1 · Leake · 2007 [cited by examiner]
US 20220392486A1 · Binnamangala Prabhu · 2022 [cited by examiner]
US 20260141062A1 · Aboukhadijeh et al. · 2026 [cited by applicant]
H. Li, T. Kim, M. Bat-Erdene and H. Lee, “Software Vulnerability Detection Using Backward Trace Analysis and Symbolic Execution ,”2013 International Conference on Availability, Reliability and Security, Regensburg, Germ… [cited by examiner]
Koala, Gouayon, et al. “Software vulnerabilities' detection by analysing application execution traces.” International Journal of Advanced Computer Science and Applications 14.6 (2023). (Year: 2023). [cited by examiner]