Agentless SBOM Generation for Cloud Workload Vulnerability Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity measures struggle to effectively manage and mitigate vulnerabilities in cloud computing environments due to the complexity of tracking software components across numerous workloads and devices.
Innovation Solution
A system and method that involves accessing workloads in a cloud computing environment, detecting software components, generating a software bill of materials (SBOM) for each workload, and storing these SBOMs in a database. This system also includes features for periodic updates, difference detection, and initiation of mitigation actions based on vulnerability assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional vulnerability management methods are used in cloud environments, then known vulnerabilities can be identified through CVE databases, but the complexity of tracking software components across hundreds or thousands of devices and workloads makes effective vulnerability management impractical
Solution Approach 1:
The patent segments the cloud environment into individual workload units, each with its own software bill of materials (SBOM). By dividing the complex ecosystem of hundreds or thousands of devices into manageable workload segments, the system can track software components and vulnerabilities at a granular level without being overwhelmed by overall system complexity. Each workload's SBOM serves as an independent inventory that can be managed separately.
Solution Approach 2:
The patent introduces an intermediary database that stores SBOMs for multiple workloads, serving as a mediator between the complex cloud environment and vulnerability assessment processes. This intermediary layer consolidates software component information from numerous workloads into a structured format, enabling efficient vulnerability matching without directly managing the complexity of individual device inventories.
2Reliability
If comprehensive software inventories are maintained for all workloads, then vulnerability assessment capability is improved, but the time and resources required to generate and maintain up-to-date SBOMs increase
Solution Approach 1:
The patent performs preliminary actions by generating SBOMs for workloads in advance and storing them in a database before vulnerability assessments are needed. This pre-computation approach ensures that software component inventories are already prepared and organized, eliminating the need for time-consuming inventory generation during actual vulnerability assessment events. The SBOMs serve as pre-prepared data structures that can be quickly queried and matched against vulnerability databases.
3Loss of information
If manual tracking of software components is performed, then detailed inventory information can be obtained, but the process becomes impractical for environments with hundreds or thousands of devices
Solution Approach 1:
The patent implements self-service by enabling the system to automatically generate, maintain, and update SBOMs for workloads without manual intervention. The automated processes scan workloads, extract software component information, and populate the database independently, eliminating the need for manual inventory tracking while maintaining complete and accurate software component information across all workloads.
Solution Approach 2:
The patent replaces manual mechanical tracking processes with automated computational systems. Instead of human operators manually inventorying software components across thousands of devices, the system uses automated scanning, data extraction, and database population mechanisms that efficiently handle large-scale inventory management without human intervention, dramatically improving productivity while maintaining information completeness.
Data Source
AI summary
A system and method for agentless generation of a software bill of materials (SBOM) in a cloud computing environment is disclosed. The method includes: accessing a plurality of workloads in a cloud computing environment; detecting in each workload of the plurality of workloads a software component; generating for each workload an SBOM based on the detected software component; and storing each SBOM in a database.


