Agentless SBOM Generation for Cloud Workload Vulnerability Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity measures struggle to effectively manage and mitigate vulnerabilities in cloud computing environments due to the complexity of tracking software components across numerous workloads and devices.

Innovation Solution

A system and method that involves accessing workloads in a cloud computing environment, detecting software components, generating a software bill of materials (SBOM) for each workload, and storing these SBOMs in a database. This system also includes features for periodic updates, difference detection, and initiation of mitigation actions based on vulnerability assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional vulnerability management methods are used in cloud environments, then known vulnerabilities can be identified through CVE databases, but the complexity of tracking software components across hundreds or thousands of devices and workloads makes effective vulnerability management impractical

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the cloud environment into individual workload units, each with its own software bill of materials (SBOM). By dividing the complex ecosystem of hundreds or thousands of devices into manageable workload segments, the system can track software components and vulnerabilities at a granular level without being overwhelmed by overall system complexity. Each workload's SBOM serves as an independent inventory that can be managed separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary database that stores SBOMs for multiple workloads, serving as a mediator between the complex cloud environment and vulnerability assessment processes. This intermediary layer consolidates software component information from numerous workloads into a structured format, enabling efficient vulnerability matching without directly managing the complexity of individual device inventories.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive software inventories are maintained for all workloads, then vulnerability assessment capability is improved, but the time and resources required to generate and maintain up-to-date SBOMs increase

Engineering Contradiction:
Improvevulnerability assessment reliabilityVSAvoidSBOM generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by generating SBOMs for workloads in advance and storing them in a database before vulnerability assessments are needed. This pre-computation approach ensures that software component inventories are already prepared and organized, eliminating the need for time-consuming inventory generation during actual vulnerability assessment events. The SBOMs serve as pre-prepared data structures that can be quickly queried and matched against vulnerability databases.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If manual tracking of software components is performed, then detailed inventory information can be obtained, but the process becomes impractical for environments with hundreds or thousands of devices

Engineering Contradiction:
Improvesoftware component information completenessVSAvoidinventory management efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent implements self-service by enabling the system to automatically generate, maintain, and update SBOMs for workloads without manual intervention. The automated processes scan workloads, extract software component information, and populate the database independently, eliminating the need for manual inventory tracking while maintaining complete and accurate software component information across all workloads.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical tracking processes with automated computational systems. Instead of human operators manually inventorying software components across thousands of devices, the system uses automated scanning, data extraction, and database population mechanisms that efficiently handle large-scale inventory management without human intervention, dramatically improving productivity while maintaining information completeness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250182052A1System and method for agentless application inventory detection
Publication Date: 2025.06.05 WIZ INC
  • US20250182052A1 patent drawing
  • US20250182052A1 patent drawing
  • US20250182052A1 patent drawing

AI summary

A system and method for agentless generation of a software bill of materials (SBOM) in a cloud computing environment is disclosed. The method includes: accessing a plurality of workloads in a cloud computing environment; detecting in each workload of the plurality of workloads a software component; generating for each workload an SBOM based on the detected software component; and storing each SBOM in a database.