Augmented SBOM Analysis for Automated Software Supply Chain Risk
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods are inefficient and error-prone for integrators/consumers to verify adherence of software code to software development standards, particularly in detecting security risks from software supply chain attacks, as they rely on manual verification of supplier-provided artifacts.
Innovation Solution
Augmenting the Software Bill of Materials (SBOM) with information about software development standards, processes, and activities to automatically assess compliance and identify potential security risks, including vulnerabilities and licensing issues, using a SBOM analyzer to generate a risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual verification of supplier-provided artifacts is used to verify adherence to software development standards, then verification can be performed, but the process is inefficient and error-prone
Solution Approach 1:
The patent replaces manual verification processes with automated computational analysis. The SBOM analyzer automatically processes software component information, vulnerability data, and license information to generate risk assessments, eliminating the need for manual review of supplier artifacts while improving both accuracy and efficiency.
Solution Approach 2:
The system enables automatic self-verification of software compliance and security. The SBOM analyzer independently evaluates software components against security criteria and generates risk assessments without requiring manual intervention, allowing the system to verify its own compliance status automatically.
2Reliability
If manual verification methods are used to detect security risks from software supply chain attacks, then risk detection can be performed, but the process is time-consuming and labor-intensive
Solution Approach 1:
The system performs preliminary security analysis by automatically evaluating software components, vulnerabilities, and licenses before deployment. The SBOM analyzer continuously monitors and assesses risk factors in advance, enabling early detection of security issues without requiring time-consuming manual verification later.
Solution Approach 2:
Manual security verification is replaced with automated computational analysis that rapidly processes vulnerability databases, license information, and software component data to detect security risks, significantly reducing the time required for security assessment.
3Measurement precision
If comprehensive software component information is collected for risk assessment, then detection accuracy improves, but data processing complexity increases
Solution Approach 1:
The patent segments the risk assessment process into distinct automated analysis modules within the SBOM analyzer. Each module handles specific aspects such as vulnerability scanning, license verification, and component validation independently, managing complex data processing through structured segmentation while maintaining high assessment accuracy.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, methods, and software can be used to identify security risks in software code based on Software Bill of Materials (SBOM). In some aspects, a method includes: obtaining, by a server, software code and a SBOM corresponding to the software code; identifying, by the server and based on the SBOM, a library used by the software code; and generating, by the server, a risk assessment based on at least one metric corresponding to the library, where the at least one metric is associated with one or more maintainers of the library.