Multi-Computer Vulnerability Analysis System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face challenges in understanding and mitigating risks associated with software products due to the complexity of open source and vendor software, as well as the difficulty in correlating software sources with current events in real-time.

Innovation Solution

A multi-computer system that receives and analyzes software bill of materials (SBOM) data, author data, and current event data using natural language processing and machine learning to generate confidence scores and alerts for potential software vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software products use open source and vendor software components, then functionality and versatility are improved, but understanding software components and assessing risks becomes more difficult

Engineering Contradiction:
Improvesoftware functionalityVSAvoidsoftware component complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments software products into individual components and tracks each component separately through SBOM data collection. This allows the system to manage complexity by breaking down large software systems into smaller, traceable units while maintaining full functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary analysis platform that sits between the complex software components and the risk assessment process. This intermediary automatically collects, analyzes, and correlates component data, making the complex software landscape understandable and assessable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time monitoring of software vulnerabilities is implemented, then security and reliability are improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvesoftware securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by continuously collecting and analyzing SBOM data and software attributes before vulnerabilities are exploited. This proactive approach enables early risk identification and mitigation without requiring complex real-time intervention systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where vulnerability data, software attributes, and risk assessments continuously inform each other. This automated feedback mechanism maintains high security and reliability while managing system complexity through self-adjusting analysis processes.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive software attribute and author data collection is performed, then measurement precision and risk assessment accuracy are improved, but data processing time and computational resources increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by prioritizing the collection and analysis of the most critical software attributes and author data. Rather than processing all possible data equally, it focuses on high-impact factors that provide the greatest risk assessment accuracy with reasonable processing time.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts data collection parameters based on risk levels, software types, and organizational priorities. This allows flexible optimization between data comprehensiveness and processing efficiency, maintaining high accuracy while adapting to different time and resource constraints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250094599A1Multi-computer system for performing vulnerability analysis and alert generation
Publication Date: 2025.03.20 BANK OF AMERICA CORP
  • US20250094599A1 patent drawing
  • US20250094599A1 patent drawing
  • US20250094599A1 patent drawing

AI summary

Arrangements for providing software vulnerability analysis and monitoring are provided. In some aspects, software bill of materials (SBOM) data may be received and software attributes may be extracted from the SBOM data. Author data may be received and analyzed using natural language processing and/or machine learning to identify author attributes. Current event or vulnerability data may be received. In some examples, one or more machine learning models may be executed to determine a confidence score associated with the software being analyzed. For instance, software attributes, author attributes, and current event data may be used as inputs in the machine learning model and a confidence score may be output. Based on the confidence score, one or more alerts may be generated and transmitted to one or more enterprise organization computing devices.