SBOM-Based Security Service Insertion for Vulnerable Cloud Data Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-native architectures increase the attack surface and expose applications to new vulnerabilities, making them susceptible to security threats, which conventional systems struggle to mitigate effectively.

Innovation Solution

Implement a service provider platform that uses a software bill of materials (SBOM) to identify vulnerable components and dynamically insert security services, such as new pods or sidecar containers, into data flows to mitigate detected threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud-native architectures are adopted to enable rapid application development with flexibility and scale, then productivity and adaptability are improved, but the attack surface increases and security reliability deteriorates

Engineering Contradiction:
Improverapid application developmentVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary vulnerability assessment by analyzing software bills of materials (SBOMs) to identify vulnerable components before they can be exploited. Security services are proactively inserted into data flows based on predicted vulnerability risks, preventing attacks before they occur rather than reacting after vulnerabilities are exploited.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces security services as intermediary components that are dynamically inserted into data flows between applications and vulnerable components. These intermediary security services monitor and protect data flows without disrupting the underlying cloud-native architecture's productivity benefits, effectively mediating between the need for rapid development and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security services are dynamically inserted into data flows to mitigate vulnerabilities, then security reliability is improved, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvevulnerability mitigationVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically inserts and removes security services based on real-time vulnerability assessments and data flow analysis. Rather than having static security configurations, the architecture adaptively adjusts security service placement and activation, reducing complexity by only introducing security components when and where vulnerabilities are detected.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The vulnerability assessment system automatically analyzes SBOMs, identifies vulnerable components, and triggers the insertion of appropriate security services without manual intervention. The system self-manages the complexity of security configuration by autonomously determining which security services are needed and where they should be inserted into data flows.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive vulnerability assessment of all components is performed, then measurement precision of security risks is improved, but processing time and loss of time increase

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidassessment processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies vulnerability assessment selectively to specific components and data flows based on their vulnerability profiles and criticality. Rather than uniformly assessing all components with the same depth, the system tailors the assessment intensity to local requirements, focusing resources on high-risk areas while reducing overhead for lower-risk components.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs partial vulnerability assessment by analyzing SBOMs and identifying only the most critical vulnerable components that require immediate security intervention. Rather than exhaustively assessing every single component in detail, the system focuses on the subset of components that pose the greatest security risk, reducing processing time while maintaining effective security coverage.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250348595A1Dynamic security service extension based on software bill of materials
Publication Date: 2025.11.13 CISCO TECHNOLOGY INC
  • US20250348595A1 patent drawing
  • US20250348595A1 patent drawing
  • US20250348595A1 patent drawing

AI summary

Techniques are described herein for dynamic service extension to provide risk mitigation upon detecting a threat. In embodiments, such techniques may be performed by a service provider platform and may comprise receiving information about a security threat, identifying one or more components susceptible to the security threat, determining, based on a software bill of materials, at least one data flow that includes a point of delivery (pod) associated with the one or more components, identifying at least one additional service determined to mitigate the security threat, and implementing the at least one additional service in relation to the at least one data flow.