Third-Party Component Vulnerability Analysis via Byte-Code BOM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software vendors face challenges in ensuring the security of software applications built from numerous third-party components, as they are responsible for the security of all components, regardless of their origin, leading to complex and dynamic security monitoring needs.

Innovation Solution

A method for analyzing and monitoring the security of software applications by generating a comprehensive bill of materials (BOM) that identifies and tracks third-party components, performs byte-code analysis, and provides updates to address vulnerabilities, using a system that includes processors and computer-readable storage media to execute instructions for processing applications and managing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a software vendor integrates many third-party components to build software applications, then the functionality and versatility of the application is improved, but the complexity of security monitoring and tracking increases

Engineering Contradiction:
Improvefunctionality of software applicationVSAvoidcomplexity of security monitoring
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the software application into its constituent third-party components by generating a bill of materials (BOM) that lists each component separately. This segmentation allows the security system to track and monitor each component independently, reducing the overall complexity of security monitoring while maintaining awareness of the complete application structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system that automatically tracks third-party components and their vulnerabilities. This intermediary layer between the vendor and the components handles the complexity of security monitoring, including automatic identification of components, tracking of vulnerability databases, and generation of security reports, thereby freeing the vendor from direct manual monitoring complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a vendor manually tracks and monitors each third-party component for security vulnerabilities, then the security monitoring thoroughness is improved, but the time consumption and operational burden increase

Engineering Contradiction:
Improvesecurity monitoring thoroughnessVSAvoidtime consumption for security monitoring
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a self-service mechanism where the system automatically tracks third-party components and monitors vulnerability databases without requiring manual intervention. The system autonomously identifies components, queries vulnerability information, and generates security reports, thereby maintaining thorough security monitoring while eliminating time-consuming manual operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes a feedback loop where the system continuously queries vulnerability databases for tracked components and automatically updates the bill of materials with vulnerability information. This automated feedback mechanism ensures thorough security monitoring by keeping the system constantly updated on component vulnerabilities without requiring manual checking or review.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If a vendor performs comprehensive byte-code analysis and multiple analyses of software applications to identify all third-party components, then the accuracy of component identification is improved, but the processing time and computational resources increase

Engineering Contradiction:
Improveaccuracy of component identificationVSAvoidprocessing time for analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-processing the software application to generate an initial bill of materials before full analysis is required. The system creates a structured list of third-party components through preliminary byte-code analysis, which then serves as a foundation for subsequent vulnerability tracking and security monitoring, reducing the time needed for comprehensive analysis when required.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial analysis initially by performing byte-code analysis to identify components, then selectively applies more thorough analysis only when vulnerabilities are detected or suspected. This partial action approach maintains high accuracy in component identification for critical areas while reducing overall processing time by avoiding exhaustive analysis of all components under normal conditions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10691808B2Vulnerability analysis of software components
Publication Date: 2020.06.23 SAP SE
  • US10691808B2 patent drawing
  • US10691808B2 patent drawing
  • US10691808B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for receiving an application developed by a first vendor. Processing the application, by performing a byte-code analysis of the application, to: identify a plurality of software components used by the application that were developed by vendors other than the first vendor, and provide a list of third-party software components associated with the application, the list including each of the identified software components. determining, for each software component included in the list, whether the software component has a vulnerability and, if so, selectively providing code to correct the vulnerability of the software component.