MUMBAI, India, Sept. 28 -- Intellectual Property India has published a patent application (202611099653 A) filed by Mr. Naga Sekhar Madala on August 18, 2026, for Ai-Based Software Supply Chain Risk Detection And Automated Dependency Security Management System.

Inventor includes Mr. Naga Sekhar Madala.

The application for the patent was published on September 25, 2026, under issue no. 39/2026.

Abstract: The present invention relates to an artificial intelligence based software supply chain risk detection and automated dependency security management system which is capable of detecting, evaluating, analyzing, and remediating vulnerabilities and threats that emerge in the software supply chain. Software development today makes extensive use of external libraries or packages, frameworks, modules, and other related coding elements sourced from various available repositories and providers. Such practice, although facilitating development and re-use of code, exposes the final product to potential threats due to the inability to establish trust and security guarantees of the source code elements and their providers. Exploitation of the software supply chain is increasingly becoming a major threat, as demonstrated by incidents of malicious code being introduced by compromising third party providers, modifying build processes, or using vulnerable versions of dependent components with known weaknesses. Traditional software supply chain risk management is often inadequate in the face of rapidly evolving threats, zero-day attacks, and complex attack chains, only detecting known issues or requiring extensive resources and time to analyze and respond. The invention described herein addresses the aforementioned shortcomings by implementing a continuously operating system which makes use of artificial intelligence methods to continuously monitor the software supply chain, detect threats and their impact, and automatically apply necessary measures to remediate them. The system employs multi-layered artificial intelligence which is trained on known vulnerabilities, malware, patterns related to compromised components, and other relevant data to detect threats and perform risk assessment. The system continuously consumes data related to packages, repositories, build configurations, and other elements related to the software supply chain and analyzes their code, structure, behavior, and network interactions. Various types of machine learning algorithms trained on different sets of data are applied to detect anomalies which may indicate compromise, such as differences between versions of similar components, connection to unexpected domains, and others. Additionally, natural language processing algorithms are used to scan relevant documentation, issue trackers, and other resources for any indication of compromise which may not be obvious from code analysis. Graphs of component relationships are also used to identify indirect relationships and interdependencies which may allow for indirect exploitation and pose risks to the entire system. The system calculates risk scores for identified threats based on factors such as exploitability, impact, likelihood of being present in the organization, and sensitivity of data. The risk calculation takes into account multiple variables related to the threat and its potential impact, such as whether an exploit requires elevated privileges and whether it has already been detected in the wild, whether the component is critical to the operation of the software, whether it is exposed to external users, and has sensitive data processing routines. Additionally, the urgency of addressing the threat is prioritized taking into consideration whether it is a newly discovered vulnerability, whether it is a known vulnerability which has not yet been actively exploited, and the potential impact of such an exploit. Risk scores are dynamically adjusted and tuned based on real-world observations and analyst feedback to reflect the current threat landscape and allow accurate risk prioritization across different components. When a threat is detected, automated dependency security management capabilities are used to address and remediate it. The system may analyze the suspicious component in detail to detect additional threats which may have been missed by earlier analysis. If a safer version of the component is available, the system may replace the compromised component with a safer alternative while maintaining compatibility, reducing the risk of introducing new bugs or issues. Compatibility is established by analyzing application programming interfaces, test suite results, and performing other analyses in restricted environments which emulate the production runtime. In cases where no safe version of the component is available, the system may apply additional compensating security controls when appropriate, restricting potential attack vectors or impact of an exploit to reduce the overall risk. Finally, the system may keep track of all actions performed, allowing for easier auditing and forensic analysis if an incident occurs. The invention also allows for prediction of future risks based on trends and patterns. By analyzing update rates, activity of maintainers, and other factors, artificial intelligence algorithms may estimate the likelihood that a particular component will become compromised in the future. This allows the organization to prioritize components which are likely to be exploited or which already have known exploits which have not yet been addressed. The system also allows for collaboration between different organizations to share intelligence on threats while keeping sensitive information protected. The system is also easily integrated into existing development and operations infrastructure with minimal disruption to the current processes. Developers may receive suggestions based on the system analysis within their integrated development environment, provide feedback, and review suggested changes. Builders may implement policies which require additional review or approval for components with known risks. Similarly, run-time environments may report relevant information to the system to facilitate analysis and mitigation of supply chain attacks. The system is also easily scalable and can be used by different sized organizations, ranging from single applications to massive enterprise-scale software stacks. The security of the management system itself is also considered, as it serves as a critical infrastructure component which must be secured against supply chain attacks itself. The artificial intelligence components which power the system are run in a secure environment which utilizes appropriate security measures such as multi-factor authentication and encrypted communications to prevent unauthorized access or tampering. The integrity of the system is constantly monitored to detect and mitigate potential attacks or compromises of the system itself. Additionally, the system does not store any private code and thus cannot be exploited to plant additional vulnerabilities in other components. All operations of the system are also available for manual review and approval, reducing the risk of automated exploitation while allowing the benefits of automation and speed. Manual review of particularly critical or high-risk changes is also possible, allowing for a balance between automation and security. The combination of these features allows for an increase in software supply chain security, reducing the attack surface and potential impact of supply chain attacks while reducing the overhead and complexity of manual review of each identified risk. Organizations which use the system benefit from reduced risk of successful attacks and reduced costs related to responding to them, as well as faster detection and response times. The system thus facilitates continuous monitoring and management of the software supply chain, allowing to reduce the overall attack surface of the organization.

Disclaimer: Curated by HT Syndication.