
IT Security
Binarly Patents New Method For Reachability Analysis For Binary Executables
By Business Wire
.png?ext=.png)
SANTA MONICA, Calif.--(BUSINESS WIRE)--Binarly, a leading firmware and software supply chain security company, has been awarded U.S. Patent No. 12,287,885 for its invention of a new method for computing context-sensitive reachability analysis metrics across binary executables.
The patented invention empowers security teams to determine not only whether a vulnerability exists, but how easily it could be exploited in a given real-world environment. Read the full patent (PDF).
The reachability analysis technology has already been fitted into the company’s flagship Binarly Transparency Platform and is currently running at scale across global enterprise deployments.
As documented in this whitepaper, the patented techniques decompose one or more binary executables (or containers of executables) into their constituent components and associated configuration artifacts. For each component, Binarly’s new method constructs inter-procedural control-flow graphs (ICFGs) and code cross-reference graphs, identifies entry points, and computes reachability metrics for every program location.
Crucially, the innovation extends traditional static analysis by integrating context-aware reachability: it factors in real-world runtime properties (loaded libraries, boot scripts, or container entry-point configurations) to produce a reachability metric that reflects how the software actually runs in production.
While existing vulnerability scanners flag potential security flaws without discriminating whether those flaws can ever be reached during execution, Binarly’s patented solution advances the field by:
- Quantifying Exploitability: Assigning metrics to code paths that gauge the difficulty of navigating from a valid entry point to a vulnerable instruction.
- Environment Contextualization: Incorporating runtime artifacts (e.g., init scripts, container manifests, file-system permissions) to refine which code paths are truly viable in a target deployment.
- Joint and Inter-Component Analysis: Extending reachability computations across multiple executables or libraries, revealing cross-binary vulnerabilities that static tools often miss.
“Understanding if and how a vulnerability can be reached in a real environment is a critical part of sharp, actionable cybersecurity,” said Alexander Matrosov, Binarly founder and one of the patent’s inventors. “This patent solidifies our breakthrough approach: moving beyond static vulnerability counts and toward a risk-centric, context-aware reasoning model that aligns remediation efforts with real-world exploitability.”
Binarly has publicly documented its approach to reachability analysis in this white paper.
The Binarly research team has separately secured US patents for CBOM generation from binaries (U.S. Patent No. 12153686) and a machine learning technique to optimize large-scale binary analysis (U.S. Patent No. 12236262).
About Binarly
Binarly is a U.S.-based firmware and software supply chain security company founded in 2021. The flagship Binarly Transparency Platform helps device manufacturers, OEMs and enterprise product security teams to detect vulnerabilities, misconfigurations, secrets, and malicious code in devices and software supply chains. Leveraging decades of research and program analysis expertise, we secure businesses, critical infrastructure, and consumers, while also assisting organizations in transitioning to a post-quantum cryptography (PQC) environment. For more information, visit https://binarly.io.
Contacts
Media Contact:
Tyler King
tyler@binarly.io
818-351-9637
Frequently Asked Questions
What is context-sensitive reachability analysis?
It's a method to determine how easily a vulnerability can be exploited in a real-world environment by considering runtime properties like loaded libraries and boot scripts.
How does Binarly's technology improve vulnerability scanning?
Unlike traditional scanners, Binarly quantifies exploitability and incorporates runtime context to prioritize vulnerabilities based on actual risk, not just potential existence.
What are the benefits of Binarly's Transparency Platform?
It helps organizations detect vulnerabilities, misconfigurations, secrets, and malicious code in their devices and software supply chains, enabling more effective remediation efforts.
First published on Thu, May 15, 2025
Liked what you read? That’s only the tip of the tech iceberg!
Explore our vast collection of tech articles including introductory guides, product reviews, trends and more, stay up to date with the latest news, relish thought-provoking interviews and the hottest AI blogs, and tickle your funny bone with hilarious tech memes!
Plus, get access to branded insights from industry-leading global brands through informative white papers, engaging case studies, in-depth reports, enlightening videos and exciting events and webinars.
Dive into TechDogs' treasure trove today and Know Your World of technology like never before!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Trending Business Wire
Brainfreeze Launches Industry's Most Granular AI Security Controls For Education, Moving Beyond One-Size-Fits-All Approach
By Business Wire
Conceptvines And Neovera Partner To Accelerate Secure AI Adoption For Organizations In Highly Regulated Industries
By Business Wire
Conduit Announces New Partnership With Braza Group In Brazil For Onchain FX
By Business Wire
DATA POEM Launches POEM365, The World's First Large Causal AI Model (LCM)
By Business Wire
DYOPATH Named To CRN Solution Provider 500 List For 2025
By Business Wire
Join Our Newsletter
Get weekly news, engaging articles, and career tips-all free!
By subscribing to our newsletter, you're cool with our terms and conditions and agree to our Privacy Policy.
Join The Discussion