IP Library Granted Patent US 12670273
Granted Patent B2
US 12670273 · App. 18/227,223 · Granted Jun 30, 2026

Methods and systems for detecting hiding and data intelligence gathering in data lakes and cloud warehousing

Inventors: Navindra Yadav (Cupertino, CA); Supreeth Hosur Nagesh Rao (Cupertino, CA); Ravi Sankuratri (Cupertino, CA); Danesh Irani (San Carlos, CA); Alok Lalit Wadhwa (Milipitas, CA); Vasil Dochkov Yordanov (San Jose, CA); Venkateshu Cherukupalli (West Windsor, NJ); Yiwei Wang (San Jose, CA); Zhiwen Zhang (San Jose, CA); Udayan Pramod Joshi (Cupertino, CA)
Assignee: Theom, Inc.
G06F21/62G06F16/254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12670273
App. No.
18/227,223
Granted
Jun 30, 2026
Kind
B2
Abstract

In one aspect, a computerized method for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, comprising: implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse; implementing a discovery process in the data lake or the cloud warehouse; implementing a data gathering process in the data lake or the cloud warehouse; and performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.

Claims (40)

1 . A computerized method for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, comprising:

implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse;

implementing a discovery process in the data lake or the cloud warehouse;

implementing a data gathering process in the data lake or the cloud warehouse; and

performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.

2 . The computerized method of claim 1 , wherein implementing the hiding and data intelligence collection analysis phase comprises:

analyzing a hiding and data intelligence collection phase of an attack and implementing a defense evasion analysis using a truncate command.

3 . The computerized method of claim 2 , wherein the truncate command is implemented on an access_history table, a login_history table and a Query_history table.

4 . The computerized method of claim 1 , wherein implementing the discovery process in the data lake or the cloud warehouse further comprises a plurality of metadata operations.

5 . The computerized method of claim 4 , wherein the plurality of metadata operations comprise a discovery operation.

6 . The computerized method of claim 5 , wherein the discovery operation comprises a show operation.

7 . The computerized method of claim 5 , wherein the discovery operation comprises an explain operation.

8 . The computerized method of claim 5 , wherein implementing the data gathering process in the data lake or the cloud warehouse further comprises:

within the cloud warehouse, identifying a plurality of lateral movements.

9 . A system for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, comprising:

one or more processors; and

a non-transitory computer-readable medium storing software that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse;

implementing a discovery process in the data lake or the cloud warehouse;

implementing a data gathering process in the data lake or the cloud warehouse; and

performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.

10 . The system of claim 9 , wherein the operation of implementing the hiding and data intelligence collection analysis phase comprises:

analyzing a hiding and data intelligence collection phase of an attack and implementing a defense evasion analysis using a truncate command.

11 . The system of claim 10 , wherein the truncate command is implemented on an access_history table, a login_history table, and a Query_history table.

12 . The system of claim 9 , wherein the operation of implementing the discovery process in the data lake or the cloud warehouse further comprises performing a plurality of metadata operations.

13 . The system of claim 12 , wherein the plurality of metadata operations comprises a discovery operation, and wherein the discovery operation comprises a show operation or an explain operation.

14 . The system of claim 9 , wherein the operation of implementing the data gathering process in the data lake or the cloud warehouse further comprises:

within the cloud data warehouse, identifying a plurality of lateral movements.

15 . A non-transitory computer-readable medium storing software that, when executed by one or more processors, cause the one or more processors to perform operations for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, the operations comprising:

implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse;

implementing a discovery process in the data lake or the cloud warehouse;

implementing a data gathering process in the data lake or the cloud warehouse; and

performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.

16 . The non-transitory computer-readable medium of claim 15 , wherein the operation of implementing the hiding and data intelligence collection analysis phase comprises:

analyzing a hiding and data intelligence collection phase of an attack and implementing a defense evasion analysis using a truncate command.

17 . The non-transitory computer-readable medium of claim 16 , wherein the truncate command is implemented on an access_history table, a login_history table, and a Query_history table.

18 . The non-transitory computer-readable medium of claim 15 , wherein the operation of implementing the discovery process in the data lake or the cloud warehouse further comprises performing a plurality of metadata operations.

19 . The non-transitory computer-readable medium of claim 18 , wherein the plurality of metadata operations comprises a discovery operation, and wherein the discovery operation comprises a show operation or an explain operation.

20 . The non-transitory computer-readable medium of claim 15 , wherein the operation of implementing the data gathering process in the data lake or the cloud warehouse further comprises:

within the cloud data warehouse, identifying a plurality of lateral movements.