IP Library Granted Patent US 12706958
Granted Patent B1
US 12706958 · App. 19/224,116 · Granted Aug 11, 2026

Techniques for cross entity correlation of user accounts in cloud computing environments

Inventors: Ron Konigsberg (Tel Aviv, IL); Itay Harel (Tel Aviv, IL); Dan Becker (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L63/20H04L63/1416H04L63/1425H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706958
App. No.
19/224,116
Granted
Aug 11, 2026
Kind
B1
Abstract

A system and method for performing cross-entity correlation of activity in a cloud computing environment for applying a cybersecurity control is presented. The method includes detecting a principal in the cloud computing environment, wherein the principal is deployed in the cloud computing environment; detecting an external identity to the cloud computing environment, wherein the external identity associated with a canonical user and the external entity is managed by an entity which is external to the cloud computing environment; detecting a hint in an event of the cloud computing environment, wherein the hint associates the external identity with the detected principal; generating a representation in a security database of the detected principal and of the external identity; connecting the representation of the detected principal with the representation of the external identity based on the hint; and applying a control on the representation.

Claims (62)

1 . A method for performing cross-entity correlation of activity in a cloud computing environment for applying a cybersecurity control, comprising:

detecting a principal in the cloud computing environment, wherein the principal is deployed in the cloud computing environment and the cloud computing environment is implemented on cloud computing infrastructure;

detecting an external identity to the cloud computing environment, wherein the external identity associated with a canonical user and the external identity is provided and managed by an entity provider which is external to the cloud computing environment, wherein the external identity corresponds to a primary identity used across multiple cloud computing environments and wherein detecting the external identity comprises querying the identity provider that is external to the cloud computing environment;

detecting a hint in an event of the cloud computing environment, wherein the hint associates the external identity with the detected principal;

generating a representation in a security database linking the detected principal and of the external identity;

connecting the representation of the detected principal with the representation of the external identity based on the hint; and

applying a control on the representation.

2 . The method of claim 1 , further comprising:

detecting the hint in a log of the cloud computing environment, wherein the log includes a plurality of event records, each event record including an identifier of a resource deployed in the cloud computing environment.

3 . The method of claim 1 , further comprising:

detecting in the hint an association between a first principal and the detected principal, wherein the first principal is deployed in another cloud computing environment.

4 . The method of claim 1 , further comprising:

detecting a first event associated with the detected principal;

detecting a second event associated with a second principal, the second principal connected to the external identity; and

detecting a cybersecurity threat based on the first event and the second event.

5 . The method of claim 4 , further comprising:

detecting in the first event in the cloud computing environment; and

detecting the second event in another cloud computing environment.

6 . The method of claim 5 , further comprising:

initiating a remediation action based on the detected cybersecurity threat.

7 . The method of claim 6 , further comprising:

initiating the remediation action in any one of: the cloud computing environment, the another cloud computing environment, or a combination thereof.

8 . The method of claim 1 , further comprising:

querying an identity and access management (IAM) service to detect the external identity.

9 . The method of claim 1 , further comprising:

applying the control to each identity associated with the canonical user.

10 . A non-transitory computer-readable medium storing a set of instructions for performing cross-entity correlation of activity in a cloud computing environment for applying a cybersecurity control, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

detect a principal in the cloud computing environment, wherein the principal is deployed in the cloud computing environment and the cloud computing environment is implemented on cloud computing infrastructure;

detect an external identity to the cloud computing environment, wherein the external identity associated with a canonical user and the external identity is provided and managed by an entity provider which is external to the cloud computing environment, wherein the external identity corresponds to a primary identity used across multiple cloud computing environments and wherein detecting the external identity comprises querying the identity provider that is external to the cloud computing environment;

detect a hint in an event of the cloud computing environment, wherein the hint associates the external identity with the detected principal;

generate a representation in a security database linking the detected principal and of the external identity;

connect the representation of the detected principal with the representation of the external identity based on the hint; and

apply a control on the representation.

11 . A system for performing cross-entity correlation of activity in a cloud computing environment for applying a cybersecurity control comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a principal in the cloud computing environment, wherein the principal is deployed in the cloud computing environment and the cloud computing environment is implemented on cloud computing infrastructure;

detect an external identity to the cloud computing environment, wherein the external identity associated with a canonical user and the external identity is provided and managed by an entity provider which is external to the cloud computing environment, wherein the external identity corresponds to a primary identity used across multiple cloud computing environments and wherein detecting the external identity comprises querying the identity provider that is external to the cloud computing environment;

detect a hint in an event of the cloud computing environment, wherein the hint associates the external identity with the detected principal;

generate a representation in a security database linking the detected principal and of the external identity;

connect the representation of the detected principal with the representation of the external identity based on the hint; and

apply a control on the representation.

12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the hint in a log of the cloud computing environment, wherein the log includes a plurality of event records, each event record including an identifier of a resource deployed in the cloud computing environment.

13 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect in the hint an association between a first principal and the detected principal, wherein the first principal is deployed in another cloud computing environment.

14 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a first event associated with the detected principal;

detect a second event associated with a second principal, the second principal connected to the external identity; and

detect a cybersecurity threat based on the first event and the second event.

15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect in the first event in the cloud computing environment; and

detect the second event in another cloud computing environment.

16 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate a remediation action based on the detected cybersecurity threat.

17 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate the remediation action in any one of: the cloud compute environment, the another cloud computing environment, or a combination thereof.

18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

query an identity and access management (IAM) service to detect the external identity.

19 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the control to each identity associated with the canonical user.