IP Library Granted Patent US 12711229
Granted Patent B1
US 12711229 · App. 19/224,141 · Granted Aug 18, 2026

Techniques for cross entity correlation of user accounts in cloud computing environments

Inventors: Ron Konigsberg (Tel Aviv, IL); Itay Harel (Tel Aviv, IL); Dan Becker (Tel Aviv, IL)
Assignee: Wiz, Inc.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12711229
App. No.
19/224,141
Granted
Aug 18, 2026
Kind
B1
Abstract

A system and method for cross-entity ephemeral resource correlation to compute entities for applying controls in a cybersecurity system is presented. The method includes detecting an IP address in a record of a network event in a cloud computing environment, wherein the IP address is an ephemeral resource which is allocated for a limited duration; associating the IP address with a compute entity of the cloud computing environment based on the record; associating each event detected in a log of the cloud computing environment including the IP address with the compute entity; storing a representation of the compute entity and the IP address in a security database, the security database further including a representation of the cloud computing environment; and applying a control on the representation of the compute entity based at least on an event detected in the log of the cloud computing environment.

Claims (84)

1 . A method for cross-entity ephemeral resource correlation to compute entities for applying controls in a cybersecurity system, comprising:

detecting, in a network log of a cloud computing environment, a record of a network event, wherein the network event includes an identifier of a network interface;

identifying an IP address in the record of the network event, wherein the IP address is an ephemeral resource which is allocated for a limited duration;

associating the identifier of the network interface with a compute entity of the cloud computing environment, wherein the compute entity is a cloud infrastructure resource deployed in the cloud computing environment;

associating the IP address with the compute entity of the cloud computing environment based on the record associated identifier of the network interface;

associating each event detected in a log of the cloud computing environment including the IP address with the compute entity;

storing a representation of the compute entity as a node in a security graph; and

applying a control on the representation of the compute entity based at least on one associated event.

2 . The method of claim 1 , further comprising:

detecting a plurality of IP addresses, each associated with a respective record;

associating the plurality of IP addresses with the compute entity based on the respective record;

detecting a plurality of events in the cloud computing environment, each event including an IP address of the plurality of IP addresses;

associating each event with the compute entity; and

applying the control on the plurality of events.

3 . The method of claim 1 , further comprising:

associating the identifier of the network interface with an identifier of a virtualization;

detecting the virtualization based on the associated identifier;

generating in the security graph a representation of the virtualization; and

connecting the representation of the virtualization to the representation of the compute entity.

4 . The method of claim 3 , further comprising:

applying the control on the representation of the virtualization.

5 . The method of claim 4 , further comprising:

initiating a remediation action on the virtualization based on a result of applying the control.

6 . The method of claim 1 , further comprising:

applying a detection rule to events associated with the compute entity;

detecting a cybersecurity risk in the cloud computing environment based the applied detection rule; and

initiating a remediation action in the cloud computing environment based on the detected cybersecurity risk.

7 . The method of claim 1 , further comprising:

detecting the ephemeral resource in the record; and

associating the ephemeral resource with the compute entity of the cloud computing environment based on the identifier of the network interface, wherein the compute entity is the network interface of a virtualization deployed in the cloud computing environment.

8 . The method of claim 1 , wherein the control is a policy and applying the control includes applying the policy on the representation of the compute entity based at least on one associated event.

9 . The method of claim 1 , wherein the control is further applied to a plurality of computing environments based on the compute entity and the at least one associated event.

10 . The method of claim 1 , further comprising:

associating a first event with a first compute entity based on the IP address during a first time period;

determining the IP address was reassigned;

detecting a second event during a second time period, wherein the second time period is after the first time period and after the IP address was reassigned; and

associating the second event with a second compute entity based on the reassigned IP address during the second time period, wherein the first compute entity is different from the second compute entity.

11 . A non-transitory computer-readable medium storing a set of instructions for cross-entity ephemeral resource correlation to compute entities for applying controls in a cybersecurity system, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

detect, in a network log of a cloud computing environment, a record of a network event, wherein the network event includes an identifier of a network interface;

identify an IP address in the record of the network event, wherein the IP address is an ephemeral resource which is allocated for a limited duration;

associate the identifier of the network interface with a compute entity of the cloud computing environment, wherein the compute entity is a cloud infrastructure resource deployed in the cloud computing environment;

associate the IP address with the compute entity of the cloud computing environment based on the associated identifier of the network interface;

associate each event detected in a log of the cloud computing environment including the IP address with the compute entity;

store a representation of the compute entity as a node in a security graph; and

apply a control on the representation of the compute entity based at least on one associated event.

12 . A system for cross-entity ephemeral resource correlation to compute entities for applying controls in a cybersecurity system comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect, in a network log of a cloud computing environment, a record of a network event, wherein the network event includes an identifier of a network interface;

identify an IP address in the record of the network event, wherein the IP address is an ephemeral resource which is allocated for a limited duration;

associate the identifier of the network interface with a compute entity of the cloud computing environment, wherein the compute entity is a cloud infrastructure resource deployed in the cloud computing environment;

associate the IP address with the compute entity of the cloud computing environment based on the associated identifier of the network interface;

associate each event detected in a log of the cloud computing environment including the IP address with the compute entity;

store a representation of the compute entity as a node in a security graph; and

apply a control on the representation of the compute entity based at least on one associated event.

13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a plurality of IP addresses, each associated with a respective record;

associate the plurality of IP addresses with the compute entity based on the respective record;

detect a plurality of events in the cloud computing environment, each event including an IP address of the plurality of IP addresses;

associate each event with the compute entity; and

apply the control on the plurality of events.

14 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

associate the identifier of the network interface with an identifier of a virtualization;

detect the virtualization based on the associated identifier;

generate in the security graph a representation of the virtualization; and

connect the representation of the virtualization to the representation of the compute entity.

15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the control on the representation of the virtualization.

16 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate a remediation action on the virtualization based on a result of applying the control.

17 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply a detection rule to events associated with the compute entity;

detect a cybersecurity risk in the cloud computing environment based the applied detection rule; and

initiate a remediation action in the cloud computing environment based on the detected cybersecurity risk.

18 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the ephemeral resource in the record; and

associate the ephemeral resource with the compute entity of the cloud computing environment based on the identifier of the network interface, wherein the compute entity is the network interface of a virtualization deployed in the cloud computing environment.

19 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

associate a first event with a first compute entity based on the IP address during a first time period;

determine the IP address was reassigned;

detect a second event during a second time period, wherein the second time period is after the first time period and after the IP address was reassigned; and

associate the second event with a second compute entity based on the reassigned IP address during the second time period, wherein the first compute entity is different from the second compute entity.

20 . The system of claim 12 , wherein the control is a policy and applying the control includes applying the policy on the representation of the compute entity based at least on one associated event.