IP Library Granted Patent US 12,278,729
Granted Patent B2
US 12,278,729 · App. 17/188,243 · Granted Apr 15, 2025

Systems, methods, and media for monitoring cloud configuration settings

Inventors: Sekhar Sarukkai (Cupertino, CA); Prasad Raghavendra Somasamudram (Bangalore, IN); Syed Ummar Farooqh (Bangalore, IN)
Assignee: Skyhigh Security LLC
H04L41/0866H04L41/0816H04L41/0886H04L41/0893
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,278,729
App. No.
17/188,243
Granted
Apr 15, 2025
Kind
B2
Abstract

Receiving configuration settings (CSs) from a resource using an API; determining a resource risk score (RERS), a first tactic risk score (TARS), a first plurality of technique risk scores (TERSs), a second TARS, and a second TERSs, wherein the RERS is based on the first TARS and the second TARS, wherein the first TARS is based on the first TERSs, wherein the second TARS is based on the second TERSs, wherein each of the first TERSs is based on a subset of a set of policy scores (SPS), wherein each of the second TERSs is based on a subset of the SPS, and wherein each of the SPS is based on compliance of the CSs with a setting; and selecting a most-important technique (MIT) based on the first TARS, the second TARS, and one of the first TERSs and the second TERSs, and remediating a CS corresponding to the MIT.

Claims (32)

1. A method comprising:

receiving configuration settings from a cloud service resource using an application programming interface;

determining a resource risk score, a first tactic risk score, a first plurality of technique risk scores, a second tactic risk score, and a second plurality of technique risk scores, wherein the resource risk score is based on the first tactic risk score and the second tactic risk score, wherein the first tactic risk score is based on the first plurality of technique risk scores, wherein the second tactic risk score is based on the second plurality of technique risk scores, wherein each of the first plurality of technique risk scores is based on a corresponding subset of a set of policy scores, wherein each of the second plurality of technique risk scores is based on a corresponding subset of the set of policy scores, and wherein each of the set of policy scores is based on compliance of the configuration settings with a corresponding setting; and

selecting a first tactic based on the first tactic risk score being worse than the second tactic risk score, selecting a technique of the first tactic based on the technique corresponding to a worst of the first plurality of technique risk scores, and remediating a configuration setting corresponding to the technique,

wherein each of the first tactic risk score and the second tactic risk score reflects a risk of a corresponding tactic that can be used to attack a resource, and

wherein each of the first plurality of technique risk scores and the second plurality of technique risk scores reflects a risk of a corresponding technique that can be used to perform a corresponding tactic in attacking a resource.

2. The method of claim 1 , wherein the resource is a cloud service of one of a Software as a Service (SaaS) vendor, a Platform as a Service (PaaS) vendor, an Infrastructure as a Service (IaaS) vendor.

3. The method of claim 1 , wherein each of the first plurality of technique risk scores is based on a weighted sum including the corresponding subset of a set of policy scores, and wherein each of the second plurality of technique risk scores is based on a weighted sum including the corresponding subset of the set of policy scores.

4. The method of claim 3 , wherein the first tactic risk score is based on a weighted sum of the first plurality of technique risk scores, and wherein the second tactic risk score is based on a weighted sum of the second plurality of technique risk scores.

5. The method of claim 4 , wherein the resource risk score is based on a weighted sum including the first tactic risk score and the second tactic risk score.

6. A system comprising:

a memory; and

a hardware processor coupled to the memory and configured to:

receive configuration settings from a cloud service resource using an application programming interface;

determine a resource risk score, a first tactic risk score, a first plurality of technique risk scores, a second tactic risk score, and a second plurality of technique risk scores, wherein the resource risk score is based on the first tactic risk score and the second tactic risk score, wherein the first tactic risk score is based on the first plurality of technique risk scores, wherein the second tactic risk score is based on the second plurality of technique risk scores, wherein each of the first plurality of technique risk scores is based on a corresponding subset of a set of policy scores, wherein each of the second plurality of technique risk scores is based on a corresponding subset of the set of policy scores, and wherein each of the set of policy scores is based on compliance of the configuration settings with a corresponding setting; and

select a first tactic based on the first tactic risk score being worse than the second tactic risk score, select a technique of the first tactic based on the technique corresponding to a worst of the first plurality of technique risk scores, and remediate a configuration setting corresponding to the technique,

wherein each of the first tactic risk score and the second tactic risk score reflects a risk of a corresponding tactic that can be used to attack a resource, and

wherein each of the first plurality of technique risk scores and the second plurality of technique risk scores reflects a risk of a corresponding technique that can be used to perform a corresponding tactic in attacking a resource.

7. The system of claim 6 , wherein the resource is a cloud service of one of a Software as a Service (SaaS) vendor, a Platform as a Service (PaaS) vendor, an Infrastructure as a Service (IaaS) vendor.

8. The system of claim 6 , wherein each of the first plurality of technique risk scores is based on a weighted sum including the corresponding subset of a set of policy scores, and wherein each of the second plurality of technique risk scores is based on a weighted sum including the corresponding subset of the set of policy scores.

9. The system of claim 8 , wherein the first tactic risk score is based on a weighted sum of the first plurality of technique risk scores, and wherein the second tactic risk score is based on a weighted sum of the second plurality of technique risk scores.

10. The system of claim 9 , wherein the resource risk score is based on a weighted sum including the first tactic risk score and the second tactic risk score.

11. A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method, the method comprising:

receiving configuration settings from a cloud service resource using an application programming interface;

determining a resource risk score, a first tactic risk score, a first plurality of technique risk scores, a second tactic risk score, and a second plurality of technique risk scores, wherein the resource risk score is based on the first tactic risk score and the second tactic risk score, wherein the first tactic risk score is based on the first plurality of technique risk scores, wherein the second tactic risk score is based on the second plurality of technique risk scores, wherein each of the first plurality of technique risk scores is based on a corresponding subset of a set of policy scores, wherein each of the second plurality of technique risk scores is based on a corresponding subset of the set of policy scores, and wherein each of the set of policy scores is based on compliance of the configuration settings with a corresponding setting; and

selecting a first tactic based on the first tactic risk score being worse than the second tactic risk score, selecting a technique of the first tactic based on the technique corresponding to a worst of the first plurality of technique risk scores, and remediating a configuration setting corresponding to the technique,

wherein each of the first tactic risk score and the second tactic risk score reflects a risk of a corresponding tactic that can be used to attack a resource, and

wherein each of the first plurality of technique risk scores and the second plurality of technique risk scores reflects a risk of a corresponding technique that can be used to perform a corresponding tactic in attacking a resource.

12. The non-transitory computer-readable medium of claim 11 , wherein the resource is a cloud service of one of a Software as a Service (SaaS) vendor, a Platform as a Service (PaaS) vendor, an Infrastructure as a Service (IaaS) vendor.

13. The non-transitory computer-readable medium of claim 11 , wherein each of the first plurality of technique risk scores is based on a weighted sum including the corresponding subset of a set of policy scores, and wherein each of the second plurality of technique risk scores is based on a weighted sum including the corresponding subset of the set of policy scores.

14. The non-transitory computer-readable medium of claim 13 , wherein the first tactic risk score is based on a weighted sum of the first plurality of technique risk scores, and wherein the second tactic risk score is based on a weighted sum of the second plurality of technique risk scores.

15. The non-transitory computer-readable medium of claim 14 , wherein the resource risk score is based on a weighted sum including the first tactic risk score and the second tactic risk score.

Assignments (11)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2022
From: SARUKKAI, SEKHAR; SOMASAMUDRAM, PRASAD RAGHAVENDRA; FAROOQH, SYED UMMAR
To: SKYHIGH SECURITY LLC
Reel/Frame 060890/0239 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →