IP Library › Granted Patent US 12,248,581
Granted Patent B1
US 12,248,581 · App. 17/653,325 · Granted Mar 11, 2025

Architecture of a multi-cloud inspector for any compute type

Inventors: Yaniv Shaked (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Gal Kozoshnik (Petach Tikva, IL); Roy Reznik (Tel Aviv, IL); Yarin Miran (Rishon Lezion, IL)
Assignee: Wiz, Inc.
G06F21/577G06F9/45558G06F9/5072G06F9/5077G06F16/288G06F2009/4557G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,581
App. No.
17/653,325
Filed
Mar 3, 2022
Granted
Mar 11, 2025
Kind
B1
Art Unit
2432
USPC
726/25
Abstract

An architecture of a multi-cloud inspector for any computing device type is provided. According to an embodiment, a method for implementing multi-cloud inspection includes accessing an object list, determining which objects to inspect, determining which inspectors to use, creating object copies, providing and running inspectors for each object copy, receiving inspection report summaries, generating an enriched dataset, and adding the enriched dataset to a security graph database.

Claims (61)

1. A method for multi-cloud vulnerability inspection, comprising:

accessing an object list, including a plurality of objects, each object having a corresponding identifier, each object deployed in a cloud environment, wherein a first object is deployed in a first cloud environment and a second object is deployed in a second cloud environment, wherein the first object is configured to be operational in the first cloud environment so as to provide functionality to the first cloud environment and the second object is configured to be operational in the second cloud environment so as to provide functionality to the second cloud environment;

selecting, from a plurality of available inspectors, at least a first inspector for inspecting at least a portion of the plurality of objects from the object list, wherein each of the at least a first inspector selected is selected based on at least one criteria of each of the objects of the at least a portion of the plurality of objects to be inspected by the selected at least a first inspector;

generating a first object copy for the first object, the first object copy including a first virtual environment;

deploying the at least a first inspector in the first virtual environment, the first virtual environment being adapted to enable execution of code implementing the at least a first inspector;

generating a second object copy for the second object, the second object copy including a second virtual environment;

deploying the at least a first inspector in the second virtual environment;

receiving an inspection report from the at least a first inspector in response to inspecting the first object copy;

generating an enriched dataset based on the inspection report; and

storing at least a portion of the enriched dataset in a security graph;

wherein the inspection report includes an indicator corresponding to a vulnerability, indicating that an inspected object includes the vulnerability.

2. The method of claim 1 , further comprising transmitting a query to the security graph for execution thereon to detect one or more nodes having an attribute with a prescribed value.

3. The method of claim 1 , wherein the security graph includes a plurality of nodes and edges, each node corresponding to an object, and each corresponding to a connection between a first object and a second object.

4. The method of claim 1 , further comprising:

representing the first cloud environment in the security graph; and

representing the second cloud environment in the security graph.

5. The method of claim 1 , further comprising:

storing at least another portion of the enriched dataset as a node in the security graph.

6. The method of claim 1 , wherein at least an object is any of: a virtual network, a firewall, a network interface card, a proxy, a gateway, a container, a container management object, a virtual machine, a serverless function, a subnet, a hub, a virtual private network (VPN), a user account, a service account, and a role.

7. The method of claim 1 , wherein the first object copy includes a disk snapshot.

8. The method of claim 1 , wherein the at least a first inspector is determined based on an object type.

9. The method of claim 1 , wherein the first inspector is executed on the first object copy in the first virtual environment.

10. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

accessing an object list, including a plurality of objects, each object having a corresponding identifier, each object deployed in a cloud environment, wherein a first object is deployed in a first cloud environment and a second object is deployed in a second cloud environment, wherein the first object is configured to be operational in the first cloud environment so as to provide functionality to the first cloud environment and the second object is configured to be operational in the second cloud environment so as to provide functionality to the second cloud environment;

selecting, from a plurality of available inspectors, at least a first inspector for inspecting at least a portion of the plurality of objects from the object list, wherein each of the at least a first inspector selected is selected based on at least one criteria of each of the objects of the at least a portion of the plurality of objects to be inspected by the selected at least a first inspector;

generating a first object copy for the first object, the first object copy including a first virtual environment;

deploying the at least a first inspector in the first virtual environment, the first virtual environment being adapted to enable execution of code implementing the at least a first inspector;

generating a second object copy for the second object, the second object copy including a second virtual environment;

deploying the at least a first inspector in the second virtual environment;

receiving an inspection report from the at least a first inspector in response to inspecting the first object copy;

generating an enriched dataset based on the inspection report; and

storing at least a portion of the enriched dataset in a security graph;

wherein the inspection report includes an indicator corresponding to a vulnerability, indicating that an inspected object includes the vulnerability.

11. A system for multi-cloud vulnerability inspection, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

access an object list, including a plurality of objects, each object having a corresponding identifier, each object deployed in a cloud environment, wherein a first object is deployed in a first cloud environment and a second object is deployed in a second cloud environment, wherein the first object is configured to be operational in the first cloud environment so as to provide functionality to the first cloud environment and the second object is configured to be operational in the second cloud environment so as to provide functionality to the second cloud environment;

select, from a plurality of available inspectors, at least a first inspector for inspecting at least a portion of the plurality of objects from the object list, wherein each of the at least a first inspector selected is selected based on at least one criteria of each of the objects of the at least a portion of the plurality of objects to be inspected by the selected at least a first inspector;

generate a first object copy for the first object, the first object copy including a first virtual environment;

deploy the at least a first inspector in the first virtual environment, the first virtual environment being adapted to enable execution of code implementing the at least a first inspector;

generate a second object copy for the second object, the second object copy including a second virtual environment;

deploy the at least a first inspector in the second virtual environment;

receive an inspection report from the at least a first inspector in response to inspecting the first object copy;

generate an enriched dataset based on the inspection report; and

store at least a portion of the enriched dataset in a security graph;

deploying the at least a first inspector in the second virtual environment;

receiving an inspection report from the at least a first inspector in response to inspecting the first object copy;

generating an enriched dataset based on the inspection report; and

storing at least a portion of the enriched dataset in a security graph;

wherein the inspection report includes an indicator corresponding to a vulnerability, indicating that an inspected object includes the vulnerability.

12. The system of claim 11 , the system is further configured to transmit a query to the security graph for execution thereon to detect one or more nodes having an attribute with a prescribed value.

13. The system of claim 11 , wherein the security graph includes a plurality of nodes and edges, each node corresponding to an object, and each corresponding to a connection between a first object and a second object.

14. The system of claim 11 , wherein the memory further contains instructions that when executed by the processing circuitry further configure the system to:

represent the first cloud environment in the security graph; and

represent the second cloud environment in the security graph.

15. The system of claim 11 , wherein the memory further contains instructions that when executed by the processing circuitry further configure the system to:

store at least another portion of the enriched dataset as a node in the security graph.

16. The system of claim 11 , wherein at least an object is any of: a virtual network, a firewall, a network interface card, a proxy, a gateway, a container, a container management object, a virtual machine, a serverless function, a subnet, a hub, a virtual private network (VPN), a user account, a service account, and a role.

17. The system of claim 11 , wherein the first object copy includes a disk snapshot.

18. The system of claim 11 , wherein the at least a first inspector is determined based on an object type.

19. The system of claim 11 , wherein the first inspector is executed on the first object copy in the first virtual environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2022
From: SHAKED, YANIV; LUTTWAK, AMI; KOZOSHNIK, GAL; REZNIK, ROY; MIRAN, YARIN
To: WIZ, INC.
Reel/Frame 059161/0634 →
Continuity (1)
Provisional Application 63156754 · Mar 4, 2021
References Cited (20)
US 1062837A · Mertz · 1913 [cited by applicant]
US 8595822B2 · Schrecker et al. · 2013 [cited by applicant]
US 9438634B1 · Ross et al. · 2016 [cited by applicant]
US 9594881B2 · Bhargava et al. · 2017 [cited by applicant]
US 9756065B2 · Keohane et al. · 2017 [cited by applicant]
US 9916321B2 · Sundaram et al. · 2018 [cited by applicant]
US 9940330B2 · Le et al. · 2018 [cited by applicant]
US 10110636B2 · Ross et al. · 2018 [cited by applicant]
US 10157276B2 · Schilling et al. · 2018 [cited by applicant]
US 10320813B1 · Ahmed et al. · 2019 [cited by applicant]
US 10649863B2 · Kumarasamy et al. · 2020 [cited by applicant]
US 11216563B1 · Veselov · 2022 [cited by examiner]
US 11409611B2 · Sancheti · 2022 [cited by applicant]
US 11431735B2 · Shua · 2022 [cited by applicant]
US 20130219050A1 · Park et al. · 2013 [cited by applicant]
US 20210168150A1 · Ross et al. · 2021 [cited by applicant]
US 20210263802A1 · Gottemukkula et al. · 2021 [cited by applicant]
US 20210303685A1 · Klonowski et al. · 2021 [cited by applicant]
US 20230011004A1 · Fellows et al. · 2023 [cited by applicant]
WO WO2018033375A2 · 2018 [cited by examiner]
Cited By (3)
US 12,683,989 US 12,693,881 US 12,711,229