IP Library Granted Patent US 11,750,618
Granted Patent B1
US 11,750,618 · App. 17/710,909 · Granted Sep 5, 2023

System and method for retrieval and analysis of operational data from customer, cloud-hosted virtual resources

Inventors: Sai Vashisht (Morgan Hill, CA); Sumer Deshpande (Milpitas, CA); Sushant Paithane (Pune, IN); Rahul Khul (Pune, IN)
Assignee: FireEye Security Holdings US LLC
H04L63/102G06F9/5077G06F9/54H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,618
App. No.
17/710,909
Granted
Sep 5, 2023
Kind
B1
Abstract

A system for protecting public cloud-hosted virtual resources features cloud visibility logic. According to one embodiment, the cloud visibility logic includes credential evaluation logic, data collection logic, correlation logic, and reporting logic. The credential evaluation logic is configured to gain authorized access to a cloud account within a first public cloud network. The data collection logic is configured to retrieve account data from the cloud account, while the correlation logic is configured to conduct analytics on the account data to determine whether the cloud account is subject to a cybersecurity threat or misconfiguration. The reporting logic is configured to generate an alert when the cloud account is determined by the correlation logic to be subject to the cybersecurity threat or misconfiguration.

Claims (40)

1. A non-transitory storage medium including software configured to protect public cloud-hosted virtual resources, comprising:

credential evaluation logic configured to gain authorized access to a cloud account within a first public cloud network based at least on submission of a valid access token obtained by the software to logic that controls access to account data within the cloud account;

data collection logic configured to retrieve the account data from the cloud account;

correlation logic configured to conduct analytics on the account data to determine whether the cloud account is subject to a cybersecurity threat or misconfiguration; and

reporting logic configured to generate an alert when the cloud account is determined to be subject to the cybersecurity threat or misconfiguration.

2. The non-transitory storage medium of claim 1 , wherein the credential evaluation logic is configured to select an authentication operation to be performed to obtain the valid access token.

3. The non-transitory storage medium of claim 1 , wherein the credential evaluation logic to obtain the valid access token by generating for display a web user interface portal to receive as input information that, upon authenticated, prompts return of the valid access token.

4. The non-transitory storage medium of claim 1 , wherein at least the credential evaluation logic and the data collection logic operate based on execution by a virtual compute engine instance.

5. The non-transitory storage medium of claim 1 , wherein the account data includes operational log data pertaining to one or more events performed by the public cloud-hosted virtual resources that cause a change of state in an infrastructure of the cloud account.

6. The non-transitory storage medium of claim 5 , wherein the operational log data include meta-information associated with one or more Application Programming Interface (API) calls stored within an API log.

7. The non-transitory storage medium of claim 1 further comprising:

visualization logic configured to receive a portion of the account data including data associated with an infrastructure of the cloud account and generate a visualization of the cloud account including public cloud-hosted virtual resources forming the infrastructure of the cloud account.

8. The non-transitory storage medium of claim 7 , wherein the visualization logic to highlight or visually enhance one or more display elements of the virtualization of the infrastructure of the cloud account that correspond to potentially compromised or misconfigured public cloud-hosted virtual resources of the public cloud-hosted virtual resources.

9. The non-transitory storage medium of claim 1 further comprising:

remediation logic to initiate one or more actions to remediate the cybersecurity threat to or misconfiguration of the cloud account, the one or more actions include reverting a policy of operation for one or more of the public cloud-hosted virtual resources utilized by the cloud account to a default or predetermined configuration, the policy of operation being established through one or more settings or rules.

10. A computerized method, comprising:

gaining authorized access to a cloud account within a first public cloud network based at least on submission of a valid access token obtained by logic that controls access to account data within the cloud account;

retrieving the account data from the cloud account;

conducting analytics on the account data to determine whether the cloud account is subject to a cybersecurity threat or misconfiguration; and

generating an alert when the cloud account is determined to be subject to the cybersecurity threat or misconfiguration.

11. The computerized method of claim 10 , wherein the gaining of authorized access to the cloud account comprises selecting an authentication operation to be performed to obtain the valid access token.

12. The computerized method of claim 10 , wherein the gaining of authorized access to the cloud account comprises obtaining the valid access token by at least generating for display a web user interface portal to receive as input information that, upon authenticated, prompts return of the valid access token.

13. The computerized method of claim 10 , wherein the account data includes operational log data pertaining to one or more events performed by public cloud-hosted virtual resources that cause a change of state in an infrastructure of the cloud account.

14. The computerized method of claim 13 , wherein the operational log data include meta-information associated with one or more Application Programming Interface (API) calls stored within an API log.

15. The computerized method of claim 10 further comprising:

receiving a portion of the account data including data associated with an infrastructure of the cloud account; and

generating a visualization of the cloud account including public cloud-hosted virtual resources forming the infrastructure of the cloud account.

16. The computerized method of claim 15 , wherein the generating of the visualization includes highlighting or visually enhancing one or more display elements of the virtualization of the infrastructure of the cloud account that correspond to potentially compromised or misconfigured public cloud-hosted virtual resources of the public cloud-hosted virtual resources.

17. The computerized method of claim 10 further comprising:

initiating one or more actions to remediate the cybersecurity threat to or misconfiguration of the cloud account, the one or more actions include reverting a policy of operation for one or more of public cloud-hosted virtual resources utilized by the cloud account to a default or predetermined configuration, the policy of operation being established through one or more settings or rules.

18. A cloud resource monitoring system, comprising:

one or more virtual compute engines; and

a non-transitory storage medium including logic executed by the one or more virtual compute engines, the logic comprises

credential evaluation logic configured to gain authorized access to a cloud account within a first public cloud network based at least on submission of a valid access token obtained by the software to logic that controls access to account data within the cloud account,

data collection logic configured to retrieve the account data from the cloud account, and

correlation logic configured to conduct analytics on the account data to determine whether the cloud account is subject to a cybersecurity threat or misconfiguration.

19. The cloud resource monitoring system of claim 18 , wherein the non-transitory storage medium further comprises reporting logic configured to generate an alert when the cloud account is determined to be subject to the cybersecurity threat or misconfiguration.

20. The cloud resource monitoring system of claim 18 , wherein the non-transitory storage medium further comprises visualization logic configured to receive a portion of the account data including data associated with an infrastructure of the cloud account and generate a visualization of the cloud account including public cloud-hosted virtual resources forming the infrastructure of the cloud account.

21. The cloud resource monitoring system of claim 20 , wherein the visualization logic to highlight or visually enhance one or more display elements of the virtualization of the infrastructure of the cloud account that correspond to potentially compromised or misconfigured public cloud-hosted virtual resources of the public cloud-hosted virtual resources.

22. The cloud resource monitoring system of claim 18 , wherein the non-transitory storage medium further comprises remediation logic to initiate one or more actions to remediate the cybersecurity threat to or misconfiguration of the cloud account, the one or more actions include reverting a policy of operation for one or more of the public cloud-hosted virtual resources utilized by the cloud account to a default or predetermined configuration, the policy of operation being established through one or more settings or rules.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063114/0701 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063114/0766 →