IP Library Granted Patent US 12,126,644
Granted Patent B2
US 12,126,644 · App. 17/745,743 · Granted Oct 22, 2024

Methods and apparatus to identify and report cloud-based security vulnerabilities

Inventors: Sriranga Seetharamaiah (Bangalore, IN); Cedric Cochin (Hillsboro, OR)
Assignee: Skyhigh Security LLC
H04L63/1433H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,126,644
App. No.
17/745,743
Granted
Oct 22, 2024
Kind
B2
Abstract

Methods, apparatus, systems, and articles of manufacture are disclosed to identify and report cloud-based security vulnerabilities. An example apparatus includes memory, instructions, and processor circuitry. The example processor circuitry is to execute the instructions to assess a first security vulnerability associated with an application programming interface (API) of a cloud compute network, the first security vulnerability corresponding to at least one call to the API that deviates from a baseline report, the baseline report based on at least one communication in the cloud compute network, and assess a second security vulnerability associated with identity and access management in the cloud compute network based on an entity in the cloud compute network permitted to access a service provided by the cloud compute network, the second security vulnerability corresponding to an unauthorized request to access at least one of a device of the cloud compute network or the service.

Claims (39)

1. An apparatus comprising:

memory;

instructions; and

processor circuitry to execute the instructions to at least:

assess a first security vulnerability associated with an application programming interface (API) of a cloud compute network, the first security vulnerability corresponding to at least one call to the API that deviates from a baseline report, the baseline report based on at least one communication in the cloud compute network; and

assess a second security vulnerability associated with identity and access management in the cloud compute network based on an entity in the cloud compute network permitted to access a service provided by the cloud compute network, the second security vulnerability corresponding to an unauthorized request to access at least one of a device of the cloud compute network or the service provided by the cloud compute network,

wherein the processor circuitry is to assess a third security vulnerability in a configuration of the cloud compute network based on at least one of (a) a policy associated with the cloud compute network or (b) metadata associated with the service provided by the cloud compute network, and

wherein the processor circuitry is to assess the third security vulnerability based on whether a change to the metadata associated with the service occurs outside of a scheduled period of at least one of deployment or maintenance.

2. The apparatus of claim 1 , wherein the processor circuitry is to assess the second security vulnerability associated with the identity and access management in the cloud compute network based on at least one rule, the at least one rule based on a policy associated with the cloud compute network.

3. The apparatus of claim 1 , wherein the processor circuitry is to assess the second security vulnerability associated with the identity and access management in the cloud compute network based on a list of which entities are permitted to access the service provided by the cloud compute network.

4. The apparatus of claim 1 , wherein the at least one communication in the cloud compute network includes one or more communications between one or more entities in the cloud compute network, one or more resources of the cloud compute network, and the API.

5. The apparatus of claim 1 , wherein the baseline report is to indicate one or more expected communications between one or more entities in the cloud compute network, one or more resources of the cloud compute network, and the API.

6. A non-transitory computer readable medium comprising instructions that, when executed, cause processor circuitry to at least:

check for a first security vulnerability associated with an application programming interface (API) of a cloud compute network, the first security vulnerability corresponding to at least one call to the API that deviates from a baseline report, the baseline report based on at least one communication in the cloud compute network; and

check for a second security vulnerability associated with identity and access management in the cloud compute network, the check for the second security vulnerability based on an entity in the cloud compute network permitted to access a service provided by the cloud compute network, the second security vulnerability corresponding to an unauthorized request to access at least one of a device of the cloud compute network or the service provided by the cloud compute network,

wherein the instructions are to cause the processor circuitry to check for a third security vulnerability in a configuration of the cloud compute network based on at least one of (a) a policy associated with the cloud compute network or (b) metadata associated with the service provided by the cloud compute network, and

wherein the instructions are to cause the processor circuitry to check for the third security vulnerability based on whether a change to the metadata associated with the service occurs outside of a scheduled period of at least one of deployment or maintenance.

7. The non-transitory computer readable medium of claim 6 , wherein the instructions are to cause the processor circuitry to check for the second security vulnerability associated with the identity and access management in the cloud compute network based on at least one rule, the at least one rule based on a policy associated with the cloud compute network.

8. The non-transitory computer readable medium of claim 6 , wherein the instructions are to cause the processor circuitry to check for the second security vulnerability associated with the identity and access management in the cloud compute network, the check for the second security vulnerability based on a list of which entities are permitted to access the service provided by the cloud compute network.

9. The non-transitory computer readable medium of claim 6 , wherein the at least one communication in the cloud compute network includes one or more communications between one or more entities in the cloud compute network, one or more resources of the cloud compute network, and the API.

10. The non-transitory computer readable medium of claim 6 , wherein the baseline report is to indicate one or more expected communications between one or more entities in the cloud compute network, one or more resources of the cloud compute network, and the API.

11. An apparatus comprising:

means for auditing cloud application programming interface (API) logs for a first security vulnerability associated with an API of a cloud compute network, the first security vulnerability corresponding to at least one call to the API that deviates from a baseline report, the baseline report based on at least one communication in the cloud compute network; and

means for auditing an identification for a second security vulnerability associated with identity and access management in the cloud compute network, the auditing of the identification based on an entity in the cloud compute network permitted to access a service provided by the cloud compute network, the second security vulnerability corresponding to an unauthorized request to access at least one of a device of the cloud compute network or the service provided by the cloud compute network,

further including means for auditing cloud configurations for a third security vulnerability in a configuration of the cloud compute network, the auditing of the configuration based on at least one of (a) a policy associated with the cloud compute network or (b) metadata associated with the service provided by the cloud compute network, and

wherein the means for auditing cloud configurations for the third security vulnerability is to audit the configuration of the cloud compute network based on whether a change to the metadata associated with the service occurs outside of a scheduled period of at least one of deployment or maintenance.

12. The apparatus of claim 11 , wherein the means for auditing the identification for the second vulnerability is to audit the identification based on at least one rule, the at least one rule based on a policy associated with the cloud compute network.

13. The apparatus of claim 11 , wherein the means for auditing the identification for the second vulnerability is to audit the identification based on a list of which entities are permitted to access the service provided by the cloud compute network.

14. The apparatus of claim 11 , wherein the at least one communication in the cloud compute network includes one or more communications between one or more entities in the cloud compute network, one or more resources of the cloud compute network, and the API.

15. The apparatus of claim 11 , wherein the baseline report is to indicate one or more expected communications between one or more entities in the cloud compute network, one or more resources of the cloud compute network, and the API.

16. A method comprising:

monitoring for a first security vulnerability associated with an application programming interface (API) of a cloud compute network, the first security vulnerability corresponding to at least one call to the API that deviates from a baseline report, the baseline report based on at least one communication in the cloud compute network; and

monitoring for a second security vulnerability associated with identity and access management in the cloud compute network, the monitoring for the second security vulnerability based on an entity in the cloud compute network permitted to access a service provided by the cloud compute network, the second security vulnerability corresponding to an unauthorized request to access at least one of a device of the cloud compute network or the service provided by the cloud compute network,

further including monitoring for a third security vulnerability in a configuration of the cloud compute network based on at least one of (a) a policy associated with the cloud compute network or (b) metadata associated with the service provided by the cloud compute network, and

further including monitoring for the third security vulnerability based on whether a change to the metadata associated with the service occurs outside of a scheduled period of at least one of deployment or maintenance.

17. The method of claim 16 , further including monitoring for the second security vulnerability associated with the identity and access management in the cloud compute network based on at least one rule, the at least one rule based on a policy associated with the cloud compute network.

18. The method of claim 16 , further including checking for the second security vulnerability associated with the identity and access management in the cloud compute network based on a list of which entities are permitted to access the service provided by the cloud compute network.

19. The method of claim 16 , wherein the at least one communication in the cloud compute network includes one or more communications between one or more entities in the cloud compute network, one or more resources of the cloud compute network, and the API.

20. The method of claim 16 , wherein the baseline report is to indicate one or more expected communications between one or more entities in the cloud compute network, one or more resources of the cloud compute network, and the API.

Assignments (8)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 060433/0826 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060561/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2022
From: SEETHARAMAIAH, SRIRANGA; COCHIN, CEDRIC
To: MCAFEE, LLC
Reel/Frame 060334/0170 →
Priority Claims (1)
IN 201911039156 · Sep 27, 2019 · national
Continuity (2)
Continuation 16728905 · Dec 27, 2019
Related Publication 20220279012A1 · Sep 1, 2022
Cited By (5)
US 12,452,290 US 12,549,581 US 12,596,791 US 12,608,260 US 12,719,914