IP Library › Granted Patent US 12,693,881
Granted Patent B1
US 12,693,881 · App. 17/804,923 · Granted Jul 28, 2026

Unified inspection techniques based on abstracted compute type

Inventors: Yaniv Shaked (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Roy Reznik (Tel Aviv, IL); Yarin Miran (Rishon Lezion, IL); Moran Cohen (Tel Aviv, IL)
Assignee: Wiz, Inc.
G06F9/45558G06F8/63G06F9/5077G06F21/602G06F2009/4557G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,693,881
App. No.
17/804,923
Filed
Jun 1, 2022
Granted
Jul 28, 2026
Kind
B1
Art Unit
2194
USPC
718/1
Abstract

A system and method for inspecting different types of cloud workloads for cybersecurity threats, all deployed in a cloud computing environment, includes a unifying extractor to expose different compute types to agnostic inspectors. The method includes accessing a first cloud workload of a first type from a plurality of deployed cloud workloads; accessing a second cloud workload of a second type from the plurality of deployed cloud workloads; extracting data from each of the first cloud workload and the second cloud workload into a storage layer having a data schema, based on a predefined data structure; and inspecting the extracted data to detect a first target object, the target object indicating a cybersecurity threat, wherein extraction for each of the first cloud workload and the second cloud workload is based on the workload type.

Claims (76)

1 . A method for inspecting different types of cloud workloads for cybersecurity threats, all of the cloud workloads deployed in a cloud computing environment, comprising:

accessing a first disk of a first cloud workload of a plurality of deployed cloud workloads, the first workload being of a first type;

accessing a second disk of a second cloud workload of a plurality of deployed cloud workloads, the second workload being of a second type;

extracting data from each of the first cloud workload and the second cloud workload into a storage layer in storage of a third disk, the storage layer having a data schema, based on a predefined data structure;

inspecting the extracted data to detect a first target object, the target object indicating a cybersecurity threat, wherein extraction for each of the first cloud workload and the second cloud workload is based on the workload type;

representing the first target object as a first node in a security graph stored on a security database;

representing a disk of the first disk and the second disk storing the first target object as a second node connected to the first node in the security graph; and

representing a cloud workload of the first cloud workload and the second cloud workload as a machine node connected to the second node, the cloud workload allocated the disk in the security graph.

2 . The method of claim 1 , wherein the cloud workload is a virtual machine.

3 . The method of claim 2 , further comprising:

generating a snapshot of a disk of the virtual machine;

mounting the snapshot as an inspection disk; and

extracting data from the inspection disk into the storage layer.

4 . The method of claim 3 , further comprising:

generating a re-encrypted snapshot of the disk of the virtual machine, wherein the disk is encrypted with an encryption key which is not accessible.

5 . The method of claim 1 , wherein the cloud workload is a software container.

6 . The method of claim 5 , further comprising:

opening each layer of a plurality of layers of the software container;

extracting data from each layer; and

storing the extracted data from each layer in the storage layer.

7 . The method of claim 5 , further comprising:

accessing a container image repository to extract an image of the software container;

deploying another container based on the extracted image; and

extracting data from the another container.

8 . The method of claim 1 , wherein the cloud workload is a serverless function.

9 . The method of claim 8 , further comprising:

receiving an extractable object associated with the serverless function; and

extracting data from the extractable object.

10 . The method of claim 9 , further comprising:

decompressing the extractable object, when the extractable object is a compressed file.

11 . The method of claim 1 , further comprising:

inspecting the extracted data with a first type of inspector for a first type of cybersecurity threat; and

inspecting the extracted data with a second type of inspector for a second type of cybersecurity threat, which is not the first type of cybersecurity threat.

12 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

accessing a first disk of a first cloud workload of a plurality of deployed cloud workloads, the first workload being of a first type;

accessing a second disk of a second cloud workload of a plurality of deployed cloud workloads, the second workload being of a second;

extracting data from each of the first cloud workload and the second cloud workload into a storage layer in storage of a third disk, the storage layer having a data schema, based on a predefined data structure;

inspecting the extracted data to detect a first target object, the target object indicating a cybersecurity threat, wherein extraction for each of the first cloud workload and the second cloud workload is based on the workload type;

representing the first target object as a first node in a security graph stored on a security database;

representing a disk of the first disk and the second disk storing the first target object as a second node connected to the first node in the security graph; and

representing a cloud workload of the first cloud workload and the second cloud workload as a machine node connected to the second node, the cloud workload allocated the disk in the security graph.

13 . A system for inspecting different types of cloud workloads for cybersecurity threats, all of the cloud workloads deployed in a cloud computing environment, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

access a first disk of a first cloud workload of a plurality of deployed cloud workloads, the first workload being of a first type;

access a second disk of a second cloud workload of a plurality of deployed cloud workloads, the second workload being of a second type;

extract data from each of the first cloud workload and the second cloud workload into a storage layer in storage of a third disk, the storage layer having a data schema, based on a predefined data structure;

inspect the extracted data to detect a first target object, the target object indicating a cybersecurity threat, wherein extraction for each of the first cloud workload and the second cloud workload is based on the workload type;

represent the first target object as a first node in a security graph stored on a security database;

represent a disk of the first disk and the second disk storing the first target object as a second node connected to the first node in the security graph; and

represent a cloud workload of the first cloud workload and the second cloud workload as a machine node connected to the second node, the cloud workload allocated the disk in the security graph.

14 . The system of claim 13 , wherein the cloud workload is a virtual machine.

15 . The system of claim 14 , wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to:

generate a snapshot of a disk of the virtual machine;

mount the snapshot as an inspection disk; and

extract data from the inspection disk into the storage layer.

16 . The system of claim 15 , wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to:

generate a re-encrypted snapshot of the disk of the virtual machine, wherein the disk is encrypted with an encryption key which is not accessible.

17 . The system of claim 13 , wherein the cloud workload is a software container.

18 . The system of claim 17 , wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to:

open each layer of a plurality of layers of the software container;

extract data from each layer; and

store the extracted data from each layer in the storage layer.

19 . The system of claim 17 , wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to:

access a container image repository to extract an image of the software container;

deploy another container based on the extracted image; and

extract data from the another container.

20 . The system of claim 13 , wherein the cloud workload is a serverless function.

21 . The system of claim 20 , wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to:

receive an extractable object associated with the serverless function; and

extract data from the extractable object.

22 . The system of claim 21 , wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to:

decompress the extractable object, when the extractable object is a compressed file.

23 . The system of claim 13 , wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to:

inspect the extracted data with a first type of inspector for a first type of cybersecurity threat; and

inspect the extracted data with a second type of inspector for a second type of cybersecurity threat, which is not the first type of cybersecurity threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2022
From: SHAKED, YANIV; LUTTWAK, AMI; REZNIK, ROY; MIRAN, YARIN; COHEN, MORAN
To: WIZ, INC.
Reel/Frame 060070/0813 →
Continuity (1)
Provisional Application 63196384 · Jun 3, 2021
References Cited (54)
US 1062837A · Mertz · 1913 [cited by applicant]
US 7606868B1 · Le et al. · 2009 [cited by applicant]
US 9171178B1 · Banerjee · 2015 [cited by applicant]
US 9203862B1 · Kashyap et al. · 2015 [cited by applicant]
US 9916321B2 · Sundaram et al. · 2018 [cited by applicant]
US 9934376B1 · Ismael · 2018 [cited by applicant]
US 9940330B2 · Le et al. · 2018 [cited by applicant]
US 9961098B2 · Antony · 2018 [cited by applicant]
US 10601807B2 · Sweet et al. · 2020 [cited by applicant]
US 10649863B2 · Kumarasamy et al. · 2020 [cited by applicant]
US 10747568B2 · Ahmed · 2020 [cited by applicant]
US 10803169B1 · Flatten et al. · 2020 [cited by applicant]
US 11216563B1 · Veselov · 2022 [cited by examiner]
US 11237807B1 · Rao et al. · 2022 [cited by applicant]
US 11409611B2 · Sancheti · 2022 [cited by applicant]
US 11431735B2 · Shua · 2022 [cited by applicant]
US 11973770B1 · Miran · 2024 [cited by examiner]
US 12231448B2 · Sakazi · 2025 [cited by examiner]
US 12238140B2 · Bazalgette · 2025 [cited by examiner]
US 12248581B1 · Shaked · 2025 [cited by examiner]
US 12333010B1 · Berkovitz · 2025 [cited by examiner]
US 12348540B2 · Ghalaty · 2025 [cited by examiner]
US 12518021B1 · Berkovitz · 2026 [cited by examiner]
US 20100138924A1 · Heim et al. · 2010 [cited by applicant]
US 20160072817A1 · Makhervaks et al. · 2016 [cited by applicant]
US 20170109536A1 · Stopel et al. · 2017 [cited by applicant]
US 20170220804A1 · Muthurajan et al. · 2017 [cited by applicant]
US 20170345016A1 · Meek et al. · 2017 [cited by applicant]
US 20180324203A1 · Estes et al. · 2018 [cited by applicant]
US 20190042328A1 · Ortega et al. · 2019 [cited by applicant]
US 20190340167A1 · Raman et al. · 2019 [cited by applicant]
US 20200065487A1 · Timashev et al. · 2020 [cited by applicant]
US 20200082094A1 · Mcallister · 2020 [cited by examiner]
US 20200159933A1 · Ciano et al. · 2020 [cited by applicant]
US 20200249928A1 · Zeng et al. · 2020 [cited by applicant]
US 20210117377A1 · Savir · 2021 [cited by examiner]
US 20210133328A1 · Wu · 2021 [cited by examiner]
US 20210149788A1 · Downie et al. · 2021 [cited by applicant]
US 20210208952A1 · Jain et al. · 2021 [cited by applicant]
US 20210255901A1 · Hintermeister et al. · 2021 [cited by applicant]
US 20210263802A1 · Gottemukkula et al. · 2021 [cited by applicant]
US 20210320938A1 · Ober · 2021 [cited by examiner]
US 20220038544A1 · Grinstein et al. · 2022 [cited by applicant]
US 20220129540A1 · Sheriff · 2022 [cited by examiner]
US 20220329616A1 · O'Hearn · 2022 [cited by examiner]
US 20230102103A1 · Mazumder · 2023 [cited by examiner]
US 20230123477A1 · Luttwak · 2023 [cited by examiner]
US 20230336550A1 · Lidgi · 2023 [cited by examiner]
US 20230336554A1 · Lidgi · 2023 [cited by examiner]
US 20230336578A1 · Lidgi · 2023 [cited by examiner]
US 20230376586A1 · Shemesh · 2023 [cited by examiner]
S. Wang et al., “Threatrace: Detecting and Tracing Host-Based Threats in Node Level Through Provenance Graph Learning,” in IEEE Transactions on Information Forensics and Security, vol. 17, pp. 3972-3987, 2022 (Year: 202… [cited by examiner]
Girma et al., Analysis of Security Vulnerabilities of Cloud Computing Environment Service Models and its Main Characteristics: 2015 12th International Conference on Information Technology—New Generations Year: 2015 | Co… [cited by applicant]
Kankhare et al., “A cloud based system to sense security vulnerabilities of web application in open-source private could IAAS,” 2016 International Conference on Electrical, Electronics, Communication, Computer and Optim… [cited by applicant]