IP Library Granted Patent US 12,488,097
Granted Patent B2
US 12,488,097 · App. 17/815,289 · Granted Dec 2, 2025

Techniques for securing deployment of infrastructure as code

Inventors: Omer Deutscher (Tel Aviv, IL); Tomer Schwartz (Tel Aviv, IL); Eshel Yaron (Tel Aviv, IL); Barak Bercovitz (Even-Yehuda, IL)
Assignee: Wiz, Inc.
G06F21/554G06F2221/031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,097
App. No.
17/815,289
Granted
Dec 2, 2025
Kind
B2
Abstract

A system and method for securing deployment of computing infrastructure resources. A method includes identifying a first set of properties in original definitions of computing infrastructure resources, where each original definition is a definition of a respective computing infrastructure resource; mapping the first set of properties to a second set of properties of universal definition templates in order to determine a matching universal definition template for each original definition, where each of the universal definitions corresponds to a respective type of computing infrastructure resource and is defined in a unified format; transforming the original definitions into universal definitions using the universal definition templates, where transforming each original definition further includes inserting at least one of the first set of properties into the matching universal definition template for the original definition; and managing deployment of the computing infrastructure resources based on the universal definitions.

Claims (61)

1 . A method for securing deployment of computing infrastructure resources, comprising:

identifying a first plurality of properties in a plurality of original definitions of a plurality of computing infrastructure resources, wherein each original definition is a definition of a respective computing infrastructure resource of the plurality of computing infrastructure resources;

mapping the first plurality of properties to a second plurality of properties of a plurality of universal definition templates in order to determine a matching universal definition template for each original definition, wherein each of the plurality of universal definitions corresponds to a respective type of computing infrastructure resource and is defined in a unified format;

transforming the plurality of original definitions into a plurality of universal definitions using the plurality of universal definition templates, wherein transforming each original definition further comprises inserting at least one of the first plurality of properties into the matching universal definition template for the original definition; and

managing deployment of the plurality of computing infrastructure resources based on the plurality of universal definitions.

2 . The method of claim 1 , further comprising:

semantically analyzing the first plurality of properties, wherein the first plurality of properties is mapped to the second plurality of properties based on the semantic analysis.

3 . The method of claim 2 , wherein the first plurality of properties is semantically analyzed with respect to a plurality of predefined semantic concepts representing a plurality of potential properties of computing infrastructure resources represented in the plurality of universal definition templates.

4 . The method of claim 1 , further comprising:

creating a graph of connections between the plurality of computing infrastructure resources based on the plurality of universal definitions, wherein the deployment of the plurality of computing infrastructure resources is managed based further on the graph.

5 . The method of claim 1 , wherein managing deployment of the plurality of computing infrastructure resources further comprises:

applying at least one policy defining misconfigurations with respect to properties expressed in the unified format.

6 . The method of claim 1 , further comprising:

reformatting at least one original definition of the plurality of original definitions into a normalized original definition.

7 . The method of claim 6 , wherein reformatting each of the at least one original definition further comprises:

parsing the original definition to identify a plurality of expressions; and

interpreting the plurality of expressions with respect to a data-interchangeable language, wherein the normalized original definition is defined using the data-interchangeable language.

8 . The method of claim 6 , wherein reformatting each of the at least one original definition further comprises:

performing control flow analysis on the original definition in order to identify a plurality of commands; and

interpreting the plurality of commands with respect to a data-interchangeable language, wherein the normalized original definition is defined using the data-interchangeable language.

9 . The method of claim 1 , wherein reformatting each of the at least one original definition further comprises:

instrumenting infrastructure as code (IaC) instructions corresponding to each of the at least one original definition; and

analyzing outputs and instrumentation logs of the IaC instructions corresponding to each of the at least one original definition, wherein each of the at least one original definition is reformatted based on the analysis of the outputs and instrumentation logs.

10 . The method of claim 1 , further comprising:

preventing deployment of at least one of the plurality of computing infrastructure resources in a cloud environment based on the plurality of universal definitions.

11 . The method of claim 1 , further comprising:

performing at least one remedial action with respect to at least one of the plurality of computing infrastructure resources based on the plurality of universal definitions.

12 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

identifying a first plurality of properties in a plurality of original definitions of a plurality of computing infrastructure resources, wherein each original definition is a definition of a respective computing infrastructure resource of the plurality of computing infrastructure resources;

mapping the first plurality of properties to a second plurality of properties of a plurality of universal definition templates in order to determine a matching universal definition template for each original definition, wherein each of the plurality of universal definitions corresponds to a respective type of computing infrastructure resource and is defined in a unified format;

transforming the plurality of original definitions into a plurality of universal definitions using the plurality of universal definition templates, wherein transforming each original definition further comprises inserting at least one of the first plurality of properties into the matching universal definition template for the original definition; and

managing deployment of the plurality of computing infrastructure resources based on the plurality of universal definitions.

13 . A system for securing deployment of computing infrastructure resources, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

identify a first plurality of properties in a plurality of original definitions of a plurality of computing infrastructure resources, wherein each original definition is a definition of a respective computing infrastructure resource of the plurality of computing infrastructure resources;

map the first plurality of properties to a second plurality of properties of a plurality of universal definition templates in order to determine a matching universal definition template for each original definition, wherein each of the plurality of universal definitions corresponds to a respective type of computing infrastructure resource and is defined in a unified format;

transform the plurality of original definitions into a plurality of universal definitions using the plurality of universal definition templates, wherein transforming each original definition further comprises inserting at least one of the first plurality of properties into the matching universal definition template for the original definition; and

manage deployment of the plurality of computing infrastructure resources based on the plurality of universal definitions.

14 . The system of claim 13 , wherein the system is further configured to:

semantically analyze the first plurality of properties, wherein the first plurality of properties is mapped to the second plurality of properties based on the semantic analysis.

15 . The system of claim 14 , wherein the first plurality of properties is semantically analyzed with respect to a plurality of predefined semantic concepts representing a plurality of potential properties of computing infrastructure resources represented in the plurality of universal definition templates.

16 . The system of claim 13 , wherein the system is further configured to:

create a graph of connections between the plurality of computing infrastructure resources based on the plurality of universal definitions, wherein the deployment of the plurality of computing infrastructure resources is managed based further on the graph.

17 . The system of claim 13 , wherein the system is further configured to:

apply at least one policy defining misconfigurations with respect to properties expressed in the unified format.

18 . The system of claim 13 , wherein the system is further configured to:

reformat at least one original definition of the plurality of original definitions into a normalized original definition.

19 . The system of claim 18 , wherein the system is further configured to:

parse each original definition to identify a plurality of expressions; and

interpret the plurality of expressions identified for each original definition with respect to a data-interchangeable language, wherein the normalized original definition is defined using the data-interchangeable language.

20 . The system of claim 18 , wherein the system is further configured to:

perform control flow analysis on the original definition in order to identify a plurality of commands; and

interpret the plurality of commands with respect to a data-interchangeable language, wherein the normalized original definition is defined using the data-interchangeable language.

21 . The system of claim 13 , wherein the system is further configured to:

execute infrastructure as code (IaC) instructions corresponding to each of the at least one original definition; and

analyze an output of the execution of the IaC instructions corresponding to each of the at least one original definition, wherein each of the at least one original definition is reformatted based on the analysis of the output of the execution of the IaC instructions corresponding to the original definition.

22 . The system of claim 13 , wherein the system is further configured to:

prevent deployment of at least one of the plurality of computing infrastructure resources in a cloud environment based on the plurality of universal definitions.

23 . The system of claim 13 , wherein the system is further configured to:

perform at least one remedial action with respect to at least one of the plurality of computing infrastructure resources based on the plurality of universal definitions.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2025
From: DAZZ, INC.
To: WIZ, INC.
Reel/Frame 071645/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2022
From: DEUTSCHER, OMER; SCHWARTZ, TOMER; YARON, ESHEL; BERCOVITZ, BARAK
To: DAZZ, INC.
Reel/Frame 060640/0835 →
Continuity (1)
Related Publication 20240037227A1 · Feb 1, 2024
References Cited (68)
US 8271653B2 · DeHaan · 2012 [cited by applicant]
US 8806425B1 · Willis et al. · 2014 [cited by applicant]
US 9052961B2 · Mangtani · 2015 [cited by examiner]
US 9449042B1 · Evans et al. · 2016 [cited by applicant]
US 9450783B2 · DeHaan · 2016 [cited by applicant]
US 9734349B1 · Prafullchandra et al. · 2017 [cited by applicant]
US 10108803B2 · Chari et al. · 2018 [cited by applicant]
US 11429353B1 · Liguori · 2022 [cited by examiner]
US 11893106B2 · Kim et al. · 2024 [cited by applicant]
US 20030131284A1 · Flanagan et al. · 2003 [cited by applicant]
US 20090222479A1 · Burukhin et al. · 2009 [cited by applicant]
US 20100070448A1 · Omoigui · 2010 [cited by applicant]
US 20130167241A1 · Siman · 2013 [cited by applicant]
US 20150341214A1 · Croy et al. · 2015 [cited by applicant]
US 20150347759A1 · Cabrera et al. · 2015 [cited by applicant]
US 20150363197A1 · Carback et al. · 2015 [cited by applicant]
US 20160379480A1 · OlmstedThompson et al. · 2016 [cited by applicant]
US 20170075749A1 · Ambichl et al. · 2017 [cited by applicant]
US 20170185785A1 · Vorona et al. · 2017 [cited by applicant]
US 20170249128A1 · Fojtik et al. · 2017 [cited by applicant]
US 20170286692A1 · Nakajima et al. · 2017 [cited by applicant]
US 20180025160A1 · Hwang et al. · 2018 [cited by applicant]
US 20180129479A1 · McPherson et al. · 2018 [cited by applicant]
US 20180285199A1 · Mitkar et al. · 2018 [cited by applicant]
US 20180321918A1 · Mcclory et al. · 2018 [cited by applicant]
US 20180373507A1 · Mizrahi et al. · 2018 [cited by applicant]
US 20190007290A1 · He et al. · 2019 [cited by applicant]
US 20190068622A1 · Lin et al. · 2019 [cited by applicant]
US 20190294477A1 · Koppes et al. · 2019 [cited by applicant]
US 20190303579A1 · Reddy et al. · 2019 [cited by applicant]
US 20190318312A1 · Foskett et al. · 2019 [cited by applicant]
US 20190354389A1 · Du et al. · 2019 [cited by applicant]
US 20200097662A1 · Hufsmith et al. · 2020 [cited by applicant]
US 20200183766A1 · Kumar-Mayernik et al. · 2020 [cited by applicant]
US 20200296117A1 · Karpovsky et al. · 2020 [cited by applicant]
US 20200342511A1 · Bursey · 2020 [cited by applicant]
US 20210042096A1 · White, III · 2021 [cited by examiner]
US 20210168165A1 · Alsaeed et al. · 2021 [cited by applicant]
US 20210182387A1 · Zhu et al. · 2021 [cited by applicant]
US 20210311855A1 · Khan et al. · 2021 [cited by applicant]
US 20210382997A1 · Yi et al. · 2021 [cited by applicant]
US 20220114023A1 · Choksi · 2022 [cited by examiner]
US 20220129539A1 · Walsh et al. · 2022 [cited by applicant]
US 20220327220A1 · Sharma et al. · 2022 [cited by applicant]
US 20220353341A1 · Östrand · 2022 [cited by examiner]
US 20230036739A1 · Deppisch et al. · 2023 [cited by applicant]
US 20230118065A1 · Kumar · 2023 [cited by applicant]
US 20230229781A1 · Stolbikov et al. · 2023 [cited by applicant]
US 20230297366A1 · Wigglesworth et al. · 2023 [cited by applicant]
US 20230333845A1 · Zand et al. · 2023 [cited by applicant]
US 20250013442A1 · Hempstead et al. · 2025 [cited by applicant]
EP 3208996A1 · 2017 [cited by applicant]
EP 3494506A1 · 2019 [cited by applicant]
WO 2023067423A1 · 2023 [cited by applicant]
International Search Report for PCT Application No. PCT/IB2022/059483. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the International Searching Authority for PCT Application No. PCT/IB2022/059483 dated Jan. 8, 2023. The International Bureau of WIPO. [cited by applicant]
International Search Report, PCT/IB2023/052415; Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the International Searching Authority, PCT/IB2023/052415. Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
International Search Report for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Microsoft. “What is Infrastructure as Code?” Article. Jun. 29, 2021. https://docs.microsoft.com/en-us/devops/deliver/what-is-infrastructure-as-code. [cited by applicant]
Doan TP, Jung S. Davs: Dockerfile Analysis for Container Image Vulnerability Scanning. CMC-Computers Materials & CONTINUA. Jan. 1, 2022;72(1):1699-711. Jan. 1, 2022 (Jan. 1, 2022). [cited by applicant]
International Search Report for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the Searching Authority for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
International Search Report for PCT/IB2025/051650, dated May 26, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2025/051650, dated May 26, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Alrabaee, “A Survey of Binary Code Fingerprinting Approaches: Taxonomy, Methodologies, and Features”, 2022, ACM (Year: 2022). [cited by applicant]
Liu, “Vfdetect: A Vulnerable Code Clone Detection System Based on Vulnerability Fingerprint”, 2017, IEEE (Year: 2017). [cited by applicant]