IP Library › Granted Patent US 11,722,554
Granted Patent B2
US 11,722,554 · App. 17/819,442 · Granted Aug 8, 2023

System and method for analyzing network objects in a cloud environment

Inventors: Shai Keren (Tel Aviv, IL); Danny Shemesh (Tel Aviv, IL); Roy Reznik (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Avihai Berkovitz (Tel Aviv, IL)
Assignee: WIZ, INC.
H04L67/10H04L41/046H04L41/5096H04L49/70H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,554
App. No.
17/819,442
Filed
Aug 12, 2022
Granted
Aug 8, 2023
Kind
B2
Art Unit
2447
USPC
709/223
Abstract

A method and system for determining abnormal configuration of network objects deployed in a cloud computing environment are provided. The method includes collecting network object data on a plurality of network objects deployed in the cloud computing environment; constructing a network graph based on the collected network object data, wherein the network graph includes a visual representation of network objects identified in the cloud computing environment; determining relationships between the identified network objects in the network graph, wherein the determined relationships between the identified network objects includes descriptions of connections between the identified network objects; and analyzing the network graph and the determined relationships to generate insights, wherein the generated insights include at least a list of abnormal connections between the identified network objects.

Claims (50)

1. A method for determining abnormal configuration of network objects deployed in a cloud computing environment, comprising:

collecting network object data on a plurality of network objects deployed in the cloud computing environment;

constructing a network graph based on the collected network object data, wherein the network graph includes a visual representation of network objects identified in the cloud computing environment;

determining relationships between the identified network objects in the network graph, wherein the determined relationships between the identified network objects includes descriptions of connections between the identified network objects;

analyzing the network graph and the determined relationships to generate insights, wherein the generated insights include at least a list of abnormal connections between the identified network objects; and

tagging network objects in the network graph for which the insight is generated.

2. The method of claim 1 , wherein the cloud computing environment includes a plurality of different cloud computing platforms.

3. The method of claim 2 , wherein collecting network object data further comprises:

connecting through an application programing interface (API) each of the plurality of different cloud computing platforms to collect network object data of network objects deployed in the respective cloud computing platform.

4. The method of claim 1 , wherein generating insights to include at least the list of abnormal connections further comprises:

detecting any one of: a rare network configuration, a novel network configuration, a rare network event, a novel network event, a connection of a new device to a network, an unauthorized connection, a re-connection of a user device to a subnet which the user is not permitted to access, a connection demonstrating anomalous behavior or misconfiguration, and a connection demonstrating spikes of network activity.

5. The method of claim 4 , further comprising:

determining impermissible relationships between the network objects.

6. The method of claim 1 , wherein determining relationships between the identified objects further comprises:

determining the relationships using a static analytic method.

7. The method of claim 1 , wherein determining the relationships between the identified network objects in further comprises:

determining the relationships using at least one of: observational methods, and active logging methods.

8. The method of claim 1 , further comprising:

adding visual representations of the determined relationships to the visual representations of the network graph.

9. The method of claim 1 , wherein each of the plurality of network objects includes any one of: a virtual network, a firewall, a network interface card, a proxy, a gateway, a software container, container, a management object, a virtual machine, a subnet, a hub, a virtual private network (VPN).

10. The method of claim 1 , wherein a generated insight of the generated insights is generated utilizing natural language representation.

11. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for determining abnormal configuration of network objects deployed in a cloud computing environment, the process comprising:

collecting network object data on a plurality of network objects deployed in the cloud computing environment;

constructing a network graph based on the collected network object data, wherein the network graph includes a visual representation of network objects identified in the cloud computing environment;

determining relationships between the identified network objects in the network graph, wherein the determined relationships between the identified network objects includes descriptions of connections between the identified network objects;

analyzing the network graph and the determined relationships to generate insights, wherein the generated insights include at least a list of abnormal connections between the identified network objects; and

tagging network objects in the network graph for which the insight is generated.

12. A system for determining abnormal configuration of network objects deployed in a cloud computing environment, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

collect network object data on a plurality of network objects deployed in the cloud computing environment;

construct a network graph based on the collected network object data, wherein the network graph includes a visual representation of network objects identified in the cloud computing environment;

determine relationships between the identified network objects in the network graph, wherein the determined relationships between the identified network objects includes descriptions of connections between the identified network objects;

analyze the network graph and the determined relationships to generate insights, wherein the generated insights include at least a list of abnormal connections between the identified network objects; and

tagging network objects in the network graph for which the insight is generated.

13. The system of claim 12 , wherein the cloud computing environment includes a plurality of different cloud computing platforms.

14. The system of claim 13 , wherein the system is further configured to:

connect through an application programing interface (API) each of the plurality of different cloud computing platforms to collect network object data of network objects deployed in the respective cloud computing platform.

15. The system of claim 12 , wherein the system is further configured to:

detect any one of: a rare network configuration, a novel network configuration, a rare network event, a novel network event, a connection of a new device to a network, an unauthorized connection, a re-connection of a user device to a subnet which the user is not permitted to access, a connection demonstrating anomalous behavior or misconfiguration, and a connection demonstrating spikes of network activity.

16. The system of claim 12 , wherein the system is further configured to:

determine impermissible relationships between the network objects.

17. The system of claim 12 , wherein the system is further configured to:

determine the relationships using a static analytic method.

18. The system of claim 12 , wherein the system is further configured to:

determine the relationships using at least one of: observational methods, and active logging methods.

19. The system of claim 12 , wherein the system is further configured to:

adding visual representations of the determined relationships to the visual representations of the network graph.

20. The system of claim 12 , wherein each of the plurality of network objects includes any one of: a virtual network, a firewall, a network interface card, a proxy, a gateway, a software container, container, a management object, a virtual machine, a subnet, a hub, a virtual private network (VPN).

21. The system of claim 12 , wherein a generated insight of the generated insights is generated utilizing natural language representation.

Continuity (2)
Continuation 17109883 · Dec 2, 2020
Related Publication 20220394082A1 · Dec 8, 2022
Cited By (110)
US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,476,915 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896 US 12,726,495 US 12,730,899 US 12,739,266 US 12,739,267 US 12,744,799 US 12,744,800 US 12,744,802 US 12,750,382 US 12,750,383