IP Library Granted Patent US 11,611,573
Granted Patent B1
US 11,611,573 · App. 17/858,914 · Granted Mar 21, 2023

In-cloud and constant time scanners

Inventors: Ravishankar Ganesh Ithal (Los Altos, CA); Yang Zhang (Fremont, CA); Kapil Neeralgi (Bangalore, IN)
Assignee: Normalyze, Inc.
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,611,573
App. No.
17/858,914
Granted
Mar 21, 2023
Kind
B1
Abstract

The technology disclosed relates to in-cloud, constant time content scanning. In particular, it relates to obtaining administrative access to a cloud environment account for bulk content scanning of storage resources, and deploying serverless, containerized scanners to run locally on the cloud environment account, including queuing objects in the cloud environment account, partitioning the objects into a plurality of object chunks, and depending upon a M number of object chunks in the plurality of object chunks, initializing a N number of instances of the serverless, containerized scanners, where M>>N. Each initialized serverless, containerized scanner scans a corresponding object chunk exactly once to detect a multiplicity of different data patterns.

Claims (50)

1. A computer-implemented method of in-cloud, constant time content scanning, the method comprising:

obtaining administrative access to a cloud environment account for bulk content scanning of storage resources; and

deploying serverless, containerized scanners to run locally on the cloud environment account, comprising:

queuing objects in the cloud environment account; partitioning the objects into a plurality of object chunks; and

depending upon a M number of object chunks in the plurality of object chunks, initializing a N number of instances of the serverless, containerized scanners,

where M wherein each initialized serverless, containerized scanner scans a corresponding object chunk exactly once to detect a multiplicity of different data patterns;

wherein the M number of object chunks is at least one hundred times the N number of instances of the serverless, containerized scanners; wherein the different data patterns comprise different sensitive data patterns.

2. The computer-implemented method of claim 1 , wherein the M number of object chunks is at least one thousand times the N number of instances of the serverless, containerized scanners.

3. The computer-implemented method of claim 1 , wherein the serverless, containerized scanners are dynamically scalable.

4. The computer-implemented method of claim 1 , wherein each serverless, containerized scanner comprises a portable and independently executable microservice.

5. The computer-implemented method of claim 1 , wherein the different sensitive data patterns comprise a multiplicity of sensitive string patterns.

6. The computer-implemented method of claim 1 , wherein the serverless, containerized scanners generate sensitivity metadata based on detection of at least some sensitive data patterns in the multiplicity of sensitivity data patterns.

7. The computer-implemented method of claim 6 , wherein the serverless, containerized scanners send the sensitivity metadata to a metadata store in a control plane in the cloud environment account.

8. The computer-implemented method of claim 7 , and further comprising:

applying sensitivity annotations to a cloud data attack surface graph based on the sensitivity metadata.

9. The computer-implemented method of claim 7 , and further comprising:

applying sensitivity annotations to a cloud infrastructure graph based on the sensitivity metadata.

10. The computer-implemented method of claim 1 , wherein each initialized serverless, containerized scanner scans a corresponding object chunk exactly once to detect a multiplicity of object metadata.

11. A computing system comprising: at least one processor; and memory storing instructions executable by the at least one processor, wherein the instructions, when executed, cause the computing system to: obtain administrative access to a cloud environment account for bulk content scan of storage resources; and deploy serverless, containerized scanners to run locally on the cloud environment account, the serverless, containerized scanners configured to:

queue objects in the cloud environment account;

partition the objects into a plurality of object chunks;

depend upon a M number of object chunks in the plurality of object chunks, initializing a N number of instances of the serverless, containerized scanners, where M>>N; and

wherein each initialized serverless, containerized scanner scans a corresponding object chunk exactly once to detect a multiplicity of different data patterns;

wherein the M number of object chunks is at least one hundred times the N number of instances of the serverless, containerized scanners; wherein the different data patterns comprise different sensitive data patterns.

12. The computing system of claim 11 , wherein the M number of object chunks is at least one thousand times the N number of instances of the serverless, containerized scanners.

13. The computing system of claim 11 , wherein the serverless, containerized scanners are dynamically scalable.

14. The computing system of claim 11 , wherein each serverless, containerized scanner comprises a portable and independently executable microservice.

15. The computing system of claim 11 , wherein the different data patterns comprise different sensitive data patterns.

16. The computing system of claim 15 , wherein the different sensitive data patterns comprise a multiplicity of sensitive string patterns.

17. The computing system of claim 15 , wherein the serverless, containerized scanners are configured to generate sensitivity metadata based on detection of at least some sensitive data patterns in the multiplicity of sensitivity data patterns.

18. The computing system of claim 17 , wherein the serverless, containerized scanners are configured to send the sensitivity metadata to a metadata store in a control plane in the cloud environment account.

19. The computing system of claim 18 , wherein the instructions configure the computing system to:

apply sensitivity annotations to a cloud data attack surface graph based on the sensitivity metadata.

20. The computing system of claim 18 , wherein the instructions configure the computing system to:

apply sensitivity annotations to a cloud infrastructure graph based on the sensitivity metadata.

21. The computing system of claim 11 , wherein each initialized serverless, containerized scanner is configured to scan a corresponding object chunk exactly once to detect a multiplicity of object metadata.

22. A computer-implemented method of in-cloud, constant time content scanning, the method comprising:

obtaining administrative access to a cloud environment account for bulk content scanning of storage resources; and deploying serverless, containerized scanners to run locally on the cloud environment account, comprising:

queuing objects in the cloud environment account;

partitioning the objects into a plurality of object chunks; and

depending upon a M number of object chunks in the plurality of object chunks, initializing a N number of instances of the serverless, containerized scanners, wherein the M number of object chunks is at least one hundred times the N number of instances of the serverless, containerized scanners; and

wherein each initialized serverless, containerized scanner scans a corresponding object chunk exactly once to detect a multiplicity of sensitive string patterns;

wherein the different data patterns comprise different sensitive data patterns.

23. The computer-implemented method of claim 22 , wherein the serverless, containerized scanners generate sensitivity metadata based on detection of at least some sensitive data patterns in the multiplicity of sensitivity data patterns.

24. The computer-implemented method of claim 23 , wherein the serverless, containerized scanners send the sensitivity metadata to a metadata store in a control plane in the cloud environment account.

25. The computer-implemented method of claim 24 , and further comprising:

applying sensitivity annotations to a cloud data attack surface graph based on the sensitivity metadata.

26. The computer-implemented method of claim 25 , and further comprising:

applying sensitivity annotations to a cloud infrastructure graph based on the sensitivity metadata.

27. The computer-implemented method of claim 22 , wherein each initialized serverless, containerized scanner scans a corresponding object chunk exactly once to detect a multiplicity of object metadata.

Assignments (4)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2025
From: NORMALYZE, INC.
To: PROOFPOINT, INC.
Reel/Frame 071618/0634 →
SECURITY INTEREST Recorded Feb 19, 2025
From: NORMALYZE, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070254/0844 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2022
From: ITHAL, RAVISHANKAR GANESH; ZHANG, YANG; NEERALGI, KAPIL
To: NORMALYZE, INC.
Reel/Frame 062047/0453 →