IP Library Granted Patent US 12,470,586
Granted Patent B2
US 12,470,586 · App. 18/161,647 · Granted Nov 11, 2025

System and method for risk monitoring of cloud based computing environments

Inventors: Ami Luttwak (Binyamina, IL); Yinon Costica (Tel Aviv, IL); Roy Reznik (Tel Aviv, IL); Raaz Herzberg (Tel Aviv, IL); Alon Schindel (Tel Aviv, IL); Guy Rozendorn (Tel Aviv, IL); Avihai Berkovitz (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L63/1433G06F16/9024H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,586
App. No.
18/161,647
Granted
Nov 11, 2025
Kind
B2
Abstract

A system and method for generating a contextual cloud risk assessment of a cloud computing environment. The method includes accessing a plurality of cloud assessment policies, wherein a policy including a query executable on a security graph; applying the plurality of cloud assessment policies to the representation of the first cloud computing environment; generating a risk assessment report based on an output generated by applying a policy of the plurality of cloud assessment polices; and initiating a mitigation action based on a cybersecurity risk from the risk assessment report.

Claims (51)

1 . A method for generating a contextual cloud risk assessment of a cloud computing environment, comprising:

accessing a plurality of cloud assessment policies, wherein each cloud assessment policy of the plurality of cloud assessment policies includes a query executable on a security graph;

applying the plurality of cloud assessment policies on the security graph, wherein the security graph is a representation of a first cloud computing environment;

generating a risk assessment report based on an output generated by applying, on the security graph, a cloud assessment policy of the plurality of cloud assessment polices; and

initiating a mitigation action based on a cybersecurity risk from the risk assessment report.

2 . The method of claim 1 , further comprising:

applying the plurality of cloud assessment policies to a representation of a second cloud computing environment, wherein the second cloud computing environment is deployed on an infrastructure which is distinct from an infrastructure on which the first cloud computing environment is deployed, wherein the security graph includes a representation of a first cloud computing environment.

3 . The method of claim 2 , further comprising:

initiating a first mitigation action in the first cloud computing environment; and

initiating a second mitigation action in the second cloud computing environment.

4 . The method of claim 1 , further comprising:

accessing a policy from a policy engine of the first cloud computing environment, the policy including a condition and a value; and

generating a query corresponding to the policy, the query including the condition and the value.

5 . The method of claim 1 , further comprising:

generating a severity index for the cybersecurity risk identified in the risk assessment report.

6 . The method of claim 5 , wherein initiating the mitigation action further comprises:

initiating the mitigation action further based on the severity index.

7 . The method of claim 5 , wherein the severity index is generated further based on a received severity score corresponding to the cybersecurity risk.

8 . The method of claim 1 , further comprising:

initiating an inspection for a cybersecurity object on a resource in the first cloud computing environment in response to determining that an identifier of the resource is included in the risk assessment report.

9 . The method of claim 1 , wherein the query includes any one of: public exposure detection, vulnerability detection, database exposure, code vulnerability, endpoint detection, malware detection, misconfiguration detection, a lateral movement detection, an exposed secret detection, and a combination thereof.

10 . The method of claim 1 , wherein the mitigation action includes any one of: initiating installation of a software patch, revoking access to a network, revoking access to a resource, modifying a permission of a principal, and a combination thereof.

11 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

accessing a plurality of cloud assessment policies, wherein each cloud assessment policy of the plurality of cloud assessment policies includes a query executable on a security graph;

applying the plurality of cloud assessment policies on the security graph, wherein the security graph is a representation of a first cloud computing environment;

generating a risk assessment report based on an output generated by applying, on the security graph, a cloud assessment policy of the plurality of cloud assessment polices; and

initiating a mitigation action based on a cybersecurity risk from the risk assessment report.

12 . A system for generating a contextual cloud risk assessment of a cloud computing environment, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

access a plurality of cloud assessment policies, wherein each cloud assessment policy of the plurality of cloud assessment policies includes a query executable on a security graph;

apply the plurality of cloud assessment policies on the security graph, wherein the security is a representation of a first cloud computing environment;

generate a risk assessment report based on an output generated by applying, on the security graph, a cloud assessment policy of the plurality of cloud assessment polices; and

initiate a mitigation action based on a cybersecurity risk from the risk assessment report.

13 . The system of claim 12 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configures the system to:

apply the plurality of cloud assessment policies to a representation of a second cloud computing environment, wherein the second cloud computing environment is deployed on an infrastructure which is distinct from an infrastructure on which the first cloud computing environment is deployed, wherein the security graph includes a representation of a first cloud computing environment.

14 . The system of claim 13 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configures the system to:

initiate a first mitigation action in the first cloud computing environment; and

initiate a second mitigation action in the second cloud computing environment.

15 . The system of claim 12 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configures the system to:

access a policy from a policy engine of the first cloud computing environment, the policy including a condition and a value; and

generate a query corresponding to the policy, the query including the condition and the value.

16 . The system of claim 12 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configures the system to:

generate a severity index for a cybersecurity risk identified in the risk assessment report.

17 . The system of claim 16 , wherein the memory contains further instructions which, when executed by the processing circuitry to initiate the mitigation action, further configures the system to:

initiate the mitigation action further based on the severity index.

18 . The system of claim 16 , wherein the severity index is generated further based on a received severity score corresponding to the cybersecurity risk.

19 . The system of claim 12 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configures the system to:

initiate an inspection for a cybersecurity object on a resource in the first cloud computing environment in response to determining that an identifier of the resource is included in the risk assessment report.

20 . The system of claim 12 , wherein the query includes any one of: public exposure detection, vulnerability detection, database exposure, code vulnerability, endpoint detection, malware detection, misconfiguration detection, a lateral movement detection, an exposed secret detection, and a combination thereof.

21 . The system of claim 12 , wherein the mitigation action includes any one of: initiating installation of a software patch, revoking access to a network, revoking access to a resource, modifying a permission of a principal, and a combination thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2023
From: LUTTWAK, AMI; COSTICA, YINON; REZNIK, ROY; HERZBERG, RAAZ; SCHINDEL, ALON; ROZENDORN, GUY; BERKOVITZ, AVIHAI
To: WIZ, INC.
Reel/Frame 063227/0016 →
Continuity (2)
Provisional Application 63267366 · Jan 31, 2022
Related Publication 20230247044A1 · Aug 3, 2023
References Cited (12)
US 7072893B1 · Rehfeld · 2006 [cited by examiner]
US 8468244B2 · Redlich et al. · 2013 [cited by applicant]
US 10917439B2 · Purathepparambil et al. · 2021 [cited by applicant]
US 11880477B2 · Marshall · 2024 [cited by examiner]
US 20160026776A1 · Hurst · 2016 [cited by examiner]
US 20160344772A1 · Monahan · 2016 [cited by examiner]
US 20170295197A1 · Parimi · 2017 [cited by examiner]
US 20180295154A1 · Crabtree et al. · 2018 [cited by applicant]
US 20200382557A1 · Woolward · 2020 [cited by examiner]
US 20200396218A1 · Crabtree et al. · 2020 [cited by applicant]
US 20220231984A1 · Wolfe · 2022 [cited by examiner]
US 20250192954A1 · Gao · 2025 [cited by examiner]