IP Library Patent Application 18162412
Patent Application
App. No. 18/162,412

TECHNIQUES FOR CLOUD DETECTION AND RESPONSE FROM CLOUD LOGS UTILIZING A SECURITY GRAPH

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/162,412
Abstract

A system and method for detecting a cloud detection and response (CDR) event from a cloud log. The method includes detecting an identifier of a cloud entity in a cloud log, wherein the cloud log includes a plurality of records generated by a cloud computing environment; detecting a node in a security graph based on the identifier of the cloud entity, wherein the security graph includes a representation of the cloud computing environment; generating a CDR event in response to determining from the security graph that the first node is associated with a cybersecurity threat; and initiating a mitigation action based on the cybersecurity threat.

Claims (55)

1 . A method for detecting a cloud detection and response (CDR) event from a cloud log, comprising:

detecting an identifier of a cloud entity in a cloud log, wherein the cloud log includes a plurality of records generated by a cloud computing environment;

detecting a node in a security graph based on the identifier of the cloud entity, wherein the security graph includes a representation of the cloud computing environment;

generating a CDR event in response to determining from the security graph that the first node is associated with a cybersecurity threat; and

initiating a mitigation action based on the cybersecurity threat.

2 . The method of claim 1 , further comprising:

detecting the identifier of the cloud entity in a record of the cloud log;

detecting the identifier of the cloud entity in a record of a second cloud log; and

generating the CDR event in response to determining that the record of the cloud log and the record of the second log indicate together a cybersecurity threat.

3 . The method of claim 1 , further comprising:

parsing each record of the plurality of records to detect a predetermined data field; and

detecting the identifier of the cloud entity based on a value of the predetermined data field.

4 . The method of claim 1 , further comprising:

applying a policy to the cloud entity, wherein the policy includes a conditional rule.

5 . The method of claim 4 , further comprising:

generating the CDR event further in response to determining that the cloud entity is in violation of the applied policy.

6 . The method of claim 1 , further comprising:

generating a query based on an attribute of the cloud entity; and

executing the query on the security graph.

7 . The method of claim 6 , further comprising:

detecting a node representing the cybersecurity threat, wherein the node representing the cybersecurity threat is connected to a node representing the cloud entity.

8 . The method of claim 7 , wherein the cybersecurity threat is any one of: a vulnerability, a misconfiguration, a public exposure detection, a vulnerability detection, a database exposure, a code vulnerability, an endpoint detection, a malware detection, a misconfiguration detection, a lateral movement detection, an exposed secret, and any combination thereof.

9 . The method of claim 1 , further comprising:

initiating the mitigation action to include any one of: revoking network access to a resource, revoking network access from a resource, modifying a permission of a principal, generating a ticket corresponding to the alert in a ticketing system, initiating an instruction to update a software on a resource, and a combination thereof.

10 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

detecting an identifier of a cloud entity in a cloud log, wherein the cloud log includes a plurality of records generated by a cloud computing environment;

detecting a node in a security graph based on the identifier of the cloud entity, wherein the security graph includes a representation of the cloud computing environment;

generating a CDR event in response to determining from the security graph that the first node is associated with a cybersecurity threat; and

initiating a mitigation action based on the cybersecurity threat.

11 . A system for detecting a cloud detection and response (CDR) event from a cloud log, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect an identifier of a cloud entity in a cloud log, wherein the cloud log includes a plurality of records generated by a cloud computing environment;

detect a node in a security graph based on the identifier of the cloud entity, wherein the security graph includes a representation of the cloud computing environment;

generate a CDR event in response to determining from the security graph that the first node is associated with a cybersecurity threat; and

initiate a mitigation action based on the cybersecurity threat.

12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the identifier of the cloud entity in a record of the cloud log;

detect the identifier of the cloud entity in a record of a second cloud log; and

generate the CDR event in response to determining that the record of the cloud log and the record of the second log indicate together a cybersecurity threat.

13 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

parse each record of the plurality of records to detect a predetermined data field; and

detect the identifier of the cloud entity based on a value of the predetermined data field.

14 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply a policy to the cloud entity, wherein the policy includes a conditional rule.

15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the CDR event further in response to determining that the cloud entity is in violation of the applied policy.

16 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a query based on an attribute of the cloud entity; and

execute the query on the security graph.

17 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a node representing the cybersecurity threat, wherein the node representing the cybersecurity threat is connected to a node representing the cloud entity.

18 . The system of claim 17 , wherein the cybersecurity threat is any one of: a vulnerability, a misconfiguration, a public exposure detection, a vulnerability detection, a database exposure, a code vulnerability, an endpoint detection, a malware detection, a misconfiguration detection, a lateral movement detection, an exposed secret, and any combination thereof.

19 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate the mitigation action to include any one of: revoking network access to a resource, revoking network access from a resource, modifying a permission of a principal, generating a ticket corresponding to the alert in a ticketing system, initiating an instruction to update a software on a resource, and a combination thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2023
From: LUTTWAK, AMI; COSTICA, YINON; REZNIK, ROY; PISHA, GEORGE; MOYSI, LIRAN; SCHINDEL, ALON
To: WIZ, INC.
Reel/Frame 063226/0986 →