IP Library › Granted Patent US 12,381,939
Granted Patent B2
US 12,381,939 · App. 18/341,134 · Granted Aug 5, 2025

System and method for analyzing network objects in a cloud environment

Inventors: Shai Keren (Tel Aviv, IL); Daniel Hershko Shemesh (Givat Shmuel, IL); Roy Reznik (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Avihai Berkovitz (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L67/10H04L41/046H04L41/5096H04L49/70H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,939
App. No.
18/341,134
Filed
Jun 26, 2023
Granted
Aug 5, 2025
Kind
B2
Art Unit
2447
USPC
709/223
Abstract

A method and system for providing textual insights on objects deployed in a cloud environment are provided. The method includes collecting object data on objects deployed in the cloud environment, wherein objects are deployed and operable at different layers of the cloud environment; identifying objects deployed in the cloud environment; constructing a visual representation of the cloud environment, including the identified objects and their relationships; and generating textual insights on the identified objects and their relationships using natural language processing.

Claims (46)

1. A computer-implemented method for providing textual insights on objects deployed in a cloud environment, comprising:

collecting object data on objects deployed in the cloud environment, wherein objects are deployed and operable at different layers of the cloud environment;

identifying objects deployed in the cloud environment;

constructing a visual representation of the cloud environment, including the identified objects and relationships between the identified objects;

generating textual insights using natural language processing based on the identified objects and the relationships; and

tagging the identified objects and respective relationships with the generated textual insights.

2. The method of claim 1 , wherein the generated textual insights further include: pure-text descriptions of objects and relationships.

3. The method of claim 1 , wherein the generated textual insights further include: multiple-step relationships.

4. The method of claim 1 , wherein the generated textual insights further include: information on anomaly detection of a relationship.

5. The method of claim 1 , wherein the generated textual insights include a network that is not detectable based on an analysis of individual objects.

6. The method of claim 1 , wherein the cloud environment includes a plurality of different cloud computing platforms.

7. The method of claim 1 , further comprising:

determining relationships between the identified objects.

8. The method of claim 7 , wherein determining the relationships between the identified objects further comprises:

determining the relationships using any one of: an observational method, a static analysis method, and an active logging method.

9. The method of claim 1 , wherein each of the objects includes any one of: a virtual network, a firewall, a network interface card, a proxy, a gateway, a software container, a container, a management object, a virtual machine, a subnet, a hub, a virtual private network (VPN).

10. The method of claim 1 , wherein using the natural language processing further comprises: applying a large language model to generate the textual insights.

11. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

collecting object data on objects deployed in a cloud environment, wherein objects are deployed and operable at different layers of the cloud environment;

identifying objects deployed in the cloud environment;

constructing a visual representation of the cloud environment, including the identified objects and relationships between the identified objects;

generating textual insights using natural language processing based on the identified objects and the relationships; and

tagging the identified objects and respective relationships with the generated textual insights.

12. A system for providing textual insights on objects deployed in a cloud environment comprising:

one or more processing circuitries configured to:

collect object data on objects deployed in the cloud environment, wherein objects are deployed and operable at different layers of the cloud environment;

identify objects deployed in the cloud environment;

construct a visual representation of the cloud environment, including the identified objects and relationships between the identified object;

generate textual insights using natural language processing based on the identified objects and the relationships; and

tag the identified objects and respective relationships with the generated textual insights.

13. The system of claim 12 , wherein the generated textual insights further include:

pure-text descriptions of objects and relationships.

14. The system of claim 12 , wherein the generated textual insights further include:

multiple-step relationships.

15. The system of claim 12 , wherein the generated textual insights further include:

information on anomaly detection of a relationship.

16. The system of claim 12 , wherein the generated textual insights include a network which may not be detectable based on an analysis of individual objects.

17. The system of claim 12 , wherein the cloud environment includes a plurality of different cloud computing platforms.

18. The system of claim 12 , wherein the one or more processing circuitries are further configured to:

determine relationships between the identified objects.

19. The system of claim 18 , wherein the system, when determining the relationships between the identified objects, is configured to:

determine the relationships using any one of: an observational method, a static analysis method, and an active log method.

20. The system of claim 12 , wherein each of the objects includes any one of:

a virtual network, a firewall, a network interface card, a proxy, a gateway, a software container, a container, a management object, a virtual machine, a subnet, a hub, a virtual private network (VPN).

21. The system of claim 12 , wherein the system, when using the natural language processing, are configured to:

apply a large language model to generate the textual insights.

Continuity (3)
Continuation 17819442 · Aug 12, 2022
Continuation 17109883 · Dec 2, 2020
Related Publication 20230344896A1 · Oct 26, 2023
References Cited (37)
US 7392539B2 · Brooks · 2008 [cited by examiner]
US 8650299B1 · Huang et al. · 2014 [cited by applicant]
US 9210185B1 · Pinney Wood et al. · 2015 [cited by applicant]
US 10171300B2 · Eggen · 2019 [cited by examiner]
US 10693743B2 · Zhong et al. · 2020 [cited by applicant]
US 10924347B1 · Narsian · 2021 [cited by examiner]
US 10977587B2 · Khalili · 2021 [cited by applicant]
US 11146581B2 · Lotem et al. · 2021 [cited by applicant]
US 11709944B2 · Salj · 2023 [cited by applicant]
US 11770387B1 · Shivamoggi et al. · 2023 [cited by applicant]
US 20040019803A1 · Jahn · 2004 [cited by applicant]
US 20140157417A1 · Grubel · 2014 [cited by examiner]
US 20160044057A1 · Chenette et al. · 2016 [cited by applicant]
US 20160048556A1 · Kelly · 2016 [cited by examiner]
US 20160359872A1 · Yadav et al. · 2016 [cited by applicant]
US 20160373944A1 · Jain · 2016 [cited by examiner]
US 20170006119A1 · Pogrebinsky et al. · 2017 [cited by applicant]
US 20170075981A1 · Carlsson · 2017 [cited by examiner]
US 20180024981A1 · Xia · 2018 [cited by examiner]
US 20190095530A1 · Booker · 2019 [cited by examiner]
US 20200089518A1 · Beyer et al. · 2020 [cited by applicant]
US 20200252461A1 · Xu · 2020 [cited by examiner]
US 20200267175A1 · Atighetchi et al. · 2020 [cited by applicant]
US 20200322227A1 · Janakiraman · 2020 [cited by examiner]
US 20200374343A1 · Novotny · 2020 [cited by examiner]
US 20200382539A1 · Janakiraman · 2020 [cited by examiner]
US 20200382560A1 · Woolward et al. · 2020 [cited by applicant]
US 20210208993A1 · Moyal · 2021 [cited by examiner]
US 20220019186A1 · De Andrade · 2022 [cited by examiner]
US 20220383865A1 · McDermid · 2022 [cited by examiner]
US 20230008765A1 · Kazato · 2023 [cited by applicant]
Amazon AWS vs Microsoft Azure: A zero-sum game? (n.d.). Armadalabs.com. Retrieved Jun. 19, 2025, from https://www.armadalabs.com/blog/amazon-aws-vs-microsoft-azure-a-zero-sum-game. [cited by applicant]
Easley, D., L.L., Davie, B.S. “Networks, Crowds, and Markets: Reasoning about a Highly Connected World.” (2010) Chapter 2. [cited by applicant]
Merriam-Webster's Collegiate Dictionary Tenth Edition (1998). [cited by applicant]
[cited by applicant]
Peterson, L.L., Davie, B.S. “Computer Networks: A Systems Approach.” Fifth Edition. (2012) pp. 1-69. (“Computer Networks—A Systems Approach”). [cited by applicant]
Zimba, A., Chama, V., “Cyber Attacks in Cloud Computing: Modelling Multi-stage Attacks using Probability Density Curves.” I. J. Computer Network and Information Security, 2018, 3, 25-36. [cited by applicant]