IP Library Granted Patent US 12,126,695
Granted Patent B1
US 12,126,695 · App. 18/361,748 · Granted Oct 22, 2024

Enhancing security of a cloud deployment based on learnings from other cloud deployments

Inventors: Úlfar Erlingsson (Palo Alto, CA); Yijou Chen (Cupertino, CA)
Assignee: Fortinet, Inc.
H04L67/535G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L63/10H04L67/306G06F16/2456H04L41/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,126,695
App. No.
18/361,748
Granted
Oct 22, 2024
Kind
B1
Abstract

Learning from other cloud deployments to combat security threats, including: identifying, for at least a portion of a first cloud deployment, one or more additional cloud deployments to utilize for cross-customer learning; receiving information describing a security threat to one or more of the additional cloud deployments; receiving information describing configuration settings used to combat the security threat; and identifying, based on the information describing configuration settings used to combat the security threat, one or more configurations to adopt for the first cloud deployment.

Claims (40)

1. A method of learning from other cloud deployments to combat security threats, the method comprising:

identifying, for at least a portion of a first cloud deployment, one or more additional cloud deployments to utilize for cross-customer learning;

receiving information describing a security threat to one or more of the additional cloud deployments;

receiving information describing configuration settings used to combat the security threat; and

identifying, based on the information describing configuration settings used to combat the security threat, one or more configurations to adopt for the first cloud deployment.

2. The method of claim 1 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to blacklist one or more internet protocol (IP) addresses.

3. The method of claim 1 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to blacklist one or more network domains.

4. The method of claim 1 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to close a vulnerability that allowed an attack to succeed.

5. The method of claim 1 further comprising:

receiving information describing one or more actions associated with the additional cloud deployments; and

wherein identifying the one or more configurations to adopt for the first cloud deployment is further based on the one or more actions.

6. The method of claim 5 wherein:

receiving information describing one or more actions associated with the additional cloud deployments further comprises receiving information describing a detected vulnerability associated with one or more of the additional cloud deployments; and

receiving information describing configurations associated with the additional cloud deployments further comprises receiving information describing configuration settings used to address the vulnerability.

7. The method of claim 1 further comprising identifying abnormally configured components in the first cloud deployment.

8. The method of claim 1 further comprising receiving information describing one or more deployment processes associated with the additional cloud deployments.

9. A system for learning from other cloud deployments to combat security threats, the system comprising at least one processor and memory storing computer program instructions that, when executed, cause the system to carry out the steps of:

identifying, for at least a portion of a first cloud deployment, one or more additional cloud deployments to utilize for cross-customer learning;

receiving information describing a security threat to one or more of the additional cloud deployments;

receiving information describing configuration settings used to combat the security threat; and

identifying, based on the information describing configuration settings used to combat the security threat, one or more configurations to adopt for the first cloud deployment.

10. The system of claim 9 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to blacklist one or more internet protocol (IP) addresses.

11. The system of claim 9 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to blacklist one or more network domains.

12. The system of claim 9 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to close a vulnerability that allowed an attack to succeed.

13. The system of claim 9 , wherein the steps further comprise:

receiving information describing one or more actions associated with the additional cloud deployments; and

wherein identifying the one or more configurations to adopt for the first cloud deployment is further based on the one or more actions.

14. The system of claim 13 wherein:

receiving information describing one or more actions associated with the additional cloud deployments further comprises receiving information describing a detected vulnerability associated with one or more of the additional cloud deployments; and

receiving information describing configurations associated with the additional cloud deployments further comprises receiving information describing configuration settings used to address the vulnerability.

15. The system of claim 9 wherein the steps further comprise identifying abnormally configured components in the first cloud deployment.

16. The system of claim 9 wherein the steps further comprise receiving information describing one or more deployment processes associated with the additional cloud deployments.

17. A computer program product for learning from other cloud deployments to combat security threats, the computer program product disposed on a non-transitory computer readable medium, the computer program product including computer program instructions that, when executed, carry out the steps of:

identifying, for at least a portion of a first cloud deployment, one or more additional cloud deployments to utilize for cross-customer learning;

receiving information describing a security threat to one or more of the additional cloud deployments;

receiving information describing configuration settings used to combat the security threat; and

identifying, based on the information describing configuration settings used to combat the security threat, one or more configurations to adopt for the first cloud deployment.

18. The computer program product of claim 17 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to blacklist one or more internet protocol (IP) addresses.

19. The computer program product of claim 17 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to blacklist one or more network domains.

20. The computer program product of claim 17 , wherein the configuration settings comprise configuration settings that caused the one or more of the additional cloud deployments to close a vulnerability that allowed an attack to succeed.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069301/0123 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: ERLINGSSON, ÚLFAR; CHEN, YIJOU
To: LACEWORK, INC.
Reel/Frame 064447/0823 →