IP Library Granted Patent US 12,401,580
Granted Patent B2
US 12,401,580 · App. 18/409,371 · Granted Aug 26, 2025

System and method for generation of unified graph models for network entities

Inventors: Daniel Hershko Shemesh (Givat-Shmuel, IL); Liran Moysi (Kfar Saba, IL); Roy Reznik (Tel Aviv, IL); Shai Keren (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L43/045G06F16/9024H04L43/08H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,580
App. No.
18/409,371
Granted
Aug 26, 2025
Kind
B2
Abstract

A system and method for generation of unified graph models for network entities are provided. The method includes collecting, for at least one network entity of a plurality of network entities, at least one network entity data feature, wherein the at least one network entity data feature is a network entity property; genericizing the collected at least one network entity; generating at least a network graph, wherein the generated network graph is a multi-dimensional data structure providing a representation of the plurality of network entities and relations between the network entities of the plurality of network entities; and storing the generated at least a network graph.

Claims (55)

1. A method performed by processing circuitry for generation of unified graph models for network entities, comprising:

collecting, by the processing circuitry, for a network entity of a plurality of network entities, a network entity data feature, the network entity data feature including a network entity property;

genericizing, by the processing circuitry, the network entity based on the collected network entity data feature to generate a generic network entity;

generating, by the processing circuitry, an imputed entity, wherein the imputed entity corresponds to and represents a functionality identified in a cloud platform, wherein the identified functionality is not executed by a network entity of the plurality of network entities;

generating, by the processing circuitry, a network graph based on the generic network entity and the imputed entity, wherein the generated network graph is a multi-dimensional data structure providing a representation of the plurality of network entities and relations between the network entities of the plurality of network entities; and

storing, by the processing circuitry, the generated network graph.

2. The method of claim 1 , wherein the network entity property relates to any one of: a network entity type, a network entity class, a network entity category, a network entity configuration, and any combination thereof.

3. The method of claim 1 , wherein genericizing the network entity further comprises:

generating a new generic network entity, wherein the new generic network entity includes a network entity property of the network entity.

4. The method of claim 1 , wherein genericizing the network entity further comprises:

converting the network entity into a new generic network entity, wherein the new generic network entity includes a network entity property of the network entity.

5. The method of claim 1 , wherein generating the imputed entity further comprises: identifying any one functionality of: a platform functionality, an environment functionality, and a combination thereof, wherein the identified functionality corresponds with a functionality of a generic network entity.

6. The method of claim 1 , wherein the generated network graph includes a unified representation of the plurality of network entities.

7. The method of claim 1 , wherein the generated network graph includes a unified representation of a plurality of environment layers.

8. The method of claim 1 , wherein the generated network graph includes a graph vertex, wherein the graph vertex represents any one of: a network entity, a generic entity, and an imputed entity.

9. The method of claim 8 , wherein the graph vertex includes a property label, wherein the property label includes a description of a property of the graph vertex.

10. The method of claim 8 , wherein the generated network graph includes a graph edge, wherein the graph edge is a connection between two graph vertices, and wherein the graph edge represents a relationship between two connected entities, wherein a connected entity is any one of: a network entity, a generic entity, and an imputed entity.

11. The method of claim 10 , wherein graph edge includes any one of: a property label, and a directionality indicator, wherein the property label includes a description of a property of the graph edge, and wherein the directionality indicator includes a description of a direction of the graph edge.

12. The method of claim 1 , further comprising:

generating a visualization of the generated network graph.

13. The method of claim 1 , wherein storing the generated network graph further comprises:

storing the generated network graph in a graph database.

14. The method of claim 1 , wherein a network entity of the plurality of network entities includes any one of: a private endpoint, a transit gateway, a tag-based ruleset, an entity configured to implement a tag-based ruleset, a container-management service, a container-management application, a third-party container, a third-party image, a web-access firewall, a firewall implementation, a multi-entity connection, a cross-entity connection, a container manager, a container manager connection, and any combination thereof.

15. A non-transitory computer-readable medium storing a set of instructions for generation of unified graph models for network entities, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a device, cause the device to:

collect, for a network entity of a plurality of network entities, a network entity data feature, the network entity data feature including a network entity property;

genericize the network entity based on the collected network entity data feature to generate a generic network entity;

generate an imputed entity, wherein the imputed entity corresponds to and represents a functionality identified in a cloud platform, wherein the identified functionality is not executed by a network entity of the plurality of network entities;

generate a network graph based on the generic network entity and the imputed entity, wherein the generated network graph is a multi-dimensional data structure providing a representation of the plurality of network entities and relations between the network entities of the plurality of network entities; and

store the generated network graph.

16. A system for generation of unified graph models for network entities comprising: a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to: collect, for a network entity of a plurality of network entities, a network entity data feature, the network entity data feature including a network entity property;

genericize the network entity based on the collected network entity data feature to generate a generic network entity;

generate an imputed entity, wherein the imputed entity corresponds to and represents a functionality identified in a cloud platform, wherein the identified functionality is not executed by a network entity of the plurality of network entities;

generate a network graph based on the generic network entity and the imputed entity, wherein the generated network graph is a multi-dimensional data structure providing a representation of the plurality of network entities and relations between the network entities of the plurality of network entities; and

store the generated network graph.

17. The system of claim 16 , wherein the network entity property relates to any one of:

a network entity type, a network entity class, a network entity category, a network entity configuration, and any combination thereof.

18. The system of claim 16 , wherein the memory contains further instructions that, when executed by the processing circuitry for genericizing the network entity, further configure the system to:

generate a new generic network entity, wherein the new generic network entity includes a network entity property of the network entity.

19. The system of claim 16 , wherein the memory contains further instructions that, when executed by the processing circuitry for genericizing the network entity, further configure the system to:

convert the network entity into a new generic network entity, wherein the new generic network entity includes a network entity property of the network entity.

20. The system of claim 16 , wherein the memory contains further instructions that, when executed by the processing circuitry for generating the imputed entity, further configure the system to: identify any one functionality of: a platform functionality, an environment functionality, and a combination thereof, wherein the identified functionality corresponds with a functionality of a generic network entity.

21. The system of claim 16 , wherein the generated network graph includes a unified representation of the plurality of network entities.

22. The system of claim 16 , wherein the generated network graph includes a unified representation of a plurality of environment layers.

23. The system of claim 16 , wherein the generated network graph includes a graph vertex, the graph vertex represents any one of:

a network entity, a generic entity, and an imputed entity.

24. The system of claim 23 , wherein the graph vertex includes a property label, the property label includes a description of a property of the graph vertex.

25. The system of claim 23 , wherein the generated network graph includes a graph edge, the graph edge is a connection between two graph vertices, and the graph edge represents a relationship between two connected entities, a connected entity is any one of:

a network entity, a generic entity, and an imputed entity.

26. The system of claim 25 , wherein graph edge includes any one of:

a property label, and a directionality indicator, wherein the property label includes a description of a property of the graph edge, and wherein the directionality indicator includes a description of a direction of the graph edge.

27. The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a visualization of the generated network graph.

28. The system of claim 16 , wherein the memory contains further instructions that, when executed by the processing circuitry for storing the generated network graph, further configure the system to:

store the generated network graph in a graph database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2024
From: SHEMESH, DANIEL HERSHKO; MOYSI, LIRAN; REZNIK, ROY; KEREN, SHAI
To: WIZ, INC.
Reel/Frame 066808/0942 →
Continuity (2)
Continuation 17161190 · Jan 28, 2021
Related Publication 20240163187A1 · May 16, 2024
References Cited (106)
US 5586254A · Kondo et al. · 1996 [cited by applicant]
US 5819028A · Manghirmalani et al. · 1998 [cited by applicant]
US 5926462A · Schenkel et al. · 1999 [cited by applicant]
US 9137110B1 · Adogla · 2015 [cited by examiner]
US 9800470B2 · Agarwal et al. · 2017 [cited by applicant]
US 9843485B2 · Desai · 2017 [cited by examiner]
US 10009251B1 · Koster et al. · 2018 [cited by applicant]
US 10326673B2 · Kulshreshtha et al. · 2019 [cited by applicant]
US 10447553B2 · Biran et al. · 2019 [cited by applicant]
US 10862928B1 · Badawy et al. · 2020 [cited by applicant]
US 10992543B1 · Rachamadugu · 2021 [cited by examiner]
US 11086709B1 · Ratkovic · 2021 [cited by examiner]
US 11159366B1 · Gawade et al. · 2021 [cited by applicant]
US 11175939B2 · Kumatagi et al. · 2021 [cited by applicant]
US 11863580B2 · Ross et al. · 2024 [cited by applicant]
US 20020147715A1 · Beyer · 2002 [cited by applicant]
US 20030101251A1 · Low · 2003 [cited by examiner]
US 20040210654A1 · Hrastar · 2004 [cited by applicant]
US 20070147269A1 · Ettle et al. · 2007 [cited by applicant]
US 20080312898A1 · Cleary · 2008 [cited by examiner]
US 20100223295A1 · Stanley et al. · 2010 [cited by applicant]
US 20100241698A1 · Hillerbrand · 2010 [cited by examiner]
US 20130219009A1 · Bheemarajaiah et al. · 2013 [cited by applicant]
US 20140130008A1 · Amulu · 2014 [cited by applicant]
US 20150200867A1 · Dutta · 2015 [cited by examiner]
US 20160019033A1 · Ebner et al. · 2016 [cited by applicant]
US 20160103706A1 · Novaes · 2016 [cited by examiner]
US 20160105350A1 · Greifeneder et al. · 2016 [cited by applicant]
US 20160219117A1 · Marlatt et al. · 2016 [cited by applicant]
US 20160352766A1 · Flacher et al. · 2016 [cited by applicant]
US 20170127427A1 · Claridge et al. · 2017 [cited by applicant]
US 20170140040A1 · Gottemukkala et al. · 2017 [cited by applicant]
US 20170279698A1 · Sartran · 2017 [cited by examiner]
US 20170310552A1 · Wallerstein · 2017 [cited by examiner]
US 20180024981A1 · Xia et al. · 2018 [cited by applicant]
US 20180063193A1 · Chandrashekhar et al. · 2018 [cited by applicant]
US 20180196685A1 · Dorr · 2018 [cited by examiner]
US 20180261001A1 · Wang et al. · 2018 [cited by applicant]
US 20190171474A1 · Malboubi · 2019 [cited by examiner]
US 20190190778A1 · Easterling et al. · 2019 [cited by applicant]
US 20190258756A1 · Minwalla et al. · 2019 [cited by applicant]
US 20190258973A1 · Prabhu et al. · 2019 [cited by applicant]
US 20190289038A1 · Li et al. · 2019 [cited by applicant]
US 20190391554A1 · Huang · 2019 [cited by examiner]
US 20200050689A1 · Tal et al. · 2020 [cited by applicant]
US 20200167642A1 · Dhurandhar et al. · 2020 [cited by applicant]
US 20200236038A1 · Liu et al. · 2020 [cited by applicant]
US 20200285977A1 · Brebner · 2020 [cited by applicant]
US 20200320130A1 · Korpman et al. · 2020 [cited by applicant]
US 20200322227A1 · Janakiraman · 2020 [cited by applicant]
US 20200336376A1 · Mahdi et al. · 2020 [cited by applicant]
US 20200364128A1 · Vittal · 2020 [cited by examiner]
US 20200366580A1 · Sinha · 2020 [cited by examiner]
US 20200366756A1 · Vittal · 2020 [cited by examiner]
US 20200366759A1 · Sinha · 2020 [cited by applicant]
US 20200382560A1 · Woolward et al. · 2020 [cited by applicant]
US 20200412754A1 · Crabtree · 2020 [cited by examiner]
US 20210149858A1 · Xia et al. · 2021 [cited by applicant]
US 20210158161A1 · Louizos · 2021 [cited by examiner]
US 20210168016A1 · Rao · 2021 [cited by examiner]
US 20210168116A1 · Shulman · 2021 [cited by examiner]
US 20210174280A1 · Ratnapuri · 2021 [cited by applicant]
US 20210327108A1 · Kumari · 2021 [cited by examiner]
US 20210342685A1 · Dhurandhar et al. · 2021 [cited by applicant]
“Nodes” Arizona.edu. Retrieved Jun. 19, 2025, from https://hpcdocs.hpc.arizona.edu/software/containers/what_are_co. [cited by applicant]
10 years of Kubernetes. (Jun. 6, 2024). Kubernetes. https://kubernetes.io/blog/2024/06/06/10-years-of-kubernetes/. [cited by applicant]
A brief history of containers. (n.d.). D2iq.com. Retrieved Jun. 19, 2025, from https://d2iq.com/blog/brief-history- containers. [cited by applicant]
Armbrust, Michael, et al. “Above the Clouds: A Berkeley View of Cloud Computing.” UC Berkeley Reliable Adaptive Distributed Systems Laboratory, Feb. 2009, pp. 1-23. [cited by applicant]
Beal, Vangie “Cloud Computing Explained,” published May 21, 2010, https://www.webopedia.com/reference/cloud-computing-guide/. Accessed Jun. 9, 2025. [cited by applicant]
Boesch, F. T. (1988). A Survey and Introduction To Network Reliability Theory. Stevens Institute of Technology . [cited by applicant]
Bollobas, B. (2000). Gradute Texts in Mathematics. [cited by applicant]
Computer Science Degree Program. (n.d.). Https://www.ohio.edu/˜ucat/97-98/colleges/comsci. [cited by applicant]
Container-bsaed Virtualization. Utah.edu. Retrieved Jun. 19, 2025, from https://www.chpc.utah.edu/documentation/software/containers.ph. [cited by applicant]
Containers on HPC—Nurc Rtd. (n.d.). Northeastern.edu. Retrieved Jun. 19, 2025, from https://rc-docs.northeastern.edu/en/latest/containers/index.html. [cited by applicant]
Datadog. “11 Facts about Real World Container Use.” Datadog, Nov. 17, 2020, https://www.datadoghq.com/container-report-2020/. [cited by applicant]
Datadog. “8 Surprising Facts about Real Docker Adoption.” Datadog, Jun. 13, 2018, https://www.datadoghq.com/docker-adoption/. [cited by applicant]
Deo, N. (1974). Graph Theory with Applications to Engineering and Computer Science. Dover Publications. [cited by applicant]
Discrete mathematics. (n.d.). Metro State University. Retrieved Jun. 18, 2025, from https://www.metrostate.edu/academics/courses/math-215. [cited by applicant]
Du, Ling Quan' Yuijan, and Leitao Guo. “Cloud Computing: An Overview.” Lecture Notes in Computer Science, vol. 5931, 2009, p. 626. [cited by applicant]
ECE 333: Introduction to Communication Networks Fall 2002. (n.d.). [cited by applicant]
Gross, J. L., Yellen, J., & Anderson, M. (2018). Graph Theory and Its Applications Third Edition. [cited by applicant]
Gruenberg, Austin. “The Introduction of Big Data in Cloud Computing.” Minnesota State University Moorhead. [cited by applicant]
Hayes, B. (Jan.-Feb. 2000). Graph Theory in Practice: Part I. American Scientist, the Magazine of Sigma Xi, the Scientific Research Society, 88(1), 9-13. [cited by applicant]
Horrigan, John B. “Use of Cloud Computing Applications and Services.” Pew Research Center, 12 Sep. 2008, https://www.pewresearch.org/internet/2008/09/12/use-of-cloud-computing-applications-and-services/. [cited by applicant]
https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication, 800-145.pdf, Sep. 2011. [cited by applicant]
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.500-291r2.pdf, Jul. 2013. [cited by applicant]
J. A. Bondy and U. S. R. Murty. (1976). Graph Theory with Applications. Department of Combinatorics and Optimization, University of Waterloo. [cited by applicant]
J.A. Bondy and U.S.R. Murty, Graph Theory, 2000. [cited by applicant]
Johnston, S. (Mar. 21, 2024). 11 years of Docker: Shaping the next decade of development. Docker. https://www.docker.com/blog/docker-11-year-anniversary/. [cited by applicant]
LaMonica, Martin. “Study: Cloud Computing to Brighten Future of Data Centers.” CNET, Mar. 11, 2008, https://www.cnet.com/culture/study-cloud-computing-to-brighten-future-of-data-centers/. [cited by applicant]
McQuillan, J. (n.d.). Graph Theory Applied To Optima L Connectivity in Computer Networks. Bolt Beranek and Newman Inc. [cited by applicant]
Mellinger, A. O., Nichols, W., & Palat, J. (n.d.). 11 leading practices when implementing a container strategy. SEI Blog. Retrieved Jun. 19, 2025, from https://insights.sei.cmu.edu/blog/11-leading-practices-when-impleme… [cited by applicant]
Microsoft Press. (2002). Microsoft computer dictionary. Microsoft Press. [cited by applicant]
[cited by applicant]
Postel, J. B., & Farber, D. (1976). Graph Modeling of computer communications protocols. https://escholarship.org/uc/item/2p87f03x. [cited by applicant]
Sadavare, A. B., & Kulkarni, R. V. (2012). A Review of Application of Graph Theory for Network. 3 (6). [cited by applicant]
Sakr, Majd F. “Introduction to Cloud Computing.” Cloud Computing I (intro), 15-319, spring 2010. Second lecture, Jan. 14, 2010. Carnegie Mellon. [cited by applicant]
Software containers—research computing documentation. (n.d.). Uab.edu. Retrieved Jun. 19, 2025, from https://docs.rc.uab.edu/workflow_solutions/getting_containers/. [cited by applicant]
Srikantaiah, Shekhar et al. “Energy Aware Consolidation for Cloud Computing” published Dec. 2008. https://www.microsoft.com/en-US/research/publication/energy-aware-consolidation-for-cloud-computing/. Accessed Jun. 9, 20… [cited by applicant]
Uhr, L. (1981). Compounding Denser (d,k) Graph Architectures for Computer Networks. [cited by applicant]
Undergraduate Catalog CSU (2000-2002). Csuohio.edu. Retrieved Jun. 19, 2025, from https://www.csuohio.edu/sites/default/files/ugradcatalog2000-2002.pdf. [cited by applicant]
Undergraduate Catalog. (1998-2000). The University of Texas-Pan American. [cited by applicant]
Velez, Jessica Garcia. “Cloud Computing Basics Explained.” Eastern Oregon University, Eastern Oregon University Online, Oct. 9, 2020, https://online.eou.edu/resources/article/understanding-cloud-computing-basics/. [cited by applicant]
Webster's New World Dictionary and Thesaurus Second Edition (2002). [cited by applicant]
What are Containers—UArizona HPC Documentation. (n.d.). Arizona.edu. Retrieved Jun. 19, 2025, from https://hpcdocs.hpc.arizona.edu/software/containers/what_are_containers/. [cited by applicant]
Zen and the Art of the Internet. Www.ou.edu. Retrieved Jun. 19, 2025, from https://www.ou.edu/research/electron/internet/zen-glos.htm. [cited by applicant]