IP Library Granted Patent US 12,438,902
Granted Patent B2
US 12,438,902 · App. 18/488,808 · Granted Oct 7, 2025

Event-driven monitoring of resources in a cloud computing environment

Inventors: Dylan Martin (Belfast, GB); Austin Lee (Pasadena, CA); Trever Allen McKee (Shafter, CA); James Andrew Green (Hidden Hills, CA); Chris DeRamus (Ashburn, VA)
Assignee: Rapid7, Inc.
H04L63/1433G06F21/554H04L47/82G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,902
App. No.
18/488,808
Granted
Oct 7, 2025
Kind
B2
Abstract

Techniques for event driven harvesting and analysis of cloud computing resources in a cloud computing environment, comprising: obtaining, from a cloud computing environment, data related to an event that occurred in the cloud computing environment; in response to obtaining the data, requesting, from the cloud computing environment, supplemental data about the event that occurred in the cloud computing environment, the supplemental data including information about the event and/or information about impact of the event on a resource; determining whether a security action is to be taken at least in part by analyzing the data and/or the supplemental data; and when it is determined a security action is to be taken, performing the security action.

Claims (83)

1. A method for event driven harvesting of data in one or more cloud computing environments, the method comprising:

using at least one computer hardware processor to perform:

obtaining, from a first cloud computing environment, first data related to a first event that occurred in the first cloud computing environment, the first event relating to a first resource in the first cloud computing environment, the first data including a first identifier for the first event;

in response to obtaining the first data,

requesting, from an application programming interface (API) of the first cloud computing environment and using the first identifier, first supplemental data about the first event, the first supplemental data including supplemental information about the first event and/or information about impact of the first event on the first resource;

determining whether a security action is to be taken at least in part by analyzing the first data and/or the first supplemental data; and

when it is determined a security action is to be taken, performing the security action.

2. The method of claim 1 , further comprising:

obtaining, from a second cloud computing environment, different from the first cloud computing environment, second data related to a second event that occurred in the second cloud computing environment, the second event relating to a second resource in the second cloud computing environment, the second data including a second identifier for the second event;

in response to obtaining the second data,

requesting, from an application programming interface (API) of the second cloud computing environment and using the second identifier, second supplemental data about the second event, the second supplemental data including supplemental information about the second event and/or information about impact of the second event on the second resource;

determining whether a second security action is to be taken at least in by analyzing the second data and/or the second supplemental data; and

when it is determined a second security action is to be taken, performing the security action.

3. The method of claim 2 , further comprising:

after obtaining the first data and the first supplemental data,

generating a first data structure; and

storing the first data and the first supplemental data in the first data structure; and

after obtaining the second data and the second supplemental data,

generating a second data structure; and

storing the second data and the second supplemental data in the second data structure,

wherein the first data structure and the second data structure are a same type of data structure.

4. The method of claim 1 , further comprising:

in response to obtaining the first data, determining whether the first supplemental data is to be requested; and

in response to determining the first supplemental data is to be requested:

generating a first data structure having a field indicating the first supplemental data is to be requested;

storing the first data in the first data structure; and

requesting the first supplemental data.

5. The method of claim 4 , further comprising:

before the requesting, storing a job associated with the first data structure in a queue, the queue storing jobs to be performed including scheduled data collections; and

prioritizing the job associated with the first data structure within the queue to be addressed before the scheduled data collections, in response to determining the first supplemental data is to be requested.

6. The method of claim 1 , wherein information about the impact of the first event on the first resource comprises information about changes to an amount of storage associated with the first resource and information about changes to metadata associated with the first resource, and wherein information about changes to metadata associated with the first resource comprises information about changes to a structure of data within the first resource, changes to software installed on the first resource, changes to permissions for accessing the first resource, and/or changes to security rules relating to the first resource.

7. The method of claim 1 , wherein performing the security action comprises performing at least one of: updating software installed in the first resource, changing a network configuration of the first resource, changing a configuration of one or more software applications executing on the first resource, changing a configuration of an operating system executing on the first resource, changing one or more permissions for the first resource, deleting malware from the first resource, removing corrupted files or data from the first resource, taking the first resource offline, killing an instance of the first resource, and/or blocking communications to and/or from the first resource.

8. The method of claim 1 , wherein analyzing the first data and the first supplemental data comprises identifying presence of one or more software bugs, one or more out-of-date software applications, one or more unpatched software applications, corrupted data, unencrypted data, one or more improper access permissions for the first resource, one or more misconfigurations, one or more computer viruses, and/or malware within the first data and the first supplemental data.

9. The method of claim 1 , wherein the first data is obtained from a queue managed within the first cloud computing environment, and the first data is pushed to the queue from a log of the first cloud computing environment.

10. The method of claim 1 , wherein the first data is obtained from an event subscription, and the requesting comprises requesting the first supplemental data from a resource API associated with the first cloud computing environment by querying the resource API for information associated with the first resource and collecting information related to the impact of the first event on the first resource.

11. The method of claim 1 , wherein the first data and/or the supplemental data includes an event type of the first event; and

further comprising:

in response to determining, based on the event type, the first event is associated with allocation of storage to the first resource, taking a snapshot of storage attached to the first resource.

12. The method of claim 11 , wherein the first cloud computing environment is an AWS cloud computing environment, and taking the snapshot is performed in response to determining the first event is an Attach Volume event type.

13. A system for event-driven harvesting of data in one or more cloud computing environments, the system comprising:

at least one computer hardware processor; and

at least one non-transitory computer-readable storage medium storing processor-executable instructions that, when executed by the at least one computer hardware processor, cause the at least one computer hardware processor to perform a method comprising:

obtaining, from a first cloud computing environment, first data related to a first event that occurred in the first cloud computing environment, the first event relating to a first resource in the first cloud computing environment, the first data including a first identifier for the first event;

in response to obtaining the first data,

requesting, from an application programming interface (API) of the first cloud computing environment and using the first identifier, first supplemental data about the first event, the first supplemental data including supplemental information about the first event and/or information about impact of the first event on the first resource;

determining whether a security action is to be taken at least in part by analyzing the first data and/or the first supplemental data; and

when it is determined a security action is to be taken, performing the security action.

14. The system of claim 13 , wherein the method further comprises:

obtaining, from a second cloud computing environment, different from the first cloud computing environment, second data related to a second event that occurred in the second cloud computing environment, the second event relating to a second resource in the second cloud computing environment, the second data including a second identifier for the second event;

in response to obtaining the second data,

requesting, from an application programming interface (API) of the second cloud computing environment and using the second identifier, second supplemental data about the second event, the second supplemental data including supplemental information about the second event and/or information about impact of the second event on the second resource;

determining whether a second security action is to be taken at least in by analyzing the second data and/or the second supplemental data; and

when it is determined a second security action is to be taken, performing the security action.

15. The system of claim 14 , wherein the method further comprises:

after obtaining the first data and the first supplemental data,

generating a first data structure; and

storing the first data and the first supplemental data in the first data structure; and

after obtaining the second data and the second supplemental data,

generating a second data structure; and

storing the second data and the second supplemental data in the second data structure,

wherein the first data structure and the second data structure are a same type of data structure.

16. The system of claim 13 , wherein information about the impact of the first event on the first resource comprises information about changes to an amount of storage associated with the first resource and information about changes to metadata associated with the first resource, and wherein information about changes to metadata associated with the first resource comprises information about changes to a structure of data within the first resource, changes to software installed on the first resource, changes to permissions for accessing the first resource, and/or changes to security rules relating to the first resource.

17. At least one non-transitory computer-readable storage medium storing processor-executable instructions that, when executed by at least one computer hardware processor, cause the at least one computer hardware processor to perform a method comprising:

obtaining, from a first cloud computing environment, first data related to a first event that occurred in the first cloud computing environment, the first event relating to a first resource in the first cloud computing environment, the first data including a first identifier for the first event;

in response to obtaining the first data,

requesting, from an application programming interface (API) of the first cloud computing environment and using the first identifier, first supplemental data about the first event, the first supplemental data including supplemental information about the first event and/or information about impact of the first event on the first resource;

determining whether a security action is to be taken at least in part by analyzing the first data and/or the first supplemental data; and

when it is determined a security action is to be taken, performing the security action.

18. The at least one non-transitory computer-readable storage medium of claim 17 , wherein the method further comprises:

obtaining, from a second cloud computing environment, different from the first cloud computing environment, second data related to a second event that occurred in the second cloud computing environment, the second event relating to a second resource in the second cloud computing environment, the second data including a second identifier for the second event;

in response to obtaining the second data,

requesting, from an application programming interface (API) of the second cloud computing environment and using the second identifier, second supplemental data about the second event, the second supplemental data including supplemental information about the second event and/or information about impact of the second event on the second resource;

determining whether a second security action is to be taken at least in by analyzing the second data and/or the second supplemental data; and

when it is determined a second security action is to be taken, performing the security action.

19. The at least one non-transitory computer-readable storage medium of claim 18 , wherein the method further comprises:

after obtaining the first data and the first supplemental data,

generating a first data structure; and

storing the first data and the first supplemental data in the first data structure; and

after obtaining the second data and the second supplemental data,

generating a second data structure; and

storing the second data and the second supplemental data in the second data structure,

wherein the first data structure and the second data structure are a same type of data structure.

20. The at least one non-transitory computer-readable storage medium of claim 17 , wherein information about the impact of the first event on the first resource comprises information about changes to an amount of storage associated with the first resource and information about changes to metadata associated with the first resource, and wherein information about changes to metadata associated with the first resource comprises information about changes to a structure of data within the first resource, changes to software installed on the first resource, changes to permissions for accessing the first resource, and/or changes to security rules relating to the first resource.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2025
From: LEE, AUSTIN; MCKEE, TREVER ALLEN; GREEN, JAMES ANDREW; DERAMUS, CHRIS
To: RAPID7, INC.
Reel/Frame 071980/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2025
From: MARTIN, DYLAN
To: RAPID7 INTERNATIONAL LIMITED
Reel/Frame 071949/0163 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2025
From: RAPID7 INTERNATIONAL LIMITED
To: RAPID7, INC.
Reel/Frame 071949/0165 →
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
Continuity (3)
Provisional Application 63460576 · Apr 19, 2023
Provisional Application 63423890 · Nov 9, 2022
Related Publication 20240152609A1 · May 9, 2024
References Cited (23)
US 7409719B2 · Armstrong et al. · 2008 [cited by applicant]
US 9917854B2 · Natanzon et al. · 2018 [cited by applicant]
US 10536471B1 · Derbeko et al. · 2020 [cited by applicant]
US 11431735B2 · Shua · 2022 [cited by applicant]
US 11663031B2 · Shua · 2023 [cited by applicant]
US 20130067582A1 · Donovan · 2013 [cited by examiner]
US 20130247185A1 · Viscuso et al. · 2013 [cited by applicant]
US 20170364412A1 · Tsirkin · 2017 [cited by applicant]
US 20210012000A1 · Halcrow et al. · 2021 [cited by applicant]
US 20210099478A1 · Seetharamaiah · 2021 [cited by examiner]
US 20220279012A1 · Seetharamaiah · 2022 [cited by examiner]
US 20220345480A1 · Shua · 2022 [cited by examiner]
US 20230239296A1 · Shachar et al. · 2023 [cited by applicant]
US 20240154992A1 · Martin et al. · 2024 [cited by applicant]
Hirwani et al., Forensic acquisition and analysis of vmware virtual hard disks. SAM'12 The 2012 International Conference on Security and Management. Jul. 2012. 8 pages. [cited by applicant]
Joseph et al., Detection of malware attacks on virtual machines for a self-heal approach in cloud computing using VM snapshots. Journal of Communications Software and Systems. Sep. 1, 2018;14(3):249-57. [cited by applicant]
Nicolae et al., BlobCR: Efficient checkpoint-restart for HPC applications on IaaS clouds using virtual disk image snapshots. SC'11: Proceedings of 2011 International Conference for High Performance Computing, Networking… [cited by applicant]
Rani et al., An efficient approach to forensic investigation in cloud using VM snapshots. In2015 International Conference on Pervasive Computing (ICPC). Jan. 8, 2015. 5 pages. [cited by applicant]
Srivastava et al., Trusted VM snapshots in untrusted cloud infrastructures. Research in Attacks, Intrusions, and Defenses: 15th International Symposium, RAID 2012, Amsterdam, The Netherlands, Sep. 12-14, 2012. 21 pages. [cited by applicant]
Tang, FVD: A High-Performance Virtual Machine Image Format for Cloud. 2011 USENIX Annual Technical Conference (USENIX ATC 11). 18 pages. [cited by applicant]
Umamaheswari et al., INSPECT—An intelligent and reliable Forensic Investigation through Virtual Machine Snapshots. International Journal of Modern Education and Computer Science. Mar. 1, 2018;12(3):17-28. [cited by applicant]
Yu et al., SNPdisk: an efficient para-virtualization snapshot mechanism for virtual disks in private clouds. IEEE Network. Jul. 18, 2011;25(4):20-6. [cited by applicant]
Zach et al., LiveCloudInspector: Towards Integrated IaaS Forensics in the Cloud. Proceedings of the 15th IFIP WG 6.1 International Conference on Distributed Applications and Interoperable Systems. Jun. 2, 2015;9038:207-… [cited by applicant]