IP Library Granted Patent US 12,231,434
Granted Patent B1
US 12,231,434 · App. 18/785,419 · Granted Feb 18, 2025

Cloud data attack surface tracking using graph-based excessive privilege detection

Inventors: Yang Zhang (Fremont, CA); Ajay Agrawal (Bangalore, IN); Ravishankar Ganesh Ithal (Los Altos, CA)
Assignee: Normalyze, Inc.
H04L63/104H04L63/105H04L63/108H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,434
App. No.
18/785,419
Granted
Feb 18, 2025
Kind
B1
Abstract

A computer-implemented method includes detecting occurrence of an event in a cloud environment, obtaining an indication of an identity associated with the event, obtaining an indication of a usage time stamp representing usage time of a privilege in association with the identity for the event, and classifying the privilege into a classification group selected from a plurality of predefined classification groups. Each respective classification group groups a respective set of privileges defined in the cloud environment. The method includes obtaining a grant time stamp representing a grant time of at least one privilege, in the respective set of privileges in the classification group, to the identity and, based on the usage time stamp and the grant time stamp, generating an excessive privilege determination that indicates the classification group includes at least one excessive privilege. The method includes performing a computing action based on the excessive privilege determination.

Claims (57)

1. A computer-implemented method comprising:

detecting occurrence of an event in a cloud environment;

obtaining an indication of an identity associated with the event;

obtaining an indication of a usage time stamp representing usage time of a privilege in association with the identity for the event in the cloud environment;

classifying the privilege into a classification group selected from a plurality of predefined classification groups, each respective classification group, of the plurality of predefined classification groups, grouping a respective set of privileges defined in the cloud environment;

obtaining a grant time stamp representing a grant time of at least one privilege, in the respective set of privileges in the classification group, to the identity;

based on the usage time stamp and the grant time stamp, generating an excessive privilege determination that indicates the classification group includes at least one excessive privilege; and

performing a computing action based on the excessive privilege determination.

2. The computer-implemented method of claim 1 , wherein detecting the occurrence of the event comprises accessing an event record.

3. The computer-implemented method of claim 2 , wherein accessing the event record comprises deploying an event log scanner that scans an event log and returns event metadata representing the event, the event metadata including privilege metadata that identifies the privilege, identity metadata that identifies the identity that utilized the privilege, resource metadata that identifies a resource accessed using the privilege, and timestamp metadata representing the usage time stamp.

4. The computer-implemented method of claim 1 , wherein the identity comprises at least one of a user or a role, and the event comprises a resource access event of the at least one of a user or a role to a resource.

5. The computer-implemented method of claim 1 , wherein performing the computing action comprises:

generating a user interface display that renders a representation of the excessive privilege determination, or

performing a privilege revocation that revokes the respective set of privileges in classification group.

6. The computer-implemented method of claim 1 , wherein each respective classification group, of the plurality of predefined classification groups, is represented by a target computing action in the cloud environment.

7. The computer-implemented method of claim 6 , wherein the respective set of privileges, in each respective classification group, is grouped based on a threshold similarity to the target computing action.

8. The computer-implemented method of claim 1 , and further comprising:

parsing a collection of granular privileges that represents semantic similarities between privileges in the collection of granular privileges; and

building a mapping file that maps, for each respective classification group of the plurality of predefined classification groups, two or more granular privileges from the collection of granular privileges into the respective classification group.

9. The computer-implemented method of claim 8 , and further comprising:

accessing policy data and identifying, based on the policy data, a set of grant times, wherein each respective grant time, in the set of grant times, represents a time at which a corresponding granular privilege, in the collection of granular privileges, was granted to a subject identity, the corresponding granular privilege defining access permissions for the subject identity to a subject resource.

10. The computer-implemented method of claim 9 , and further comprising:

mapping the set of grant times to the plurality of predefined classification groups and generating an infrastructure graph to include

nodes that represent the subject identities,

nodes that represent the subject resources, and

edges that represent the set of grant times.

11. The computer-implemented method of claim 10 , and further comprising:

updating the infrastructure graph to include an indication of the usage time stamp; and

generating the excessive privilege determination based on a comparison of the grant time stamp to the usage time stamp in the updated infrastructure graph.

12. A computing system comprising:

at least one processor; and

memory storing instructions executable by the at least one processor, wherein the instructions, when executed, cause the computing system to:

detect occurrence of an event in a cloud environment;

obtain an indication of an identity associated with the event;

obtain an indication of a usage time stamp representing usage time of a privilege in association with the identity for the event in the cloud environment;

classify the privilege into a classification group selected from a plurality of predefined classification groups, each respective classification group, of the plurality of predefined classification groups, grouping a respective set of privileges defined in the cloud environment;

based on a comparison of the usage time stamp to a threshold, generate an excessive privilege determination that indicates the classification group includes at least one excessive privilege; and

perform a computing action based on the excessive privilege determination.

13. The computing system of claim 12 , wherein the instructions, when executed, cause the computing system to:

deploy an event log scanner that scans an event log including an event record representing the event; and

return event metadata representing the event, the event metadata including privilege metadata that identifies the privilege, identity metadata that identifies the identity that utilized the privilege, resource metadata that identifies a resource accessed using the privilege, and timestamp metadata representing the usage time stamp.

14. The computing system of claim 12 , wherein the identity comprises at least one of a user or a role, and the event comprises a resource access event of the at least one of a user or a role to a resource, and wherein the instructions, when executed, cause the computing system to:

obtain a grant time stamp representing a grant time of at least one privilege, in the respective set of privileges in the classification group, to the identity;

generate the excessive privilege determination based on a comparison of the usage time stamp to the grant time stamp.

15. The computing system of claim 12 , wherein each respective classification group, of the plurality of predefined classification groups, is represented by a target computing action in the cloud environment.

16. The computing system of claim 12 , wherein the instructions, when executed, cause the computing system to:

parse a collection of granular privileges that represents semantic similarities between privileges in the collection of granular privileges; and

build a mapping file that maps, for each respective classification group of the plurality of predefined classification groups, two or more granular privileges from the collection of granular privileges into the respective classification group.

17. The computing system of claim 16 , wherein the instructions, when executed, cause the computing system to:

identify, based on policy data, a set of grant times,

wherein each respective grant time, in the set of grant times, represents a time at which a corresponding granular privilege, in the collection of granular privileges, was granted to a subject identity, and

the corresponding granular privilege defines access permissions for the subject identity to a subject resource.

18. The computing system of claim 17 , wherein the instructions, when executed, cause the computing system to:

map the set of grant times to the plurality of predefined classification groups and generating an infrastructure graph to include

nodes that represent the subject identities,

nodes that represent the subject resources, and

edges that represent the set of grant times.

Assignments (4)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2025
From: NORMALYZE, INC.
To: PROOFPOINT, INC.
Reel/Frame 071618/0634 →
SECURITY INTEREST Recorded Feb 19, 2025
From: NORMALYZE, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070254/0844 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2024
From: ZHANG, YANG; AGRAWAL, AJAY; ITHAL, RAVISHANKAR GANESH
To: NORMALYZE, INC.
Reel/Frame 069033/0563 →
References Cited (9)
US 10601876B1 · Levy · 2020 [cited by examiner]
US 10728034B2 · Sandoval · 2020 [cited by examiner]
US 11895121B1 · Karim · 2024 [cited by examiner]
US 20140055804A1 · Eguchi · 2014 [cited by examiner]
US 20170295197A1 · Parimi · 2017 [cited by examiner]
US 20190087489A1 · Culhane · 2019 [cited by examiner]
US 20200336503A1 · Xu · 2020 [cited by examiner]
US 20210112086A1 · Chandana · 2021 [cited by examiner]
US 20220263835A1 · Pieczul · 2022 [cited by examiner]