IP Library Patent Application 18911218
Patent Application
App. No. 18/911,218

CLOUD DATA SCANNING BASED ON INCREMENTAL INFRASTRUCTURE DETECTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/911,218
Abstract

The technology disclosed relates to analysis of security posture of a cloud environment that invokes an incremental change detector to perform an infrastructure scan of the cloud environment and return a scan result that identifies one or more changes to one or more infrastructure assets in the cloud environment. The scan result includes, for each particular change in the one or more changes, first information indicative of the particular change. A data scan is constrained to the one or more infrastructure assets having the one or more changes and second information associated with the one or more changes is obtained based on the data scan. A cloud infrastructure graph is updated based on one or more of the first information or the second information. The cloud infrastructure graph defines nodes that represent resources in the cloud environment and edges, between the nodes, that represent relationships between the resources.

Claims (56)

1 . A computer-implemented method for analyzing a cloud environment, the computer-implemented method comprising:

invoking an incremental change detector configured to perform an infrastructure scan of the cloud environment and return a scan result that identifies one or more changes to one or more infrastructure assets in the cloud environment, wherein the scan result includes, for each particular change in the one or more changes, first information indicative of the particular change;

running a data scan on the cloud environment that is constrained to the one or more infrastructure assets having the one or more changes;

obtaining, based on the data scan, second information associated with the one or more changes; and

updating a cloud infrastructure graph based on one or more of the first information or the second information, wherein the cloud infrastructure graph defines nodes that represent resources in the cloud environment and edges, between the nodes, that represent relationships between the resources.

2 . The computer-implemented method of claim 1 , wherein running the data scan comprises:

running the data scan by executing a query only for entities that had a change identified in the one or more changes.

3 . The computer-implemented method of claim 2 , wherein the data scan scans data stored in the cloud environment in association with the one or more infrastructure assets.

4 . The computer-implemented method of claim 2 , wherein the query comprises an add/delete/update query.

5 . The computer-implemented method of claim 1 , wherein the one or more changes comprise a set of changes identified based on a time period.

6 . The computer-implemented method of claim 5 , and comprising selecting the time period based on a selection criterion.

7 . The computer-implemented method of claim 5 , and further comprising:

selecting the time period based on a previous scan of the cloud environment;

generating a scan parameter based on the time period; and

performing the infrastructure scan based on the scan parameter.

8 . The computer-implemented method of claim 1 , wherein the cloud environment comprises a set of infrastructure assets, and each change, of the one or more changes, comprises at least one of:

an infrastructure asset added to the set of infrastructure assets,

an infrastructure asset deleted from the set of infrastructure assets, and

an infrastructure asset changed in the set of infrastructure assets.

9 . The computer-implemented method of claim 1 , wherein the one or more infrastructure assets comprise at least one of:

a compute resource,

a storage resource,

a privilege, or

a role.

10 . The computer-implemented method of claim 1 , wherein invoking an incremental change detector comprises invoking a log analyzer microservice configured to scan an event log having a plurality of event log entries that represent events in the cloud environment.

11 . The computer-implemented method of claim 10 , and further comprising:

providing a set of parameters to the log analyzer microservice, and

receiving an analysis result from the log analyzer microservice based on the set of parameters, wherein the analysis result is indicative of a filtered set of event log entries from the plurality of event log entries.

12 . The computer-implemented method of claim 10 , wherein the log analyzer microservice is configured to identify write changes in the event log.

13 . The computer-implemented method of claim 1 , and comprising updating the cloud infrastructure graph by at least one of adding a node to the cloud infrastructure graph or deleting a node from the cloud infrastructure graph.

14 . A computing system comprising:

at least one processor; and

memory storing instructions executable by the at least one processor, wherein the instructions, when executed, cause the computing system to:

invoke an incremental change detector configured to perform an infrastructure scan of a cloud environment and return a scan result that identifies one or more changes to one or more infrastructure assets in the cloud environment, wherein the scan result includes, for each particular change in the one or more changes, first information indicative of the particular change;

run a data scan on the cloud environment that is constrained to the one or more infrastructure assets having the one or more changes;

obtain, based on the data scan, second information associated with the one or more changes; and

update a cloud infrastructure graph based on one or more of the first information or the second information, wherein the cloud infrastructure graph defines nodes that represent resources in the cloud environment and edges, between the nodes, that represent relationships between the resources.

15 . The computing system of claim 14 , wherein the data scan executes a query only for entities that had a change identified in the one or more changes.

16 . The computing system of claim 15 , wherein the data scan scans data stored in the cloud environment in association with the one or more infrastructure assets.

17 . The computing system of claim 14 , wherein the one or more infrastructure assets comprise at least one of:

a compute resource,

a storage resource,

a privilege, or

a role.

18 . The computing system of claim 14 , wherein the instructions, when executed, cause the computing system to:

invoke a log analyzer microservice configured to scan an event log having a plurality of event log entries that represent events in the cloud environment.

19 . The computing system of claim 14 , wherein the instructions, when executed, cause the computing system to:

update the cloud infrastructure graph by at least one of adding a node to the cloud infrastructure graph or deleting a node from the cloud infrastructure graph.

20 . A computing system comprising:

a cloud infrastructure detector configured to:

perform an infrastructure scan of a cloud environment; and

return a scan result that identifies one or more changes to one or more infrastructure assets in the cloud environment, wherein the scan result includes, for each particular change in the one or more changes, first information indicative of the particular change;

a data scanner configured to:

run a data scan on the cloud environment that is constrained to the one or more infrastructure assets having the one or more changes; and

obtain, based on the data scan, second information associated with the one or more changes; and

a cloud infrastructure representation updater configured to update a cloud infrastructure graph based on one or more of the first information or the second information, wherein the cloud infrastructure graph defines nodes that represent resources in the cloud environment and edges, between the nodes, that represent relationships between the resources.

Assignments (4)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2025
From: NORMALYZE, INC.
To: PROOFPOINT, INC.
Reel/Frame 071618/0634 →
SECURITY INTEREST Recorded Feb 19, 2025
From: NORMALYZE, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070254/0844 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2024
From: MURUGESAN, MUMMOORTHY; JEYAKUMAR, VIVEK; ITHAL, RAVISHANKAR GANESH
To: NORMALYZE, INC.
Reel/Frame 068885/0705 →