IP Library Granted Patent US 12,273,258
Granted Patent B1
US 12,273,258 · App. 18/917,690 · Granted Apr 8, 2025

System and method for determining code reachability in a networked computing environment

Inventors: Assaf Segal (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Shir Tamari (Tel Aviv, IL); Arnon Trabelsi (Tel Aviv, IL); Amir Lande Blau (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L45/02G06F21/577G06F21/62H04L63/1416H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,258
App. No.
18/917,690
Granted
Apr 8, 2025
Kind
B1
Abstract

A system and method for performing inspection of a reachable code object of a cloud computing environment is presented. The method includes detecting a network path for each resource of a plurality of resources deployed in a cloud computing environment, wherein the network path includes at least a portion between an external network and the cloud computing environment; determining reachability parameters of each resource of the plurality of resources for which a network path is detected; accessing a code repository including a plurality of code objects; actively inspecting the network path of a resource to determine if the network path is a viable network path; mapping each resource having a viable network path to a code object of the plurality of code objects; inspecting a mapped code object for a cybersecurity object; and initiating a remediation action based on the cybersecurity object.

Claims (70)

1. A method for performing inspection of a reachable code object of a cloud computing environment, comprising:

detecting a network path for each resource of a plurality of resources deployed in a cloud computing environment, wherein the network path includes at least a portion between an external network and the cloud computing environment;

determining reachability parameters of each resource of the plurality of resources for which a network path is detected;

accessing a code repository including a plurality of code objects;

actively inspecting the network path of a resource to determine if the network path is a viable network path;

mapping each resource having a viable network path to a code object of the plurality of code objects;

inspecting a mapped code object for a cybersecurity object; and

initiating a remediation action based on the cybersecurity object.

2. The method of claim 1 , further comprising:

generating the reachability parameters utilizing static analysis.

3. The method of claim 2 , further comprising:

generating the network path for a resource based on the reachability parameters.

4. The method of claim 1 , further comprising:

determining whether the network path is viable by executing an access instruction over the network path.

5. The method of claim 1 , further comprising:

detecting an identifier of a resource;

detecting an identifier of a code object, wherein the identifier of the resource indicates the identifier of the resource.

6. The method of claim 5 , further comprising:

mapping the resource to the code object based on the detected identifiers.

7. The method of claim 6 , further comprising:

inspecting only a mapped code object for a cybersecurity object.

8. The method of claim 1 , further comprising:

detecting a second cybersecurity object in the mapped code object; and

detecting a cybersecurity risk based on the detected cybersecurity object and the detected second cybersecurity object.

9. The method of claim 1 , wherein the remediation action includes any one of: revoking access to a resource, generating a new code object, revoking access from a resource, and any combination thereof.

10. The method of claim 1 , further comprising:

initiating the remediation action to generate a new code object, the new code object based on the mapped code object.

11. The method of claim 10 , further comprising:

generating the new code object by removing the cybersecurity object from the mapped code object.

12. A device for performing inspection of a reachable code object of a cloud computing environment comprising:

one or more processing circuitries configured to:

detect a network path for each resource of a plurality of resources deployed in a cloud computing environment, wherein the network path includes at least a portion between an external network and the cloud computing environment;

determine reachability parameters of each resource of the plurality of resources for which a network path is detected;

access a code repository including a plurality of code objects;

actively inspect the network path of a resource to determine if the network path is a viable network path;

map each resource having a viable network path to a code object of the plurality of code objects;

inspect a mapped code object for a cybersecurity object; and

initiate a remediation action based on the cybersecurity object.

13. A system for performing inspection of a reachable code object of a cloud computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a network path for each resource of a plurality of resources deployed in a cloud computing environment, wherein the network path includes at least a portion between an external network and the cloud computing environment;

determine reachability parameters of each resource of the plurality of resources for which a network path is detected;

access a code repository including a plurality of code objects;

actively inspect the network path of a resource to determine if the network path is a viable network path;

map each resource having a viable network path to a code object of the plurality of code objects;

inspect a mapped code object for a cybersecurity object; and

initiate a remediation action based on the cybersecurity object.

14. The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the reachability parameters utilizing static analysis.

15. The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the network path for a resource based on the reachability parameters.

16. The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine whether the network path is viable by executing an access instruction over the network path.

17. The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect an identifier of a resource; and

detect an identifier of a code object, wherein the identifier of the resource indicates the identifier of the resource.

18. The system of claim 17 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

map the resource to the code object based on the detected identifiers.

19. The system of claim 18 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

inspect only a mapped code object for a cybersecurity object.

20. The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a second cybersecurity object in the mapped code object; and

detect a cybersecurity risk based on the detected cybersecurity object and the detected second cybersecurity object.

21. The system of claim 13 , wherein the remediation action includes any one of:

revoking access to a resource, generating a new code object, revoking access from a resource, and any combination thereof.

22. The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate the remediation action to generate a new code object, the new code object based on the mapped code object.

23. The system of claim 22 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the new code object by removing the cybersecurity object from the mapped code object.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2024
From: SEGAL, ASSAF; LUTTWAK, AMI; TAMARI, SHIR; TRABELSI, ARNON; LANDE BLAU, AMIR
To: WIZ, INC.
Reel/Frame 069549/0988 →
References Cited (13)
US 10515212B1 · McClintock · 2019 [cited by examiner]
US 11218510B2 · Crabtree et al. · 2022 [cited by applicant]
US 11297109B2 · Crabtree et al. · 2022 [cited by applicant]
US 11587177B2 · Sankar et al. · 2023 [cited by applicant]
US 20160112445A1 · Abramowitz · 2016 [cited by examiner]
US 20200396254A1 · Crabtree · 2020 [cited by examiner]
US 20210021644A1 · Crabtree · 2021 [cited by examiner]
US 20220286479A1 · Keren · 2022 [cited by examiner]
US 20230164164A1 · Herzberg · 2023 [cited by examiner]
US 20230336550A1 · Lidgi · 2023 [cited by examiner]
US 20240146745A1 · Lidgi · 2024 [cited by examiner]
US 20240168792A1 · Shemesh · 2024 [cited by examiner]
US 20240214382A1 · Lidgi · 2024 [cited by examiner]