IP Library › Granted Patent US 12,566,658
Granted Patent B1
US 12,566,658 · App. 19/057,067 · Granted Mar 3, 2026

System and method for root cause analysis using tree structure analysis

Inventors: Pavel Resnianski (Tel Aviv, IL); Amit Tal (Ramat Gan, IL); Bernie Pinkenzon-Howard (Tel Aviv, IL); Barak Bercovitz (Even-Yehuda, IL)
Assignee: Wiz, Inc.
G06F11/079G06F11/0736G06F16/2272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,566,658
App. No.
19/057,067
Granted
Mar 3, 2026
Kind
B1
Abstract

A system and method for root cause analysis. A method includes defining tree structures based on metadata of interconnected systems. Each tree structure represents at least a portion of one of the interconnected systems and includes subtrees. Tree structure pairs are identified based on the tree structures. Each tree structure pair includes first and second tree structures. Graph data structures are generated based on the tree structures. Each graph data structure corresponds to one of the tree structures and includes nodes. Each node of each graph data structure represents a respective subtree of the corresponding tree structure. A comparison is performed between graph data structures, where a first graph data structure representing the first tree structure of each tree structure pair is compared to a second graph data structure representing the second tree structure of the tree structure pair in the comparison. Tree structures are matched based on the comparison.

Claims (48)

1 . A method for root cause analysis, comprising:

defining a plurality of tree structures based on metadata of a plurality of interconnected systems, wherein each tree structure represents at least a portion of one of the plurality of interconnected systems, wherein each tree structure includes a plurality of subtrees;

identifying a plurality of tree structure pairs based on the plurality of tree structures, wherein each tree structure pair includes a first tree structure and a second tree structure;

generating a plurality of graph data structures based on the plurality of tree structures, wherein each graph data structure corresponds to a tree structure of the plurality of tree structures and includes a plurality of nodes, wherein each node of each graph data structure represents a respective subtree of the plurality of subtrees of the corresponding tree structure;

comparing between graph data structures among the plurality of graph data structures, wherein a first graph data structure representing the first tree structure of each tree structure pair is compared to a second graph data structure representing the second tree structure of the tree structure pair;

matching between tree structures of the plurality of tree structures based on the comparison in order to identify a tree structure of the plurality of tree structures which matches a tree structure of a file indicated in cybersecurity data;

identifying a root cause of a cyber threat of the cybersecurity data based on the matching; and

blocking traffic to one of the plurality of interconnected systems based on the identified root cause.

2 . The method of claim 1 , further comprising:

generating an embedding for each of the plurality of graph data structures, wherein comparing between pairs of graph data structures of the plurality of graph data structures further comprises comparing the embeddings of the graph data structures in order to determine a maximum common embedding between each pair of compared graph data structures, wherein the matching is performed based on the determined maximum common embeddings.

3 . The method of claim 1 , further comprising:

generating a plurality of reduced tree structures based on the plurality of tree structures, wherein each reduced tree structure corresponds to one of the plurality of tree structures, wherein each reduced tree structure is a subset of the corresponding tree structure, wherein generating the plurality of graph data structures further comprises transforming the plurality of reduced tree structures into the plurality of graph data structures.

4 . The method of claim 3 , wherein generating the plurality of reduced tree structures further comprises:

identifying a plurality subtrees among the plurality of tree structures for subsequent processing, wherein the plurality of reduced tree structures only include the identified plurality of subtrees for subsequent processing.

5 . The method of claim 4 , wherein the identified plurality of subtrees includes at least one of: subtrees among suffixes of the plurality of tree structures, and subtrees including predetermined portions of text.

6 . The method of claim 1 , wherein identifying the plurality of tree structure pairs further comprises:

filtering a plurality of potential tree structure pairs based on the metadata of the plurality of interconnected systems in order to create a plurality of filtered tree structure pairs, wherein the identified plurality of tree structure pairs is the plurality of filtered tree structure pairs.

7 . The method of claim 6 , wherein filtering the plurality of potential tree structure pairs further comprises:

comparing between the metadata of the interconnected systems of the plurality of potential tree structure pairs in order to determine a plurality of intersection values for the plurality of potential tree structure pairs, wherein the plurality of potential tree structure pairs is filtered based on the plurality of intersection values.

8 . A non-transitory computer-readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

defining a plurality of tree structures based on metadata of a plurality of interconnected systems, wherein each tree structure represents at least a portion of one of the plurality of interconnected systems, wherein each tree structure includes a plurality of subtrees;

identifying a plurality of tree structure pairs based on the plurality of tree structures, wherein each tree structure pair includes a first tree structure and a second tree structure;

generating a plurality of graph data structures based on the plurality of tree structures, wherein each graph data structure corresponds to a tree structure of the plurality of tree structures and includes a plurality of nodes, wherein each node of each graph data structure represents a respective subtree of the plurality of subtrees of the corresponding tree structure;

comparing between graph data structures among the plurality of graph data structures, wherein a first graph data structure representing the first tree structure of each tree structure pair is compared to a second graph data structure representing the second tree structure of the tree structure pair;

matching between tree structures of the plurality of tree structures based on the comparison in order to identify a tree structure of the plurality of tree structures which matches a tree structure of a file indicated in cybersecurity data;

identifying a root cause of a cyber threat of the cybersecurity data based on the matching; and

blocking traffic to one of the plurality of interconnected systems based on the identified root cause.

9 . A system for root cause analysis, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

define a plurality of tree structures based on metadata of a plurality of interconnected systems, wherein each tree structure represents at least a portion of one of the plurality of interconnected systems, wherein each tree structure includes a plurality of subtrees;

identify a plurality of tree structure pairs based on the plurality of tree structures, wherein each tree structure pair includes a first tree structure and a second tree structure;

generate a plurality of graph data structures based on the plurality of tree structures, wherein each graph data structure corresponds to a tree structure of the plurality of tree structures and includes a plurality of nodes, wherein each node of each graph data structure represents a respective subtree of the plurality of subtrees of the corresponding tree structure;

compare between graph data structures among the plurality of graph data structures, wherein a first graph data structure representing the first tree structure of each tree structure pair is compared to a second graph data structure representing the second tree structure of the tree structure pair;

match between tree structures of the plurality of tree structures based on the comparison in order to identify a tree structure of the plurality of tree structures which matches a tree structure of a file indicated in cybersecurity data;

identify a root cause of a cyber threat of the cybersecurity data based on the matching; and

block traffic to one of the plurality of interconnected systems based on the identified root cause.

10 . The system of claim 9 , wherein the system is further configured to:

generate an embedding for each of the plurality of graph data structures, wherein comparing between pairs of graph data structures of the plurality of graph data structures further comprises comparing the embeddings of the graph data structures in order to determine a maximum common embedding between each pair of compared graph data structures, wherein the matching is performed based on the determined maximum common embeddings.

11 . The system of claim 9 , wherein the system is further configured to:

generate a plurality of reduced tree structures based on the plurality of tree structures, wherein each reduced tree structure corresponds to one of the plurality of tree structures, wherein each reduced tree structure is a subset of the corresponding tree structure, wherein generating the plurality of graph data structures further comprises transforming the plurality of reduced tree structures into the plurality of graph data structures.

12 . The system of claim 11 , wherein the system is further configured to:

identify a plurality subtrees among the plurality of tree structures for subsequent processing, wherein the plurality of reduced tree structures only include the identified plurality of subtrees for subsequent processing.

13 . The system of claim 12 , wherein the identified plurality of subtrees includes at least one of: subtrees among suffixes of the plurality of tree structures, and subtrees including predetermined portions of text.

14 . The system of claim 9 , wherein the system is further configured to:

filter a plurality of potential tree structure pairs based on the metadata of the plurality of interconnected systems in order to create a plurality of filtered tree structure pairs, wherein the identified plurality of tree structure pairs is the plurality of filtered tree structure pairs.

15 . The system of claim 14 , wherein the system is further configured to:

compare between the metadata of the interconnected systems of the plurality of potential tree structure pairs in order to determine a plurality of intersection values for the plurality of potential tree structure pairs, wherein the plurality of potential tree structure pairs is filtered based on the plurality of intersection values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2025
From: RESNIANSKI, PAVEL; TAL, AMIT; PINKENZON-HOWARD, BERNIE; BERCOVITZ, BARAK
To: WIZ, INC.
Reel/Frame 070257/0595 →
References Cited (19)
US 7792770B1 · Phoha · 2010 [cited by examiner]
US 10061637B1 · Halbersberg · 2018 [cited by examiner]
US 10063570B2 · Muddu · 2018 [cited by examiner]
US 10768868B2 · Ota · 2020 [cited by examiner]
US 12130720B2 · Mandal · 2024 [cited by examiner]
US 12242332B2 · Ashrafi · 2025 [cited by examiner]
US 20090113248A1 · Bock · 2009 [cited by examiner]
US 20160036844A1 · Kopp · 2016 [cited by examiner]
US 20170083920A1 · Zoldi · 2017 [cited by examiner]
US 20190050279A1 · Derr · 2019 [cited by examiner]
US 20190278647A1 · Bakucz · 2019 [cited by examiner]
US 20190324836A1 · Fleischman · 2019 [cited by examiner]
US 20200012551A1 · Liang · 2020 [cited by examiner]
US 20220222238A1 · Herrema, III · 2022 [cited by examiner]
US 20230050889A1 · Kumar Jaya Kumar · 2023 [cited by examiner]
US 20230105304A1 · Mandal · 2023 [cited by examiner]
US 20230353447A1 · Vaderna · 2023 [cited by examiner]
“On the maximum common embedded subtree problem for ordered trees,” String Algorithmics (2004): 155-170 (available at https://pdfs.semanticscholar.org/0b6e/061af02353f7d9b887f9a378be70be64d165.pdf) (last accessed Nov. 4… [cited by applicant]
Github, “The network_algo_common_subtree Module,” Author username: Erotemic (available at https://github.com/Erotemic/networkx_algo_common_subtree/tree/669889b4a4dcd8864f27c494863c5d4d4f48ace0?tab=readme-ov-file#the-net… [cited by applicant]