IP Library Granted Patent US 12,470,583
Granted Patent B1
US 12,470,583 · App. 19/217,385 · Granted Nov 11, 2025

Techniques for active inspection detection of effective network exposure through a cloud-native proxy appliance

Inventors: Ron David Ben Arzi (Kyoto, JP); Ami Luttwak (Binyamina, IL); Shai Keren (Oporto, PT); Oron Noah (Geulim, IL)
Assignee: Wiz, Inc.
H04L63/1425H04L63/02H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,583
App. No.
19/217,385
Granted
Nov 11, 2025
Kind
B1
Abstract

A system and method for agentless detection of network exposure of a software appliance is presented. The method includes detecting a software appliance in a cloud computing environment, wherein the software appliance includes an immutable preconfigured, self-contained software application; inspecting the software appliance for a proxy-type application; detecting network traffic associated with the software appliance; generating a network path based on the network traffic and a network identifier of a component of the cloud computing environment based on detecting the proxy-type application and an identifier of the component in the detected network traffic; actively inspecting the generated network path through an external network, wherein the external network is external to the cloud computing environment; determining that the network path exposes the component based on a result of actively inspecting the generated network path; and initiating a remediation action based on the result of the active inspection.

Claims (65)

1 . A method for agentless detection of network exposure of a software appliance, comprising:

detecting a software appliance in a cloud computing environment, wherein the software appliance includes an immutable preconfigured, self-contained software application;

inspecting the software appliance utilizing agentless inspection for a proxy-type application;

detecting network traffic associated with the software appliance;

generating a network path based on the network traffic and a network identifier of at least a component of the cloud computing environment based on detecting the proxy-type application and an identifier of the at least a component in the detected network traffic;

actively inspecting the generated network path through an external network, wherein the external network is external to the cloud computing environment;

determining that the network path exposes the at least a component based on a result of actively inspecting the generated network path; and

initiating a remediation action based on the result of the active inspection.

2 . The method of claim 1 , further comprising:

detecting that the software appliance includes a web application firewall.

3 . The method of claim 1 , wherein inspecting the software appliance further comprises:

generating an inspectable disk from the software appliance; and

inspecting the inspectable disk for a cybersecurity object, wherein the cybersecurity object indicates the proxy-type application.

4 . The method of claim 1 , wherein detecting network traffic further comprises:

detecting a plurality of network traffic records in a network traffic log of the cloud computing environment.

5 . The method of claim 4 , further comprising:

detecting a second plurality of network traffic records from a sensor deployed on a resource, wherein the software appliance is accessible to the resource.

6 . The method of claim 1 , wherein actively inspecting the generating network path further comprises:

generating an access instruction; and

executing the access instruction over the network path.

7 . The method of claim 6 , further comprising:

routing the access instruction through a proxy server, the proxy server connected to the external network.

8 . The method of claim 1 , wherein initiating the remediation action comprises:

generating a network traffic routing rule based on the network identifier; and

configuring the proxy-type application to apply the network traffic routing rule.

9 . The method of claim 1 , wherein initiating the remediation action comprises:

initiating an action in a data plane of the cloud computing environment to sever the network path.

10 . A non-transitory computer-readable medium storing a set of instructions for agentless detection of network exposure of a software appliance, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

detect a software appliance in a cloud computing environment, wherein the software appliance includes an immutable preconfigured, self-contained software application;

inspect the software appliance utilizing agentless inspection for a proxy-type application;

detect network traffic associated with the software appliance;

generate a network path based on the network traffic and a network identifier of at least a component of the cloud computing environment based on detecting the proxy-type application and an identifier of the at least a component in the detected network traffic;

actively inspect the generated network path through an external network, wherein the external network is external to the cloud computing environment;

determine that the network path exposes the at least a component based on a result of actively inspecting the generated network path; and

initiate a remediation action based on the result of the active inspection.

11 . A system for agentless detection of network exposure of a software appliance comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a software appliance in a cloud computing environment, wherein the software appliance includes an immutable preconfigured, self-contained software application;

inspect the software appliance utilizing agentless inspection for a proxy-type application;

detect network traffic associated with the software appliance;

generate a network path based on the network traffic and a network identifier of at least a component of the cloud computing environment based on detecting the proxy-type application and an identifier of the at least a component in the detected network traffic;

actively inspect the generated network path through an external network, wherein the external network is external to the cloud computing environment;

determine that the network path exposes the at least a component based on a result of actively inspecting the generated network path; and

initiate a remediation action based on the result of the active inspection.

12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect that the software appliance includes a web application firewall.

13 . The system of claim 11 , wherein the memory contains further instructions that, when executed by the processing circuitry for inspecting the software appliance, further configure the system to:

generate an inspectable disk from the software appliance; and

inspect the inspectable disk for a cybersecurity object, wherein the cybersecurity object indicates the proxy-type application.

14 . The system of claim 11 , wherein the memory contains further instructions that, when executed by the processing circuitry for detecting network traffic, further configure the system to:

detect a plurality of network traffic records in a network traffic log of the cloud computing environment.

15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a second plurality of network traffic records from a sensor deployed on a resource, wherein the software appliance is accessible to the resource.

16 . The system of claim 11 , wherein the memory contains further instructions that, when executed by the processing circuitry for actively inspecting the generating network path, further configure the system to:

generate an access instruction; and

execute the access instruction over the network path.

17 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

route the access instruction through a proxy server, the proxy server connected to the external network.

18 . The system of claim 11 , wherein the memory contains further instructions that, when executed by the processing circuitry for initiating the remediation action, further configure the system to:

generate a network traffic routing rule based on the network identifier; and

configure the proxy-type application to apply the network traffic routing rule.

19 . The system of claim 11 , wherein the memory contains further instructions that, when executed by the processing circuitry for initiating the remediation action, further configure the system to:

initiate an action in a data plane of the cloud computing environment to sever the network path.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2025
From: BEN ARZI, RON DAVID; LUTTWAK, AMI; KEREN, SHAI; NOAH, ORON
To: WIZ, INC.
Reel/Frame 072043/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2025
From: BEN ARZI, RON DAVID; KEREN, SHAI; NOAH, ORON
To: WIZ, INC.
Reel/Frame 072045/0807 →
References Cited (11)
US 10764313B1 · Mushtaq · 2020 [cited by applicant]
US 11546360B2 · Woodford et al. · 2023 [cited by applicant]
US 11831420B2 · Kapelevich et al. · 2023 [cited by applicant]
US 20060184682A1 · Suchowski · 2006 [cited by examiner]
US 20170126709A1 · Baradaran · 2017 [cited by examiner]
US 20180131711A1 · Chen · 2018 [cited by examiner]
US 20210067489A1 · Jayawardena · 2021 [cited by examiner]
US 20210367935A1 · Dykes et al. · 2021 [cited by applicant]
US 20240346424A1 · Orzechowski et al. · 2024 [cited by applicant]
US 20250080574A1 · Shua · 2025 [cited by examiner]
E. Hou, Y. Ylmaz and A. O. Hero, “Anomaly Detection in Partially Observed Traffic Networks,” in IEEE Transactions on Signal Processing, vol. 67, No. 6, pp. 1461-1476, Mar. 1, 15, 2019, doi: 10.1109/TSP.2019.2892026. (Ye… [cited by examiner]
Cited By (1)
US 12,694,125