IP Library Granted Patent US 12,476,939
Granted Patent B1
US 12,476,939 · App. 19/217,405 · Granted Nov 18, 2025

System and method for applying cybersecurity controls on cloud native routing services

Inventors: Ron David Ben Arzi (Kyoto, JP); Ami Luttwak (Binyamina, IL); Shai Keren (Oporto, PT); Oron Noah (Geulim, IL)
Assignee: Wiz, Inc.
H04L63/0263H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,939
App. No.
19/217,405
Granted
Nov 18, 2025
Kind
B1
Abstract

A system and method for applying a cybersecurity control on a cloud native routing service is presented. The method includes detecting a cloud native routing component in a cloud computing environment; inspecting network traffic associated with the routing component; detecting routing configuration rules based at least on the inspected network traffic associated with the routing component; storing the detected routing configuration rules as representations on a security database, wherein the security database further includes a representation of the cloud computing environment; and applying a control on the detected routing configuration rules.

Claims (53)

1 . A method for applying a cybersecurity control on a cloud native routing service, comprising:

detecting a cloud native routing component in a cloud computing environment;

inspecting network traffic associated with the cloud native routing component;

detecting routing configuration rules based at least on the inspected network traffic associated with the cloud native routing component;

storing the detected routing configuration rules as representations on a security database, wherein the security database further includes a representation of the cloud computing environment; and

applying a control on the detected routing configuration rules.

2 . The method of claim 1 , further comprising:

detecting network traffic event records in a network log of the cloud computing environment; and

detecting the cloud native routing component in the network traffic based on ingress network traffic and egress network traffic associated with an identifier of the cloud native routing component.

3 . The method of claim 1 , further comprising:

inspecting the network traffic to detect an identifier of the cloud native routing component and an identifier of a resource of the cloud computing environment.

4 . The method of claim 3 , further comprising:

inspecting the network traffic to detect an identifier of the cloud native routing component and a identifier of an external entity, wherein the external entity is deployed in an external network which is external to the cloud computing environment.

5 . The method of claim 1 , further comprising:

storing detected routing configuration rules from a plurality of different routing components; and

applying the control on all stored detected routing configuration rules.

6 . The method of claim 5 , wherein each different routing component is deployed in a different cloud computing environment.

7 . The method of claim 5 , wherein each different routing component is of a different type of routing components.

8 . The method of claim 1 , further comprising:

utilizing a policy engine to apply the control, wherein the control includes a conditional rule.

9 . The method of claim 1 , further comprising:

applying the control on a combination of a routing configuration rule and a representation of an entity of the cloud computing environment.

10 . A non-transitory computer-readable medium storing a set of instructions for applying a cybersecurity control on a cloud native routing service, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

detect a cloud native routing component in a cloud computing environment;

inspect network traffic associated with the cloud native routing component;

detect routing configuration rules based at least on the inspected network traffic associated with the cloud native routing component;

store the detected routing configuration rules as representations on a security database, wherein the security database further includes a representation of the cloud computing environment; and

apply a control on the detected routing configuration rules.

11 . A system for applying a cybersecurity control on a cloud native routing service comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a cloud native routing component in a cloud computing environment;

inspect network traffic associated with the cloud native routing component;

detect routing configuration rules based at least on the inspected network traffic associated with the cloud native routing component;

store the detected routing configuration rules as representations on a security database, wherein the security database further includes a representation of the cloud computing environment; and

apply a control on the detected routing configuration rules.

12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect network traffic event records in a network log of the cloud computing environment; and

detect the cloud native routing component in the network traffic based on ingress network traffic and egress network traffic associated with an identifier of the cloud native routing component.

13 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

inspect the network traffic to detect an identifier of the cloud native routing component and an identifier of a resource of the cloud computing environment.

14 . The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

inspect the network traffic to detect an identifier of the cloud native routing component and a identifier of an external entity, wherein the external entity is deployed in an external network which is external to the cloud computing environment.

15 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

store detected routing configuration rules from a plurality of different routing components; and

apply the control on all stored detected routing configuration rules.

16 . The system of claim 15 , wherein each different routing component is deployed in a different cloud computing environment.

17 . The system of claim 15 , wherein each different routing component is of a different type of routing components.

18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

utilize a policy engine to apply the control, wherein the control includes a conditional rule.

19 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the control on a combination of a routing configuration rule and a representation of an entity of the cloud computing environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2025
From: BEN ARZI, RON DAVID; KEREN, SHAI; NOAH, ORON
To: WIZ, INC.
Reel/Frame 072045/0872 →
References Cited (11)
US 10389760B2 · Bryson · 2019 [cited by examiner]
US 10764313B1 · Mushtaq · 2020 [cited by applicant]
US 11546360B2 · Woodford et al. · 2023 [cited by applicant]
US 11831420B2 · Kapelevich et al. · 2023 [cited by applicant]
US 20210367935A1 · Dykes et al. · 2021 [cited by applicant]
US 20230108054A1 · Meng · 2023 [cited by examiner]
US 20240346424A1 · Orzechowski et al. · 2024 [cited by applicant]
US 20250016190A1 · Rawat · 2025 [cited by examiner]
US 20250080574A1 · Shua · 2025 [cited by examiner]
WO WO2018094516A1 · 2018 [cited by examiner]
Joshi, Manish, and Theyazn Hassn Hadi. “A review of network traffic analysis and prediction techniques.” arXiv preprint arXiv:1507.05722 (2015). (Year: 2015). [cited by examiner]