IP Library Granted Patent US 11,368,479
Granted Patent B2
US 11,368,479 · App. 16/728,905 · Granted Jun 21, 2022

Methods and apparatus to identify and report cloud-based security vulnerabilities

Inventors: Sriranga Seetharamaiah (Bangalore, IN); Cedric Cochin (Hillsboro, OR)
Assignee: Musarubra US LLC
H04L63/1433H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,368,479
App. No.
16/728,905
Granted
Jun 21, 2022
Kind
B2
Abstract

Methods, apparatus, systems and articles of manufacture are disclosed to identify and report cloud-based security vulnerabilities. An apparatus comprising: a security vulnerability detector to, in response to a resource monitor monitoring a threshold amount of activity in a resource of a cloud computing environment, determine one or more security vulnerabilities associated with the resource and the cloud computing environment; a vulnerability processor to correlate the one or more security vulnerabilities with one or more kill chains to exploit at least one security vulnerability in the cloud computing environment; and a report generator to generate a report including a story graph indicating a subset of at least one of: (a) the one or more security vulnerabilities associated with the one or more kill chains, (b) one or more remediation actions to obviate the one or more security vulnerabilities, or (c) threat intelligence feeds associated with the one or more security vulnerabilities.

Claims (78)

1. An apparatus comprising:

a security vulnerability detector to, in response to a resource monitor monitoring a threshold amount of resource activity in a resource of a cloud computing environment, determine one or more security vulnerabilities associated with the resource and the cloud computing environment;

a vulnerability processor to correlate the one or more security vulnerabilities with one or more kill chains to exploit at least one of the one or more security vulnerabilities in the cloud computing environment;

a report generator to generate a report including a story graph, the story graph indicating a subset of at least one of: (a) the one or more security vulnerabilities associated with the one or more kill chains, (b) one or more remediation actions to obviate the one or more security vulnerabilities, or (c) threat intelligence feeds associated with the one or more security vulnerabilities;

a cloud application programming interface (API) log auditor to:

audit a log associated with an API of the cloud computing environment; and

in response to detecting a first vulnerability in the log associated with the API of the cloud computing environment, store a first indication of the first vulnerability in a database; and

an identification proxy monitor to:

monitor an identification and access management device; and

in response to detecting a second vulnerability at the identification and access management device, store a second indication of the second vulnerability in the database.

2. The apparatus of claim 1 , wherein the story graph is indicative of operations executed at a device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment and operations related to the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment.

3. The apparatus of claim 2 , wherein (1) the operations executed at the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment include processing operations, file access operations, and registry operations, and (2) the operations related to the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment include virtual firewalls associated with the device, identification and access management roles of the device, and a location of the device.

4. The apparatus of claim 1 , wherein the vulnerability processor is to, in response to the security vulnerability detector detecting the one or more security vulnerabilities, execute the one or more remediation actions to obviate the one or more security vulnerabilities.

5. The apparatus of claim 1 , wherein the threshold amount of resource activity is a threshold to be satisfied to generate a baseline report, the baseline report indicating at least one of: (a) expected communications between devices in the cloud computing environment, (b) expected configurations for the cloud computing environment, and (c) expected calls to the API associated with the cloud computing environment.

6. The apparatus of claim 1 , further including:

an operating system-based security vulnerability detector to detect one or more security vulnerabilities based on an operating system of the resource; and

a cloud-based security vulnerability detector to detect the one or more security vulnerabilities based on the cloud computing environment.

7. The apparatus of claim 1 , wherein the log is a first log and the apparatus further includes:

a cloud configuration auditor to:

audit a configuration of the cloud computing environment;

in response to detecting a third vulnerability in the configuration, store a third indication of the third first vulnerability in the database;

monitor a second log associated with the configuration of the cloud computing environment; and

in response to detecting a fourth vulnerability in the second log associated with the configuration of the cloud computing environment, store a fourth indication of the fourth vulnerability in the database.

8. The apparatus of claim 1 , wherein the resource includes at least one of a compute resource, a network resource, or a storage resource.

9. A non-transitory computer readable medium comprising instructions that, when executed, cause one or more processors to at least:

in response to monitoring a threshold amount of resource activity in a resource of a cloud computing environment, determine one or more security vulnerabilities associated with the resource and the cloud computing environment;

correlate the one or more security vulnerabilities with one or more kill chains to exploit at least one of the one or more security vulnerabilities in the cloud computing environment;

generate a report including a story graph, the story graph indicating a subset of at least one of: (a) the one or more security vulnerabilities associated with the one or more kill chains, (b) one or more remediation actions to obviate the one or more security vulnerabilities, or (c) threat intelligence feeds associated with the one or more security vulnerabilities;

audit a log associated with an application programming interface (API) of the cloud computing environment;

in response to detecting a first vulnerability in the log associated with the API of the cloud computing environment, store a first indication of the first vulnerability in a database;

monitor an identification and access management device; and

in response to detecting a second vulnerability at the identification and access management device, store a second indication of the second vulnerability in the database.

10. The non-transitory computer readable medium of claim 9 , wherein the story graph is indicative of operations executed at a device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment and operations related to the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment.

11. The non-transitory computer readable medium of claim 10 , wherein (1) the operations executed at the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment include processing operations, file access operations, and registry operations, and (2) the operations related to the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment include virtual firewalls associated with the device, identification and access management roles of the device, and a location of the device.

12. The non-transitory computer readable medium of claim 9 , wherein the instructions, when executed, cause the one or more processors to, in response to detecting the one or more security vulnerabilities, execute the one or more remediation actions to obviate the one or more security vulnerabilities.

13. The non-transitory computer readable medium of claim 9 , wherein the threshold amount of resource activity is a threshold to be satisfied to generate a baseline report, the baseline report indicating at least one of: (a) expected communications between devices in the cloud computing environment, (b) expected configurations for the cloud computing environment, and (c) expected calls to the API associated with the cloud computing environment.

14. The non-transitory computer readable medium of claim 9 , wherein the one or more security vulnerabilities include one or more security vulnerabilities based on an operating system of the resource and one or more security vulnerabilities based on the cloud computing environment.

15. The non-transitory computer readable medium of claim 9 , wherein the log is a first log, and the instructions, when executed, cause the one or more processors to:

audit a configuration of the cloud computing environment;

in response to detecting a third vulnerability in the configuration, store a third indication of the third vulnerability in the database;

monitor a second log associated with the configuration of the cloud computing environment; and

in response to detecting a fourth vulnerability in the second log associated with the configuration of the cloud computing environment, store a fourth indication of the fourth vulnerability in the database.

16. The non-transitory computer readable medium of claim 9 , wherein the resource includes at least one of a compute resource, a network resource, or a storage resource.

17. An apparatus comprising:

means for detecting a security vulnerability to, in response to monitoring a threshold amount of resource activity in a resource of a cloud computing environment, determine one or more security vulnerabilities associated with the resource and the cloud computing environment;

means for processing a security vulnerability to correlate the one or more security vulnerabilities with one or more kill chains to exploit at least one of the one or more security vulnerabilities in the cloud computing environment;

means for generating a report including a story graph, the story graph indicating a subset of at least one of: (a) the one or more security vulnerabilities associated with the one or more kill chains, (b) one or more remediation actions to obviate the one or more security vulnerabilities, or (c) threat intelligence feeds associated with the one or more security vulnerabilities;

means for auditing cloud application programming interface (API) logs to:

audit a log associated with an API of the cloud computing environment; and

in response to detecting a first vulnerability in the log associated with the API of the cloud computing environment, store a first indication of the first vulnerability in a database; and

means for monitoring an identification to:

monitor an identification and access management device; and

in response to detecting a second vulnerability at the identification and access management device, store a second indication of the second vulnerability in the database.

18. The apparatus of claim 17 , wherein the story graph is indicative of operations executed at a device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment and operations related to the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment.

19. The apparatus of claim 18 , wherein (1) the operations executed at the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment include processing operations, file access operations, and registry operations, and (2) the operations related to the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment include virtual firewalls associated with the device, identification and access management roles of the device, and a location of the device.

20. The apparatus of claim 17 , wherein the means for processing the vulnerability is to, in response to the means for detecting the security vulnerability detecting the one or more security vulnerabilities, execute the one or more remediation actions to obviate the one or more security vulnerabilities.

21. An apparatus comprising:

at least one memory;

instructions;

processor circuitry to execute the instructions to at least:

in response to monitoring a threshold amount of resource activity in a resource of a cloud computing environment, determine one or more security vulnerabilities associated with the resource and the cloud computing environment;

correlate the one or more security vulnerabilities with one or more kill chains to exploit at least one of the one or more security vulnerabilities in the cloud computing environment;

generate a report including a story graph, the story graph indicating a subset of at least one of: (a) the one or more security vulnerabilities associated with the one or more kill chains, (b) one or more remediation actions to obviate the one or more security vulnerabilities, or (c) threat intelligence feeds associated with the one or more security vulnerabilities;

audit a log associated with an application programming interface (API) of the cloud computing environment;

in response to detecting a first vulnerability in the log associated with the API of the cloud computing environment, store a first indication of the first vulnerability in a database;

monitor an identification and access management device; and

in response to detecting a second vulnerability at the identification and access management device, store a second indication of the second vulnerability in the database.

22. The apparatus of claim 21 , wherein the story graph is indicative of operations executed at a device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment and operations related to the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment.

23. The apparatus of claim 22 , wherein (1) the operations executed at the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment include processing operations, file access operations, and registry operations, and (2) the operations related to the device associated with the at least one of the one or more security vulnerabilities in the cloud computing environment include virtual firewalls associated with the device, identification and access management roles of the device, and a location of the device.

24. The apparatus of claim 21 , wherein the processor circuitry is to execute the instructions to, in response to detecting the one or more security vulnerabilities, execute the one or more remediation actions to obviate the one or more security vulnerabilities.

25. The apparatus of claim 21 , wherein the threshold amount of resource activity is a threshold to be satisfied to generate a baseline report, the baseline report indicating at least one of: (a) expected communications between devices in the cloud computing environment, (b) expected configurations for the cloud computing environment, and (c) expected calls to the API associated with the cloud computing environment.

26. The apparatus of claim 21 , wherein the one or more security vulnerabilities include one or more security vulnerabilities based on an operating system of the resource and one or more security vulnerabilities based on the cloud computing environment.

27. The apparatus of claim 21 , wherein the log is a first log, and the processor circuitry is to execute the instructions to:

audit a configuration of the cloud computing environment;

in response to detecting a third vulnerability in the configuration, store a third indication of the third vulnerability in the database;

monitor a second log associated with the configuration of the cloud computing environment; and

in response to detecting a fourth vulnerability in the second log associated with the configuration of the cloud computing environment, store a fourth indication of the fourth vulnerability in the database.

28. The apparatus of claim 21 , wherein the resource includes at least one of a compute resource, a network resource, or a storage resource.

Assignments (12)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 060433/0826 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 057393/0546 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2020
From: SEETHARAMAIAH, SRIRANGA; COCHIN, CEDRIC
To: MCAFEE, LLC
Reel/Frame 051741/0839 →