IP Library › Granted Patent US 11,431,786
Granted Patent B1
US 11,431,786 · App. 17/109,883 · Granted Aug 30, 2022

System and method for analyzing network objects in a cloud environment

Inventors: Shai Keren (Tel Aviv, IL); Danny Shemesh (Netanya, IL); Roy Reznik (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Avihai Berkovitz (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L67/10H04L41/046H04L41/5096H04L49/70H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,431,786
App. No.
17/109,883
Filed
Dec 2, 2020
Granted
Aug 30, 2022
Kind
B1
Art Unit
2447
USPC
709/223
Abstract

A method and system for cataloging network objects in a cloud environment are presented. The system includes collecting at least network object data on a plurality of network objects operable in a cloud environment, wherein the plurality of network objects are operable at different layers of the cloud environment; identifying the plurality of network objects operable in the cloud environment; constructing at least a network graph based on the identified network objects; determining relationships between the identified network objects in the at least a network graph; generating at least an insight for least one of the identified network objects, wherein the insight is generated in response to the network graph and the determined relationships; and tagging each of the plurality of network objects for which an insight is generated.

Claims (51)

1. A method for cataloging network objects in a cloud environment, comprising:

collecting network object data on a plurality of network objects operable in a cloud environment, wherein the plurality of network objects is operable at different layers of the cloud environment;

identifying the plurality of network objects operable in the cloud environment;

constructing a network graph based on the identified network objects;

determining relationships between the identified network objects in the network graph using static analysis of at least configuration files of the identified network objects, wherein determining the relationships between the identified network objects further includes determining access permission between the identified network objects;

generating an insight for at least one of the identified network objects, wherein the insight is generated based on the network graph and the determined relationships; and

tagging each of the plurality of network objects for which the insight is generated.

2. The method of claim 1 , wherein the cloud environment includes at least one cloud computing platform.

3. The method of claim 2 , wherein collecting at least network object data further comprises:

querying the at least one cloud computing platform.

4. The method of claim 1 , wherein constructing the network graph further comprises:

generating visual representations of the network graph.

5. The method of claim 1 , wherein determining relationships between the identified objects further comprises:

determining the relationships using a static analytic method.

6. The method of claim 5 , further comprising:

adding visual representations of the determined relationships to visual representations of the network graph.

7. The method of claim 1 , wherein determining the relationships between the identified network objects in the network graph further comprises:

determining the relationships using at least one of: observational methods, and active logging methods.

8. The method of claim 1 , wherein tagging each of the plurality of network objects further comprises:

updating one or more search tags associated with the plurality of network objects.

9. The method of claim 1 , wherein each of the plurality of network objects includes a virtual network, a firewall, a network interface card, a proxy, a gateway, a software container, container, a management object, a virtual machine, a subnet, a hub, a virtual private networks (VPN).

10. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for cataloging network objects in a cloud environment, the process comprising:

collecting network object data on a plurality of network objects operable in a cloud environment, wherein the plurality of network objects is operable at different layers of the cloud environment;

identifying the plurality of network objects operable in the cloud environment;

constructing a network graph based on the identified network objects;

determining relationships between the identified network objects in the network graph using static analysis of at least configuration files of the identified network objects, wherein determining the relationships between the identified network objects further includes determining access permissions between the identified network objects;

generating an insight for at least one of the identified network objects, wherein the insight is generated based on the network graph and the determined relationships; and

tagging each of the plurality of network objects for which the insight is generated.

11. A system for cataloging network objects in a cloud environment, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

collect network object data on a plurality of network objects operable in a cloud environment, wherein the plurality of network objects is operable at different layers of the cloud environment;

identify the plurality of network objects operable in the cloud environment;

construct a network graph based on the identified network objects;

determine relationships between the identified network objects in the network graph using static analysis of at least configuration files of the identified network objects, wherein determining the relationships between the identified network objects further includes determining access permissions between the identified network objects;

generate an insight for at least one of the identified network objects, wherein the insight is generated based on the network graph and the determined relationships; and

tag each of the plurality of network objects for which the insight is generated.

12. The system of claim 11 , wherein the cloud environment includes at least one cloud computing platform.

13. The system of claim 12 , wherein the system is further configured to:

query the at least one cloud computing platform.

14. The system of claim 11 , wherein the system is further configured to:

generate visual representations of the network graph.

15. The system of claim 11 , wherein the system is further configured to:

determine the relationships using a static analytic method.

16. The system of claim 11 , wherein the system is further configured to:

add visual representations of the determined relationships to visual representations of the network graph.

17. The system of claim 11 , wherein the system is further configured to:

determine the relationships using at least one of: observational methods, and active logging methods.

18. The system of claim 11 , wherein the system is further configured to:

update one or more search tags associated with the plurality of network objects.

19. The system of claim 13 , wherein each of the plurality of network objects includes a virtual network, a firewall, a network interface card, a proxy, a gateway, a software container, container, a management object, a virtual machine, a subnet, a hub, a virtual private networks (VPN).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2020
From: KEREN, SHAI; SHEMESH, DANNY; REZNIK, ROY; LUTTWAK, AMI; BERKOVITZ, AVIHAI
To: WIZ, INC.
Reel/Frame 054520/0448 →
Cited By (6)
US 12,621,205 US 12,634,202 US 12,647,324 US 12,663,974 US 12,681,775 US 12,710,987