IP Library › Granted Patent US 11,722,522
Granted Patent B2
US 11,722,522 · App. 17/027,830 · Granted Aug 8, 2023

Cloud security posture management systems and methods with a cloud-based system

Inventors: Gururaj Pandurangi (Redmond, WA); Pravin Kulkarni (Pune, IN); Rahul Khengare (Pune, IN); Unmesh Meshram (Pune, IN); Santosh Kumar Abhayraj Yadav (Pune, IN); Shraddha Agrawal (Pune, IN); Ankit Rao (Pune, IN); Himalay Kondekar (Pune, IN); Girish Murlidhar Jaju (Pune, IN)
Assignee: Zscaler, Inc.
H04L63/20H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,522
App. No.
17/027,830
Granted
Aug 8, 2023
Kind
B2
Abstract

Cloud Security Posture Management (CSPM) systems and methods include, in a node in a cloud-based system, obtaining a plurality of security policies and one or more compliance frameworks for a tenant of a cloud provider where the tenant has a cloud application deployed with the cloud provider, wherein each security policy defines a configuration and an expected value, and wherein each compliance framework includes one or more of the security policies; obtaining configurations of the cloud application; identifying misconfigurations of the cloud application based on a comparison of the obtained configurations with the plurality of security policies; analyzing the misconfigurations to determine risks including prioritization of the risks based on their likelihood of exposure to security breaches; and causing remediation of the identified misconfigurations and the determined risks, wherein the cloud-based system performs the CSPM service in addition to one or more additional cloud services.

Claims (48)

1. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming one or more processors in a node in a cloud-based system to perform a Cloud Security Posture Management (CSPM) service via steps of:

obtaining governance a tenant of a cloud provider where the tenant has a cloud application deployed with the cloud provider, wherein the governance includes (1) a plurality of security policies, each security policy defines a configuration and an expected value, and the plurality of security policies include a combination of out of the box policies and tenant-defined policies, (2) one or more compliance frameworks, each compliance framework includes one or more of the security policies, (3) risk-based prioritization for describing risk of any misconfigurations, and (4) enforcement for any of the misconfigurations;

obtaining configurations of the cloud application;

identifying the misconfigurations of the cloud application based on a comparison of the obtained configurations with the configurations of the plurality of security policies, wherein each of the security policies are assigned a status based on a number of compliant resources;

analyzing the misconfigurations and status to determine risks including prioritization of the risks based on (1) their likelihood of exposure to security breaches and (2) the risk-based prioritization; and

causing remediation of the misconfigurations and based on the determined risks and the enforcement,

wherein the cloud-based system performs the CSPM service in addition to one or more additional cloud services.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the one or more additional cloud services include any of a cloud security service, a Cloud Access Security Broker (CASB) service, a Data Loss Prevention (DLP) service, and a Zero Trust Network Access (ZTNA) service.

3. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

causing display of any of a security posture, a compliance posture to the one or more compliance frameworks, a risk posture, and a data privacy posture.

4. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

determining a risk matrix for the tenant; and

causing display of the risk matrix, wherein the risk matrix visualizes risk based on a combination of impact and likelihood.

5. The non-transitory computer-readable storage medium of claim 1 , wherein the tenant has a plurality of users that use the cloud application, and wherein the cloud application is deployed in a public cloud.

6. The non-transitory computer-readable storage medium of claim 1 , wherein the plurality of security policies relate to both cloud infrastructure and the cloud application, wherein the security policies for the cloud infrastructure relate to how underlying cloud resources should be properly configured, and wherein the security policies for the cloud application relate to how the cloud application should be configured and used.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the obtaining, identifying, analyzing, and causing steps are performed during development of the cloud application and while the cloud application is operational.

8. An enforcement node in a cloud-based system configured to implement Cloud Security Posture Management (CSPM), the enforcement node comprising:

one or more processors;

a network interface communicatively coupled to the one or more processors and connected to a network for communication with one or more users and one or more cloud providers with cloud applications deployed thereon; and

memory storing instructions that, when executed, cause the one or more processors to

obtain governance for a tenant of a cloud provider where the tenant has a cloud application deployed with the cloud provider, wherein the governance includes (1) a plurality of security policies, each security policy defines a configuration and an expected value, and the plurality of security policies include a combination of out of the box policies and tenant-defined policies, (2) one or more compliance frameworks, each compliance framework includes one or more of the security policies (3) risk-based prioritization for describing risk of any misconfigurations, and (4) enforcement for any of the misconfigurations;

obtain configurations of the cloud application;

identify the misconfigurations of the cloud application based on a comparison of the obtained configurations with the configurations of the plurality of security policies, wherein each of the security policies are assigned a status based on a number of compliant resources;

analyze the misconfigurations and status to determine risks including prioritization of the risks based on (1) their likelihood of exposure to security breaches and (2) the risk-based prioritization; and

cause remediation of the misconfigurations based on the determined risks and the enforcement,

wherein the node in the cloud-based system performs the CSPM service in addition to one or more additional cloud services.

9. The enforcement node of claim 8 , wherein the one or more additional cloud services include any of a cloud security service, a Cloud Access Security Broker (CASB) service, a Data Loss Prevention (DLP) service, and a Zero Trust Network Access (ZTNA) service.

10. The enforcement node of claim 8 , wherein the instructions that, when executed, cause the one or more processors to

cause display of any of a security posture, a compliance posture to the one or more compliance frameworks, a risk posture, and a data privacy posture.

11. The enforcement node of claim 8 , wherein the instructions that, when executed, cause the one or more processors to

determine a risk matrix for the tenant; and

cause display of the risk matrix, wherein the risk matrix visualizes risk based on a combination of impact and likelihood.

12. The enforcement node of claim 8 , wherein the tenant has a plurality of users that use the cloud application, and wherein the cloud application is deployed in a public cloud.

13. The enforcement node of claim 8 , wherein the plurality of security policies relate to both cloud infrastructure and the cloud application, wherein the security policies for the cloud infrastructure relate to how underlying cloud resources should be properly configured, and wherein the security policies for the cloud application relate to how the cloud application should be configured and used.

14. A method, implemented in a node in a cloud-based system, comprising:

obtaining governance for a tenant of a cloud provider where the tenant has a cloud application deployed with the cloud provider, wherein the governance includes (1) a plurality of security policies, each security policy defines a configuration and an expected value, and the plurality of security policies include a combination of out of the box policies and tenant-defined policies, (2) one or more compliance frameworks, each compliance framework includes one or more of the security policies, (3) risk-based prioritization for describing risk of any misconfigurations, and (4) enforcement for any of the misconfigurations;

obtaining configurations of the cloud application

identifying the misconfigurations of the cloud application based on a comparison of the obtained configurations with the configurations of the plurality of security policies, wherein each of the security policies are assigned a status based on a number of compliant resources;

analyzing the misconfigurations and status to determine risks including prioritization of the risks based on their (1) likelihood of exposure to security breaches and (2) the risk-based prioritization; and

causing remediation of the misconfigurations based on the determined risks and the enforcement,

wherein the cloud-based system performs the CSPM service in addition to one or more additional cloud services.

15. The method of claim 14 , wherein the one or more additional cloud services include any of a cloud security service, a Cloud Access Security Broker (CASB) service, a Data Loss Prevention (DLP) service, and a Zero Trust Network Access (ZTNA) service.

16. The method of claim 14 , further comprising

causing display of any of a security posture, a compliance posture to the one or more compliance frameworks, a risk posture, and a data privacy posture.

17. The method of claim 14 , further comprising

determining a risk matrix for the tenant; and

causing display of the risk matrix, wherein the risk matrix visualizes risk based on a combination of impact and likelihood.

18. The method of claim 14 , wherein the tenant has a plurality of users that use the cloud application, and wherein the cloud application is deployed in a public cloud.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2020
From: PANDURANGI, GURURAJ; KULKARNI, PRAVIN; KHENGARE, RAHUL; MESHRAM, UNMESH; YADAV, SANTOSH KUMAR ABHAYRAJ; AGRAWAL, SHRADDHA; RAO, ANKIT; KONDEKAR, HIMALAY; JAJU, GIRISH MURLIDHAR
To: ZSCALER, INC.
Reel/Frame 053840/0082 →
Priority Claims (1)
IN 202011033837 · Aug 7, 2020 · national
Continuity (1)
Related Publication 20220046059A1 · Feb 10, 2022
Cited By (1)
US 12,726,489