IP Library › Granted Patent US 12,255,948
Granted Patent B2
US 12,255,948 · App. 18/888,981 · Granted Mar 18, 2025

System and method for analyzing network objects in a cloud environment

Inventors: Shai Keren (Oporto, PT); Daniel Hershko Shemesh (Givat-Shmuel, IL); Roy Reznik (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Avihai Berkovitz (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L67/10H04L41/046H04L41/5096H04L49/70H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,948
App. No.
18/888,981
Granted
Mar 18, 2025
Kind
B2
Abstract

A method and system for providing textual insights on objects deployed in a cloud environment are provided. The method includes collecting object data on objects deployed in the cloud environment, wherein objects are deployed and operable at different layers of the cloud environment; identifying objects deployed in the cloud environment; constructing a visual representation of the cloud environment, including the identified objects and their relationships; and generating textual insights on the identified objects and their relationships using natural language processing.

Claims (61)

1. A method for determining exposure of vulnerable network objects having cyber-threats, comprising:

collecting network object data on a plurality of network objects deployed in a cloud computing environment;

constructing a network graph based on the collected network object data, wherein the network graph includes a visual representation of network objects identified in the cloud computing environment;

determining relationships between the identified network objects in the network graph, wherein the determined relationships between the identified network objects includes descriptions of connections between the identified network objects;

analyzing the network graph and the determined relationships to generate insights, wherein the generated insights include at least a route between an identified network object and an external network; and

tagging network objects in the network graph for which the insight is generated.

2. The method of claim 1 , further comprising:

determining a number of transmissions based on a route between a first identified network object and the external network; and

generating a visual indication of the number of transmissions.

3. The method of claim 2 , further comprising:

determining an order of transmission between the identified network objects; and

populating the network graph with a data path based on the determined order of transmission and the determined route.

4. The method of claim 1 , further comprising:

generating a list including each network object in the route between an identified network object and the external network.

5. The method of claim 4 , further comprising:

determining an order of transmission between the identified network objects; and

generating the list further based on the determined order of transmission.

6. The method of claim 5 , further comprising:

generating a visual representation of the generated list.

7. The method of claim 1 , further comprising:

populating the network graph with a data path between the identified network object and a destination network object, wherein the identified network object is exposed to the external network.

8. The method of claim 7 , further comprising:

determining an order of transmission between the identified network object and the destination network object; and

populating the network graph with the data path further based on the determined order of transmission.

9. The method of claim 1 , further comprising:

generating an alert based on the generated insights.

10. A non-transitory computer-readable medium storing a set of instructions for determining exposure of vulnerable network objects having cyber-threats, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

collect network object data on a plurality of network objects deployed in a cloud computing environment;

construct a network graph based on the collected network object data, wherein the network graph includes a visual representation of network objects identified in the cloud computing environment;

determine relationships between the identified network objects in the network graph, wherein the determined relationships between the identified network objects includes descriptions of connections between the identified network objects;

analyze the network graph and the determined relationships to generate insights, wherein the generated insights include at least a route between an identified network object and an external network; and

tag network objects in the network graph for which the insight is generated.

11. A system for determining exposure of vulnerable network objects having cyber-threats comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

collect network object data on a plurality of network objects deployed in a cloud computing environment;

construct a network graph based on the collected network object data, wherein the network graph includes a visual representation of network objects identified in the cloud computing environment;

determine relationships between the identified network objects in the network graph, wherein the determined relationships between the identified network objects includes descriptions of connections between the identified network objects;

analyze the network graph and the determined relationships to generate insights, wherein the generated insights include at least a route between an identified network object and an external network; and

tag network objects in the network graph for which the insight is generated.

12. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine a number of transmissions based on a route between a first identified network object and the external network; and

generate a visual indication of the number of transmissions.

13. The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine an order of transmission between the identified network objects; and

populate the network graph with a data path based on the determined order of transmission and the determined route.

14. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a list including each network object in the route between an identified network object and the external network.

15. The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine an order of transmission between the identified network objects; and

generate the list further based on the determined order of transmission.

16. The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a visual representation of the generated list.

17. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

populate the network graph with a data path between the identified network object and a destination network object, wherein the identified network object is exposed to the external network.

18. The system of claim 17 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine an order of transmission between the identified network object and the destination network object; and

populate the network graph with the data path further based on the determined order of transmission.

19. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate an alert based on the generated insights.

Continuity (7)
Continuation 18887753 · Sep 17, 2024
Continuation 18479573 · Oct 2, 2023
Continuation 18478534 · Sep 29, 2023
Continuation 18341134 · Jun 26, 2023
Continuation 17819442 · Aug 12, 2022
Continuation 17109883 · Dec 2, 2020
Related Publication 20250016222A1 · Jan 9, 2025
References Cited (21)
US 7392539B2 · Brooks · 2008 [cited by examiner]
US 9210185B1 · Pinney Wood et al. · 2015 [cited by applicant]
US 10171300B2 · Eggen · 2019 [cited by examiner]
US 10924347B1 · Narsian · 2021 [cited by examiner]
US 10977587B2 · Khalili · 2021 [cited by applicant]
US 11709944B2 · Salji · 2023 [cited by applicant]
US 20040019803A1 · Jahn · 2004 [cited by applicant]
US 20140157417A1 · Grubel · 2014 [cited by examiner]
US 20160044057A1 · Chenette et al. · 2016 [cited by applicant]
US 20160048556A1 · Kelly · 2016 [cited by examiner]
US 20160359872A1 · Yadav · 2016 [cited by examiner]
US 20160373944A1 · Jain · 2016 [cited by examiner]
US 20170075981A1 · Carlsson · 2017 [cited by examiner]
US 20180024981A1 · Xia · 2018 [cited by examiner]
US 20190095530A1 · Booker · 2019 [cited by examiner]
US 20200252461A1 · Xu et al. · 2020 [cited by applicant]
US 20200267175A1 · Atighetchi et al. · 2020 [cited by applicant]
US 20200322227A1 · Janakiraman · 2020 [cited by examiner]
US 20200374343A1 · Novotny · 2020 [cited by examiner]
US 20200382539A1 · Janakiraman · 2020 [cited by examiner]
US 20230008765A1 · Kazato · 2023 [cited by applicant]