IP Library › Granted Patent US 12,411,950
Granted Patent B2
US 12,411,950 · App. 19/058,833 · Granted Sep 9, 2025

Techniques for semantic analysis of cybersecurity event data and remediation of cybersecurity event root causes

Inventors: Tomer Schwartz (Tel Aviv, IL); Eshel Yaron (Amsterdam, NL); Barak Bercovitz (Even-Yehuda, IL)
Assignee: Wiz, Inc.
G06F21/554G06F8/70G06F16/245G06F16/9024G06F40/242G06F40/30G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,411,950
App. No.
19/058,833
Granted
Sep 9, 2025
Kind
B2
Abstract

A system and method for remediating cybersecurity events. A method includes creating a semantic concepts dictionary defining semantic concepts representing characteristics of software components. An entity graph is created based on correlations between entities, where the entity graph has nodes representing respective entities and the entities include software components of a software infrastructure as well as event logic components of cybersecurity event logic deployed with respect to the software infrastructure. A knowledge base is built such that the knowledge base includes the semantic concepts dictionary and the entity graph. The knowledge base is queried using a query generated based on one or more semantic concepts and one or more entity-identifying values extracted from cybersecurity event data. The query includes at least one semantic concept and at least one entity-identifying value. One or more remedial actions are performed based on one or more query results from the knowledge base.

Claims (50)

1. A method for remediating cybersecurity events, comprising:

creating a semantic concepts dictionary, wherein the semantic concepts dictionary defines a plurality of semantic concepts representing characteristics of software components;

creating an entity graph based on a plurality of correlations between entities among a plurality of entities, wherein the entity graph has a plurality of nodes representing respective entities of the plurality of entities, wherein the plurality of entities includes a plurality of software components of a software infrastructure and a plurality of event logic components of cybersecurity event logic deployed with respect to the software infrastructure;

building a knowledge base such that the knowledge base includes the semantic concepts dictionary and the entity graph;

querying the knowledge base using a query generated based on at least one semantic concept and at least one entity-identifying value extracted from cybersecurity event data indicating a cybersecurity event for the software infrastructure, wherein the knowledge base returns at least one query result, wherein the query includes at least one semantic concept and at least one entity-identifying value; and

performing at least one remedial action based on the at least one query result.

2. The method of claim 1 , wherein creating the entity graph further comprises:

embedding at least one entity-defining dataset into the entity graph, wherein each entity-defining dataset provides a plurality of explicit definitions of entity features.

3. The method of claim 1 , wherein the plurality of nodes includes data indicating software component characteristics.

4. The method of claim 1 , further comprising:

identifying at least one path in the entity graph based on the at least one query result, wherein each identified path is between one of the plurality of software components and one of the plurality of event logic components; and

identifying a root cause entity based on the identified at least one path, wherein the at least one remedial action is performed based further on the identified root cause entity.

5. The method of claim 1 , further comprising:

deriving the plurality of correlations by analyzing software development lifecycle pipeline data.

6. The method of claim 5 , wherein the plurality of correlations is derived based on references between software components among the plurality of software components indicated in the software development lifecycle pipeline data.

7. The method of claim 1 , further comprising:

linking source code to binaries of at least one application based on the plurality of correlations between the entities among the plurality of entities, wherein the entity graph is created based further on the linking of the source code to the binaries.

8. The method of claim 1 , wherein the plurality of correlations is identified based on an analysis of log files, wherein the analysis of the log files includes identifying at least one action and at least one event related to the at least one action indicated in a plurality of log files.

9. The method of claim 1 , further comprising:

performing natural language processing on the cybersecurity event data in order to identify the at least one semantic concept in the cybersecurity event data based on the plurality of semantic concepts defined in the semantic concepts dictionary; and

extracting the identified at least one semantic concept from the cybersecurity event data.

10. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

creating a semantic concepts dictionary, wherein the semantic concepts dictionary defines a plurality of semantic concepts representing characteristics of software components;

creating an entity graph based on a plurality of correlations between entities among a plurality of entities, wherein the entity graph has a plurality of nodes representing respective entities of the plurality of entities, wherein the plurality of entities includes a plurality of software components of a software infrastructure and a plurality of event logic components of cybersecurity event logic deployed with respect to the software infrastructure;

building a knowledge base such that the knowledge base includes the semantic concepts dictionary and the entity graph;

querying the knowledge base using a query generated based on at least one semantic concept and at least one entity-identifying value extracted from cybersecurity event data indicating a cybersecurity event for the software infrastructure, wherein the knowledge base returns at least one query result, wherein the query includes at least one semantic concept and at least one entity-identifying value; and

performing at least one remedial action based on the at least one query result.

11. A system for remediating cybersecurity events, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

create a semantic concepts dictionary, wherein the semantic concepts dictionary defines a plurality of semantic concepts representing characteristics of software components;

create an entity graph based on a plurality of correlations between entities among a plurality of entities, wherein the entity graph has a plurality of nodes representing respective entities of the plurality of entities, wherein the plurality of entities includes a plurality of software components of a software infrastructure and a plurality of event logic components of cybersecurity event logic deployed with respect to the software infrastructure;

build a knowledge base such that the knowledge base includes the semantic concepts dictionary and the entity graph;

query the knowledge base using a query generated based on at least one semantic concept and at least one entity-identifying value extracted from cybersecurity event data indicating a cybersecurity event for the software infrastructure, wherein the knowledge base returns at least one query result, wherein the query includes at least one semantic concept and at least one entity-identifying value; and

perform at least one remedial action based on the at least one query result.

12. The system of claim 11 , wherein the system is further configured to:

embed at least one entity-defining dataset into the entity graph, wherein each entity-defining dataset provides a plurality of explicit definitions of entity features.

13. The system of claim 11 , wherein the plurality of nodes includes data indicating software component characteristics.

14. The system of claim 11 , wherein the system is further configured to:

identify at least one path in the entity graph based on the at least one query result, wherein each identified path is between one of the plurality of software components and one of the plurality of event logic components; and

identify a root cause entity based on the identified at least one path, wherein the at least one remedial action is performed based further on the identified root cause entity.

15. The system of claim 11 , wherein the system is further configured to:

derive the plurality of correlations by analyzing software development lifecycle pipeline data.

16. The system of claim 15 , wherein the plurality of correlations is derived based on references between software components among the plurality of software components indicated in the software development lifecycle pipeline data.

17. The system of claim 11 , wherein the system is further configured to:

link source code to binaries of at least one application based on the plurality of correlations between the entities among the plurality of entities, wherein the entity graph is created based further on the linking of the source code to the binaries.

18. The system of claim 11 , wherein the plurality of correlations is identified based on an analysis of log files, wherein the analysis of the log files includes identifying at least one action and at least one event related to the at least one action indicated in a plurality of log files.

19. The system of claim 11 , wherein the system is further configured to:

perform natural language processing on the cybersecurity event data in order to identify the at least one semantic concept in the cybersecurity event data based on the plurality of semantic concepts defined in the semantic concepts dictionary; and

extract the identified at least one semantic concept from the cybersecurity event data.

Continuity (2)
Continuation 17507180 · Oct 21, 2021
Related Publication 20250190555A1 · Jun 12, 2025
References Cited (63)
US 8806425B1 · Willis et al. · 2014 [cited by applicant]
US 9052961B2 · Mangtani et al. · 2015 [cited by applicant]
US 9449042B1 · Evans et al. · 2016 [cited by applicant]
US 10108803B2 · Chari · 2018 [cited by examiner]
US 11429353B1 · Liguori et al. · 2022 [cited by applicant]
US 11893106B2 · Kim et al. · 2024 [cited by applicant]
US 20030131284A1 · Flanagan et al. · 2003 [cited by applicant]
US 20090222479A1 · Burukhin et al. · 2009 [cited by applicant]
US 20100070448A1 · Omoigui · 2010 [cited by applicant]
US 20130167241A1 · Siman · 2013 [cited by applicant]
US 20150341214A1 · Croy et al. · 2015 [cited by applicant]
US 20150347759A1 · Cabrera · 2015 [cited by examiner]
US 20150363197A1 · Carback et al. · 2015 [cited by applicant]
US 20160379480A1 · OlmstedThompson et al. · 2016 [cited by applicant]
US 20170075749A1 · Ambichl et al. · 2017 [cited by applicant]
US 20170185785A1 · Vorona et al. · 2017 [cited by applicant]
US 20170249128A1 · Fojtik et al. · 2017 [cited by applicant]
US 20170286692A1 · Nakajima et al. · 2017 [cited by applicant]
US 20180025160A1 · Hwang et al. · 2018 [cited by applicant]
US 20180129479A1 · McPherson et al. · 2018 [cited by applicant]
US 20180285199A1 · Mitkar et al. · 2018 [cited by applicant]
US 20180321918A1 · Mcclory et al. · 2018 [cited by applicant]
US 20180373507A1 · Mizrahi et al. · 2018 [cited by applicant]
US 20190007290A1 · He et al. · 2019 [cited by applicant]
US 20190068622A1 · Lin et al. · 2019 [cited by applicant]
US 20190294477A1 · Koppes et al. · 2019 [cited by applicant]
US 20190303579A1 · Reddy et al. · 2019 [cited by applicant]
US 20190354389A1 · Du et al. · 2019 [cited by applicant]
US 20200097662A1 · Hufsmith et al. · 2020 [cited by applicant]
US 20200183766A1 · Kumar-Mayernik et al. · 2020 [cited by applicant]
US 20200296117A1 · Karpovsky et al. · 2020 [cited by applicant]
US 20210042096A1 · White, III et al. · 2021 [cited by applicant]
US 20210168165A1 · Alsaeed et al. · 2021 [cited by applicant]
US 20210182387A1 · Zhu et al. · 2021 [cited by applicant]
US 20210311855A1 · Khan et al. · 2021 [cited by applicant]
US 20210382997A1 · Yi et al. · 2021 [cited by applicant]
US 20220114023A1 · Choksi et al. · 2022 [cited by applicant]
US 20220129539A1 · Walsh et al. · 2022 [cited by applicant]
US 20220311794A1 · Maya et al. · 2022 [cited by applicant]
US 20220327220A1 · Sharma et al. · 2022 [cited by applicant]
US 20220353341A1 · Östrand et al. · 2022 [cited by applicant]
US 20230036739A1 · Deppisch et al. · 2023 [cited by applicant]
US 20230118065A1 · Kumar · 2023 [cited by applicant]
US 20230229781A1 · Stolbikov et al. · 2023 [cited by applicant]
US 20230297366A1 · Wigglesworth et al. · 2023 [cited by applicant]
US 20230333845A1 · Zand et al. · 2023 [cited by applicant]
US 20250013442A1 · Hempstead et al. · 2025 [cited by applicant]
EP 3208996A1 · 2017 [cited by applicant]
EP 3494506A1 · 2019 [cited by applicant]
WO 2023067423A1 · 2023 [cited by applicant]
Doan TP, Jung S. Davs: Dockerfile Analysis for Container Image Vulnerability Scanning. CMC—Computers Materials & Continua. Jan. 1, 2022;72(1):1699-711. Jan. 1, 2022 (Jan. 1, 2022). [cited by applicant]
International Search Report for PCT Application No. PCT/IB2022/059483. The International Bureau of WIPO. [cited by applicant]
International Search Report for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
International Search Report for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
International Search Report, PCT/IB2023/052415; Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the International Searching Authority for PCT Application No. PCT/IB2022/059483 dated Jan. 8, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the International Searching Authority, PCT/IB2023/052415. Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the Searching Authority for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
International Search Report for PCT/IB2025/051650, dated May 26, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2025/051650, dated May 26, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Alrabaee, “A Survey of Binary Code Fingerprinting Approaches: Taxonomy, Methodologies, and Features”, 2022, ACM (Year: 2022). [cited by applicant]
Liu, “Vfdetect: A Vulnerable Code Clone Detection System Based on Vulnerability Fingerprint”, 2017, IEEE (Year: 2017). [cited by applicant]