IP Library › Granted Patent US 12,452,293
Granted Patent B1
US 12,452,293 · App. 19/070,154 · Granted Oct 21, 2025

Detection of stale data objects and associated cybersecurity risk

Inventors: Matilda Lidgi (Haifa, IL); Liron Levin (Kfar Saba, IL)
Assignee: Wiz, Inc.
H04L63/1433G06F9/45558G06F2009/45562G06F2009/4557
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,293
App. No.
19/070,154
Granted
Oct 21, 2025
Kind
B1
Abstract

A system and method for detecting stale objects in a cloud computing environment is presented. The method includes detecting a plurality of resources deployed in a cloud computing environment; generating for each resource a representation in a security database, the security database including a representation of the cloud computing environment; generating for each resource a state, based at least on a detected utilization of a respective resource; detecting, based on the state, a resource of the plurality of resources which is an underutilized resource; and initiating a mitigation action on the underutilized resource.

Claims (57)

1. A method for detecting underutilized objects in a cloud computing environment, comprising:

detecting a plurality of resources deployed in a cloud computing environment;

generating for each resource a representation in a security database, the security database including a representation of the cloud computing environment;

generating for each resource a state, based at least on a detected utilization of a respective resource;

detecting, based on the state, a resource of the plurality of resources which is an underutilized resource; and

initiating a mitigation action to disable a permission associated with a principal of the resource on the underutilized resource.

2. The method of claim 1 , further comprising:

generating in the security database an edge connecting a first representation to a second representation, based on at least a detected permission.

3. The method of claim 2 , further comprising:

detecting the underutilized resource in the security database based on a number of edges of a representation of the underutilized resource.

4. The method of claim 2 , further comprising:

detecting a group of representations in the security database wherein each representation of the group is not connected to a representation outside of the group; and

detecting the underutilized resource in the group of representations.

5. The method of claim 4 , further comprising:

determining that a number of representations in the group of representations is below a first threshold; and

determining that each resource represented in the group of representations is an underutilized resource.

6. The method of claim 5 , further comprising:

initiating a mitigation action on each resource represented in the group of representations.

7. The method of claim 1 , further comprising:

detecting a utilization of a resource based on an event log, the event log including a plurality of events, each event stored as a data record, at least a portion of which include an identifier of a resource.

8. The method of claim 1 , further comprising:

initiating the mitigation action to deprovision the underutilized resource.

9. The method of claim 1 , further comprising:

initiating the mitigation action to move the underutilized resource to a second computing environment.

10. A non-transitory computer-readable medium storing a set of instructions for detecting underutilized objects in a cloud computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

detect a plurality of resources deployed in a cloud computing environment;

generate for each resource a representation in a security database, the security database including a representation of the cloud computing environment;

generate for each resource a state, based at least on a detected utilization of a respective resource;

detect, based on the state, a resource of the plurality of resources which is an underutilized resource; and

initiate a mitigation action to disable a permission associated with a principal of the resource on the underutilized resource.

11. A system for detecting underutilized objects in a cloud computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a plurality of resources deployed in a cloud computing environment;

generate for each resource a representation in a security database, the security database including a representation of the cloud computing environment;

generate for each resource a state, based at least on a detected utilization of a respective resource;

detect, based on the state, a resource of the plurality of resources which is an underutilized resource; and

initiate a mitigation action to disable a permission associated with a principal of the resource on the underutilized resource.

12. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate in the security database an edge connecting a first representation to a second representation, based on at least a detected permission.

13. The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the underutilized resource in the security database based on a number of edges of a representation of the underutilized resource.

14. The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a group of representations in the security database wherein each representation of the group is not connected to a representation outside of the group; and

detect the underutilized resource in the group of representations.

15. The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine that a number of representations in the group of representations is below a first threshold; and

determine that each resource represented in the group of representations is an underutilized resource.

16. The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate a mitigation action on each resource represented in the group of representations.

17. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a utilization of a resource based on an event log, the event log including a plurality of events, each event stored as a data record, at least a portion of which include an identifier of a resource.

18. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate the mitigation action to deprovision the underutilized resource.

19. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate the mitigation action to move the underutilized resource to a second computing environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2025
From: LIDGI, MATILDA; LEVIN, LIRON
To: WIZ, INC.
Reel/Frame 071371/0558 →
References Cited (10)
US 11153331B2 · Zou et al. · 2021 [cited by applicant]
US 11775640B1 · Sathe · 2023 [cited by examiner]
US 20140149354A1 · Chan · 2014 [cited by examiner]
US 20140359091A1 · Senniappan · 2014 [cited by examiner]
US 20160285906A1 · Fine · 2016 [cited by examiner]
US 20170147399A1 · Cropper · 2017 [cited by examiner]
US 20210216345A1 · Natu · 2021 [cited by examiner]
US 20220407907A1 · Cheng · 2022 [cited by examiner]
US 20230176886A1 · Lal · 2023 [cited by examiner]
US 20240273203A1 · Raca et al. · 2024 [cited by applicant]