IP Library Granted Patent US 12,468,807
Granted Patent B1
US 12,468,807 · App. 19/188,648 · Granted Nov 11, 2025

Techniques for control plane level containment

Inventors: Ron Konigsberg (Tel Aviv, IL); Matan Haim (Tel Aviv, IL); Itay Harel (Tel Aviv, IL); Itamar Gilad (Tel Aviv, IL); Arik Nemtsov (New York, NY)
Assignee: Wiz, Inc.
G06F21/562G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,468,807
App. No.
19/188,648
Filed
Apr 24, 2025
Granted
Nov 11, 2025
Kind
B1
Art Unit
2435
USPC
726/24
Abstract

A method and system for control plane containment of cybersecurity threat is presented. The method includes generating at least a detection rule for application by a sensor configured to detect events; configuring the sensor to deploy on a resource in a cloud computing environment, and deploying the sensor on the resource, wherein the sensor is configured to: apply the at least a detection rule on a detected event; detect an event which triggers the at least a detection rule, the event corresponding to a process running on the resource; and halt execution of the process.

Claims (54)

1 . A method for control plane containment of cybersecurity threats, comprising:

generating at least a detection rule for application by a sensor configured to detect events;

configuring the sensor to deploy on a resource in a cloud computing environment;

generating the at least a detection rule based on static analysis of a code object utilized in deploying the resource;

deploying the sensor on the resource, wherein the sensor is configured to:

apply the at least a detection rule on a detected event;

detect an event which triggers the at least a detection rule, the event corresponding to a process running on the resource; and

halt execution of the process.

2 . The method of claim 1 , further comprising:

generating the at least a detection rule based on a determined state of the resource.

3 . The method of claim 1 , further comprising:

configuring the sensor to detect runtime data, wherein runtime data includes any one of: a state of a resource, a cloud entity, a component, an application, and any combination thereof.

4 . The method of claim 1 , further comprising:

applying the at least a detection rule to an event based on comparing data of the detected event with a predefined condition of the at least a detection rule.

5 . The method of claim 1 , further comprising:

configuring the sensor to deploy on any one of: a virtual machine, a software container, a serverless function, and any combination thereof.

6 . The method of claim 1 , further comprising:

configuring the sensor to perform any one of: real-time tracing of system calls, monitor resource usage, and any combination thereof.

7 . The method of claim 6 , further comprising:

configuring the sensor to perform a mitigation action in response to detecting a potential threat based on an event which triggers the at least a detection rule.

8 . The method of claim 7 , wherein a mitigation action includes any one of: halting an execution of a process running on a resource, isolating a system, modifying a permission, disabling a compromised account, blocking an unauthorized user, and any combination thereof.

9 . A non-transitory computer-readable medium storing a set of instructions for control plane containment of cybersecurity threats, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

generate at least a detection rule for application by a sensor configured to detect events;

configure the sensor to deploy on a resource in a cloud computing environment;

generate the at least a detection rule based on static analysis of a code object utilized in deploying the resource;

deploy the sensor on the resource, wherein the sensor is configured to:

apply the at least a detection rule on a detected event

detect an event which triggers the at least a detection rule, the event correspond to a process running on the resource; and

halt execution of the process.

10 . A system for control plane containment of cybersecurity threats comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

generate at least a detection rule for application by a sensor configured to detect events;

configure the sensor to deploy on a resource in a cloud computing environment;

generate the at least a detection rule based on static analysis of a code object utilized in deploying the resource;

deploy the sensor on the resource, wherein the sensor is configured to:

apply the at least a detection rule on a detected event

detect an event which triggers the at least a detection rule, the event correspond to a process running on the resource; and

halt execution of the process.

11 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the at least a detection rule based on a determined state of the resource.

12 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure the sensor to detect runtime data, wherein runtime data includes any one of: a state of a resource, a cloud entity, a component, an application, and any combination thereof.

13 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the at least a detection rule to an event based on comparing data of the detected event with a predefined condition of the at least a detection rule.

14 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure the sensor to deploy on any one of: a virtual machine, a software container, a serverless function, and any combination thereof.

15 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure the sensor to perform any one of: real-time trace of system calls, monitor resource usage, and any combination thereof.

16 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure the sensor to perform a mitigation action in response to detecting a potential threat based on an event which triggers the at least a detection rule.

17 . The system of claim 16 , wherein a mitigation action includes any one of:

halting an execution of a process running on a resource, isolating a system, modifying a permission, disabling a compromised account, blocking an unauthorized user, and any combination thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2025
From: KONIGSBERG, RON; HAIM, MATAN; HAREL, ITAY; GILAD, ITAMAR; NEMTSOV, ARIK
To: WIZ, INC.
Reel/Frame 072043/0550 →
References Cited (26)
US 10032026B1 · Xu · 2018 [cited by examiner]
US 10205733B1 · Park · 2019 [cited by examiner]
US 10250619B1 · Park · 2019 [cited by examiner]
US 10574683B1 · Ghosh · 2020 [cited by examiner]
US 10872145B2 · Brown et al. · 2020 [cited by applicant]
US 10893059B1 · Aziz · 2021 [cited by examiner]
US 11316900B1 · Schottland · 2022 [cited by examiner]
US 11397808B1 · Prabhu · 2022 [cited by examiner]
US 11513782B1 · Landry · 2022 [cited by examiner]
US 11575563B2 · Woolward et al. · 2023 [cited by applicant]
US 11736525B1 · Rungta · 2023 [cited by examiner]
US 12309182B1 · McAleer · 2025 [cited by examiner]
US 20170300690A1 · Ladnai · 2017 [cited by examiner]
US 20170310692A1 · Ackerman · 2017 [cited by examiner]
US 20190102551A1 · Zimmermann · 2019 [cited by examiner]
US 20190196939A1 · Lengauer · 2019 [cited by examiner]
US 20190342150A1 · Smith · 2019 [cited by examiner]
US 20200244695A1 · Veselov · 2020 [cited by examiner]
US 20220114262A1 · Bhatia · 2022 [cited by examiner]
US 20220247678A1 · Atwal et al. · 2022 [cited by applicant]
US 20230054226A1 · Gross · 2023 [cited by examiner]
US 20240220634A1 · Benameur · 2024 [cited by examiner]
US 20240273179A1 · Gupta · 2024 [cited by examiner]
US 20240281530A1 · Carru · 2024 [cited by examiner]
US 20240291863A1 · Cohen · 2024 [cited by examiner]
US 20240422258A1 · Gottfurcht · 2024 [cited by examiner]