IP Library › Granted Patent US 12,563,054
Granted Patent B2
US 12,563,054 · App. 18/146,065 · Granted Feb 24, 2026

Detecting malware infection path in a cloud computing environment utilizing a security graph

Inventors: Elad Gabay (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Roy Reznik (Tel Aviv, IL); Yaniv Shaked (Tel Aviv, IL); Alon Schindel (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,054
App. No.
18/146,065
Granted
Feb 24, 2026
Kind
B2
Abstract

A system and method provide detection of a malware attack path. The method includes detecting at a first time a malware object on a first workload deployed in the compute environment, wherein the first workload is represented by a first node in a security graph, the security graph including a representation of the compute environment; querying the security graph to detect a second node connected to the first node, wherein the connection indicates that the first workload represented by the first node can access a second workload represented by the second node; and generating an instruction to inspect the second workload represented by the second node at a second time, occurring after the first time.

Claims (57)

1 . A method for detecting a malware attack path in a compute environment, comprising:

detecting at a first time a malware object on a first workload deployed in the compute environment, wherein the first workload is represented by a first node in a security graph, the security graph including a representation of the compute environment including a plurality of nodes representing principals and resources of the compute environment;

querying the security graph to detect a malware attack path between the first node and an endpoint node;

identifying a second node connected to the first node on the malware attack path, wherein the connection indicates that the first workload represented by the first node is authorized to access a second workload represented by the second node; and

generating an instruction to inspect the second workload represented by the second node at a second time, occurring after the first time.

2 . The method of claim 1 , further comprising:

generating a plurality of malware attack paths, each malware attack path associated with an identifier of a secondary node representing a workload of the compute environment, wherein the secondary node is connected to the first node with a vertex indicating that the first workload represented by the first node can access the workload represented by the secondary node; and

generating a malware attack path output, including a workload identifier of the workload represented by the secondary node.

3 . The method of claim 2 , wherein a malware attack path further includes an identifier of a tertiary node connected to the second node with a vertex indicating that the workload represented by the second node can access a workload represented by the tertiary node.

4 . The method of claim 2 , further comprising:

generating an instruction to inspect a workload represented by any one of: the secondary node, and a tertiary node.

5 . The method of claim 4 , further comprising:

generating the instruction to inspect a workload represented by the secondary node at a second time which occurs after the first time; and

generating the instruction to inspect a workload represented by the tertiary node at a third time which occurs after the second time.

6 . The method of claim 1 , further comprising:

detecting the malware object on the second workload based on executing the instruction to inspect the second workload; and

determining that the second workload is on the malware attack path of the malware object, in response to detecting the malware object at the second time which is after the malware object is detected on the first workload at the first time.

7 . The method of claim 1 , further comprising:

generating an instruction to periodically inspect a plurality of workloads in the malware attack path, including the second workload for the malware object.

8 . The method of claim 1 , further comprising:

detecting the malware object based on a signature of the malware object.

9 . The method of claim 8 , wherein the signature is generated based on computer code of the malware object.

10 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

detecting at a first time a malware object on a first workload deployed in a compute environment, wherein the first workload is represented by a first node in a security graph, the security graph including a representation of the compute environment including a plurality of nodes representing principals and resources of the compute environment;

querying the security graph to detect a malware attack path between the first node and an endpoint node;

identifying a second node connected to the first node on the malware attack path, wherein the connection indicates that the first workload represented by the first node is authorized to access a second workload represented by the second node; and

generating an instruction to inspect the second workload represented by the second node at a second time, occurring after the first time.

11 . The method of claim 1 , further comprising:

generating an inspectable disk from a storage volume associated with the second workload; and

performing the instruction to inspect on the inspectable disk.

12 . A system for detecting a malware attack path in a compute environment, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect at a first time a malware object on a first workload deployed in the compute environment, wherein the first workload is represented by a first node in a security graph, the security graph including a representation of the compute environment including a plurality of nodes representing principals and resources of the compute environment;

query the security graph to detect a malware attack path between the first node and an endpoint node;

identify a second node connected to the first node on the malware attack path, wherein the connection indicates that the first workload represented by the first node is authorized to access a second workload represented by the second node; and

generate an instruction to inspect the second workload represented by the second node at a second time, occurring after the first time.

13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a plurality of malware attack paths, each malware attack path associated with an identifier of a secondary node representing a workload of the compute environment, wherein the secondary node is connected to the first node with a vertex indicating that the first workload represented by the first node can access the workload represented by the secondary node; and

generate a malware attack path output, including a workload identifier of the workload represented by the secondary node.

14 . The system of claim 13 , wherein the malware attack path further includes an identifier of a tertiary node connected to the second node with a vertex indicating that the workload represented by the second node can access a workload represented by the tertiary node.

15 . The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate an instruction to inspect a workload represented by any one of: the secondary node, and a tertiary node.

16 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the instruction to inspect a workload represented by the secondary node at a second time which occurs after the first time; and

generate the instruction to inspect a workload represented by the tertiary node at a third time which occurs after the second time.

17 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the malware object on the second workload based on executing the instruction to inspect the second workload; and

determine that the second workload is on the malware attack path of the malware object, in response to detecting the malware object at the second time which is after the malware object is detected on the first workload at the first time.

18 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate an instruction to periodically inspect a plurality of workloads in the malware attack path, including the second workload for the malware object.

19 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the malware object based on a signature of the malware object.

20 . The system of claim 19 , wherein the signature is generated based on computer code of the malware object.

21 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate an inspectable disk from a storage volume associated with the second workload; and

perform the instruction to inspect on the inspectable disk.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2023
From: GABAY, ELAD; LUTTWAK, AMI; REZNIK, ROY; SHAKED, YANIV; SCHINDEL, ALON
To: WIZ, INC.
Reel/Frame 062458/0062 →
Continuity (2)
Provisional Application 63266032 · Dec 27, 2021
Related Publication 20230208862A1 · Jun 29, 2023
References Cited (13)
US 8499354B1 · Satish et al. · 2013 [cited by applicant]
US 9165142B1 · Sanders et al. · 2015 [cited by applicant]
US 9542556B2 · Sanders · 2017 [cited by examiner]
US 9749336B1 · Zhang · 2017 [cited by examiner]
US 9838405B1 · Guo · 2017 [cited by examiner]
US 10389738B2 · Muddu · 2019 [cited by examiner]
US 11374982B1 · Keren · 2022 [cited by examiner]
US 20110035802A1 · Arajujo, Jr. · 2011 [cited by examiner]
US 20130024940A1 · Hutchins et al. · 2013 [cited by applicant]
US 20180219888A1 · Apostolopoulos · 2018 [cited by examiner]
US 20220237303A1 · Inokuchi · 2022 [cited by examiner]
WO WO2012061663A2 · 2012 [cited by examiner]
Hellal et al., ‘A survey on graph-based methods for malware detection’, Dec. 15, 2020, IEEE, 2020 4th International Conference on Advanced Systems and Emergent Technologies (IC_ASET) (2020, pp. 130-134) (Year: 2020). [cited by examiner]