IP Library › Granted Patent US 12,563,058
Granted Patent B1
US 12,563,058 · App. 19/224,127 · Granted Feb 24, 2026

Techniques for cross entity correlation of user accounts in cloud computing environments

Inventors: Ron Konigsberg (Tel Aviv, IL); Itay Harel (Tel Aviv, IL); Dan Becker (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,058
App. No.
19/224,127
Filed
May 30, 2025
Granted
Feb 24, 2026
Kind
B1
Art Unit
2435
USPC
726/23
Abstract

A system and method for cross-entity correlation of software containers in a cloud computing environment is presented. The method includes detecting in a log an event record related to a software container platform utilized in a cloud computing environment; extracting from the event record a software container identifier and a principal identifier; cross-referencing the software container identifier with a unique software container identifier list based at least on the principal identifier; associating in a security database the event record and the unique software container identifier; and applying a control based on the event record and the unique software container identifier.

Claims (55)

1 . A method for cross-entity correlation of software containers in a cloud computing environment, comprising:

detecting in a log an event record related to a software container platform utilized in a cloud computing environment;

extracting from the event record a software container identifier and a principal identifier;

cross-referencing the software container identifier with a unique software container identifier list based at least on the principal identifier;

associating in a security database the event record and the unique software container identifier; and

applying a control based on the event record and the unique software container identifier.

2 . The method of claim 1 , further comprising:

applying the control only on a software container corresponding to the software container identifier.

3 . The method of claim 2 , further comprising:

applying the control to halt execution of a process on the software container.

4 . The method of claim 2 , further comprising:

applying the control to detect a cybersecurity risk associated with the software container.

5 . The method of claim 1 , further comprising:

deploying a runtime sensor in the software container platform, the runtime sensor configured to detect runtime events;

detecting the event record utilizing the runtime sensor.

6 . The method of claim 1 , further comprising:

applying the control to detect a cybersecurity risk.

7 . The method of claim 6 , further comprising:

detecting the cybersecurity risk in response to determining that a plurality of events are each associated with a unique software container corresponding to the unique software.

8 . The method of claim 6 , further comprising:

determining that there is no cybersecurity risk in response to determining that a plurality of events associated with the software container platform are each associated with a different software container of the software container platform.

9 . The method of claim 6 , further comprising:

initiating a remediation action in the software container platform.

10 . A non-transitory computer-readable medium storing a set of instructions for cross-entity correlation of software containers in a cloud computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

detect in a log an event record related to a software container platform utilized in a cloud computing environment;

extract from the event record a software container identifier and a principal identifier;

cross-reference the software container identifier with a unique software container identifier list based at least on the principal identifier;

associate in a security database the event record and the unique software container identifier; and

apply a control based on the event record and the unique software container identifier.

11 . A system for cross-entity correlation of software containers in a cloud computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect in a log an event record related to a software container platform utilized in a cloud computing environment;

extract from the event record a software container identifier and a principal identifier;

cross-reference the software container identifier with a unique software container identifier list based at least on the principal identifier;

associate in a security database the event record and the unique software container identifier; and

apply a control based on the event record and the unique software container identifier.

12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the control only on a software container corresponding to the software container identifier.

13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the control to halt execution of a process on the software container.

14 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the control to detect a cybersecurity risk associated with the software container.

15 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

deploy a runtime sensor in the software container platform, the runtime sensor configured to detect runtime events; and

detect the event record utilizing the runtime sensor.

16 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the control to detect a cybersecurity risk.

17 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the cybersecurity risk in response to determining that a plurality of events are each associated with a unique software container corresponding to the unique software.

18 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine that there is no cybersecurity risk in response to determining that a plurality of events associated with the software container platform are each associated with a different software container of the software container platform.

19 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate a remediation action in the software container platform.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2025
From: KONIGSBERG, RON; HAREL, ITAY; BECKER, DAN
To: WIZ, INC.
Reel/Frame 072603/0382 →
References Cited (9)
US 10419463B2 · Muddu · 2019 [cited by examiner]
US 11074218B2 · Faith · 2021 [cited by examiner]
US 11151268B2 · Daniel · 2021 [cited by examiner]
US 11334833B2 · Friske · 2022 [cited by examiner]
US 20120137283A1 · Antill · 2012 [cited by examiner]
US 20180260574A1 · Morello · 2018 [cited by examiner]
US 20200034133A1 · Dattatri · 2020 [cited by examiner]
US 20220231985A1 · Rapaport et al. · 2022 [cited by applicant]
US 20240386349A1 · Barton · 2024 [cited by examiner]
Cited By (1)
US 12,706,958