IP Library › Granted Patent US 12,572,665
Granted Patent B1
US 12,572,665 · App. 18/488,635 · Granted Mar 10, 2026

System and method for generating a security graph in a cloud computing environment

Inventors: Avihai Berkovitz (Tel Aviv, IL); Raaz Herzberg (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Roy Reznik (Tel Aviv, IL); Shai Keren (Tel Aviv, IL); Yinon Costica (Tel Aviv, IL)
Assignee: Wiz, Inc.
G06F21/577G06F21/604G06F21/62G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,572,665
App. No.
18/488,635
Filed
Oct 17, 2023
Granted
Mar 10, 2026
Kind
B1
Art Unit
2495
USPC
726/25
Abstract

A cybersecurity system provides the ability to detect security risks in a cross-platform cloud solution. A unified data schema is used to abstract resources, principals and others across multiple platforms. A security graph is generated to present a unified view of cloud environments, which are then easily queried using the structure of the data schema. The solution allows a compact representation of cloud environments, which is scalable and multi-layered. Various enrichments may be added to the security graph, which are generated for example based on policies, and inspection of workloads in the cloud environment. The security graph allows for representation of production environments, staging environments, as well as code for deploying workloads in the cloud environment. Thus the solution is also able to present a complete picture of a user's entire cloud environment.

Claims (69)

1 . A method for detecting attack paths, comprising:

generating an exposure path between a workload in a cloud computing environment deployed on a cloud computing infrastructure and an external network;

inspecting the workload for a vulnerability;

detecting the vulnerability on the workload;

generating a representation of the cloud computing environment in a security database, the representation including a representation of the workload and a representation of the vulnerability; and

applying a plurality of queries on the representation of the cloud computing environment, each query corresponding to a potential cybersecurity attack on the workload based on the exposure path.

2 . The method of claim 1 , further comprising:

detecting the vulnerability based on a cybersecurity object.

3 . The method of claim 1 , further comprising:

detecting a software on the workload, the software having a software version;

determining that the software version is an outdated software version; and

detecting the vulnerability based on the outdated software version.

4 . The method of claim 1 , further comprising:

detecting a cybersecurity risk on the workload.

5 . The method of claim 1 , further comprising:

detecting a permission associated with a storage; and

detecting the vulnerability further based on the permission.

6 . The method of claim 1 , further comprising:

detecting a first virtualization associated with the workload; and

detecting a second virtualization nested within the first virtualization.

7 . The method of claim 1 , further comprising:

applying the query with a filter, the filter indicating a severity associated with the vulnerability.

8 . The method of claim 1 , further comprising:

applying the query with a filter, the filter indicating a cybersecurity finding.

9 . The method of claim 1 , further comprising:

detecting a secret on the workload; and

detecting the vulnerability further based on the detected secret.

10 . The method of claim 1 , further comprising:

detecting a policy in the computing environment; and

applying the query further based on the policy.

11 . A non-transitory computer-readable medium storing a set of instructions for detecting attack paths, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

generate an exposure path between a workload in a cloud computing environment deployed on a cloud computing infrastructure and an external network;

inspect the workload for a vulnerability;

detect the vulnerability on the workload;

generate a representation of the cloud computing environment in a security database, the representation including a representation of the workload and a representation of the vulnerability; and

apply a plurality of queries on the representation of the cloud computing environment, each query corresponding to a potential cybersecurity attack on the workload based on the exposure path.

12 . A system detecting attack paths comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

generate an exposure path between a workload in a cloud computing environment deployed on a cloud computing infrastructure and an external network;

inspect the workload for a vulnerability;

detect the vulnerability on the workload;

generate a representation of the cloud computing environment in a security database, the representation including a representation of the workload and a representation of the vulnerability; and

apply a plurality of queries on the representation of the cloud computing environment, each query corresponding to a potential cybersecurity attack on the workload based on the exposure path.

13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the vulnerability based on a cybersecurity object.

14 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a software on the workload, the software having a software version;

determine that the software version is an outdated software version; and

detect the vulnerability based on the outdated software version.

15 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a cybersecurity risk on the workload.

16 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a permission associated with a storage; and

detect the vulnerability further based on the permission.

17 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a first virtualization associated with the workload; and

detect a second virtualization nested within the first virtualization.

18 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the query with a filter, the filter indicating a severity associated with the vulnerability.

19 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the query with a filter, the filter indicating a cybersecurity finding.

20 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a secret on the workload; and

detect the vulnerability further based on the detected secret.

21 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a policy in the computing environment; and

apply the query further based on the policy.

Continuity (2)
Continuation 18477191 · Sep 28, 2023
Continuation 17524410 · Nov 11, 2021
References Cited (39)
US 8813234B1 · Bowers et al. · 2014 [cited by applicant]
US 9043922B1 · Dumitras · 2015 [cited by examiner]
US 9239745B1 · Pennington · 2016 [cited by examiner]
US 9298927B2 · Lietz et al. · 2016 [cited by applicant]
US 9692789B2 · Kirti et al. · 2017 [cited by applicant]
US 9843598B2 · Chauhan et al. · 2017 [cited by applicant]
US 10482245B2 · El-Moussa et al. · 2019 [cited by applicant]
US 10503904B1 · Singh · 2019 [cited by examiner]
US 10558809B1 · Joyce · 2020 [cited by examiner]
US 10701104B2 · Malkov et al. · 2020 [cited by applicant]
US 10747886B2 · El-Moussa et al. · 2020 [cited by applicant]
US 10924503B1 · Pereira et al. · 2021 [cited by applicant]
US 11546767B1 · Shaw et al. · 2023 [cited by applicant]
US 20060037019A1 · Austin et al. · 2006 [cited by applicant]
US 20120054368A1 · Brown et al. · 2012 [cited by applicant]
US 20130031628A1 · Wang · 2013 [cited by examiner]
US 20140157363A1 · Banerjee · 2014 [cited by applicant]
US 20150033351A1 · Oliphant · 2015 [cited by examiner]
US 20160381030A1 · Chillappa et al. · 2016 [cited by applicant]
US 20160381060A1 · Floering · 2016 [cited by examiner]
US 20170034023A1 · Nickolov · 2017 [cited by examiner]
US 20170270295A1 · Park et al. · 2017 [cited by applicant]
US 20170289187A1 · Noel et al. · 2017 [cited by applicant]
US 20180173502A1 · Biskup et al. · 2018 [cited by applicant]
US 20190087368A1 · Bhandari · 2019 [cited by examiner]
US 20190207985A1 · Yuan · 2019 [cited by applicant]
US 20190258525A1 · Glenn · 2019 [cited by examiner]
US 20190324820A1 · Krishnan et al. · 2019 [cited by applicant]
US 20190354906A1 · Stanciu et al. · 2019 [cited by applicant]
US 20200120120A1 · Cybulski · 2020 [cited by applicant]
US 20200244678A1 · Shua · 2020 [cited by applicant]
US 20200382363A1 · Woolward et al. · 2020 [cited by applicant]
US 20210176317A1 · Yeoh et al. · 2021 [cited by applicant]
US 20210226980A1 · Riccetti · 2021 [cited by examiner]
US 20220083536A1 · Hogan · 2022 [cited by applicant]
US 20220368702A1 · Robbins · 2022 [cited by examiner]
US 20220399120A1 · Godden · 2022 [cited by applicant]
US 20230011397A1 · Panse · 2023 [cited by examiner]
US 20230012202A1 · Wu et al. · 2023 [cited by applicant]