IP Library › Granted Patent US 12,598,208
Granted Patent B2
US 12,598,208 · App. 18/461,181 · Granted Apr 7, 2026

Infrastructure as code (IaC) scanner for infrastructure component security

Inventors: Jeevan Reddy Ragula (Hyderabad, IN); Abhijeet Singh Rawat (Hyderabad, IN); Shyam Baitmangalkar (Hyderabad, IN); Aparna Saripaka (Hyderabad, IN); Robert Valek (Odessa, UA); Oleksii Stetsyk (Kyiv, UA)
Assignee: Zscaler, Inc.
H04L63/1433H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,208
App. No.
18/461,181
Granted
Apr 7, 2026
Kind
B2
Abstract

Systems and methods for an Infrastructure as Code (IaC) scanner for infrastructure component security. Various embodiments include steps of receiving one or more files for security scanning; extracting and parsing one or more resources from the one or more files; evaluating one or more policies for each of the one or more resources thereby ensures that underlying infrastructure components are configured securely; and displaying findings and details associated with the evaluating of the one or more resources.

Claims (30)

1 . A method comprising steps of:

receiving one or more Infrastructure as Code (IaC) files for security scanning from a user, the receiving including authenticating the user via a posture control platform to obtain an authorization token;

extracting and parsing, by an IaC parser, one or more resources from the one or more IaC files, the extracting including recursively evaluating functions within template files;

storing the extracted resources in a database created at the start of the scanning, wherein the database is locally maintained on a developer machine,

evaluating, by a policy engine, one or more policies for each of the one or more resources, the policies being maintained as Structured Query Language (SQL) expressions compiled from universal policy definition retrieved from the posture control platform;

persisting results of the evaluating in the database; and

displaying findings and details associated with the evaluating of the one or more resources, the findings including recommended remedial procedures, and uploading the findings and the one or more resources to the posture control platform for further processing and graphical visualization.

2 . The method of claim 1 , wherein the authenticating includes storing an authorization token in secure operating system storage.

3 . The method of claim 1 , wherein resources are stored in a database prior to the evaluating.

4 . The method of claim 3 , wherein the database is created when the one or more files are received.

5 . The method of claim 1 , wherein the one or more policies are maintained as Structured Query Language (SQL) expressions in a database, the SQL expressions being automatically compiled from a universal source policy language into SQLite-compatible queries for local execution on a developer machine.

6 . The method of claim 5 , wherein the SQL expressions are derived from policy definitions retrieved from a posture control platform in a cloud-based system.

7 . The method of claim 1 , wherein results of the evaluating are persisted in a database.

8 . The method of claim 1 , wherein the findings and resources are uploaded to a posture control platform for display and further processing, including correlation with multi-cloud configuration management databases (CMDBs) to identify misconfigurations, excessive permissions, or correlated risks across build-time and run-time environments.

9 . The method of claim 1 , wherein the findings include security issues associated with the one or more resources, and the details include recommended and remedial procedures for the security issues.

10 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

receiving one or more Infrastructure as Code (IaC) files for security scanning from a user, the receiving including authenticating the user via a posture control platform to obtain an authorization token;

extracting and parsing, by an IaC parser, one or more resources from the one or more IaC files, the extracting including recursively evaluating functions within template files;

storing the extracted resources in a database created at the start of the scanning, wherein the database is locally maintained on a developer machine;

evaluating. by a policy engine, one or more policies for each of the one or more resources, the policies being maintained as Structured Query Language (SQL) expressions compiled from universal policy definitions retrieved from the posture control platform;

persisting results of the evaluating in the database; and

displaying findings and details associated with the evaluating of the one or more resources, the findings including recommended remedial procedures, and uploading the findings and the one or more resources to the posture control platform for further processing and graphical visualization.

11 . The non-transitory computer-readable medium of claim 10 , wherein the authenticating includes storing an authorization token in secure operating system storage.

12 . The non-transitory computer-readable medium of claim 10 , wherein resources are stored in a database prior to the evaluating.

13 . The non-transitory computer-readable medium of claim 12 , wherein the database is created when the one or more files are received.

14 . The non-transitory computer-readable medium of claim 10 , wherein the one or more policies are maintained as Structured Query Language (SQL) expressions in a database, the SQL expressions being automatically compiled from a universal source policy language into SQLite-compatible queries for local execution on a developer machine.

15 . The non-transitory computer-readable medium of claim 14 , wherein the SQL expressions are derived from policy definitions retrieved from a posture control platform in a cloud-based system.

16 . The non-transitory computer-readable medium of claim 10 , wherein results of the evaluating are persisted in a database.

17 . The non-transitory computer-readable medium of claim 10 , wherein the findings and resources are uploaded to a posture control platform for display and further processing, including correlation with multi-cloud configuration management databases (CMDBs) to identify misconfigurations, excessive permissions, or correlated risks across build-time and run-time environments.

18 . The non-transitory computer-readable medium of claim 10 , wherein the findings include security issues associated with the one or more resources, and the details include recommended and remedial procedures for the security issues.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2023
From: RAGULA, JEEVAN REDDY; RAWAT, ABHIJEET SINGH; BAITMANGALKAR, SHYAM; SARIPAKA, APARNA; VALEK, ROBERT; STETSYK, OLEKSII
To: ZSCALER, INC.
Reel/Frame 064798/0523 →
Priority Claims (1)
IN 202311049062 · Jul 20, 2023 · national
Continuity (1)
Related Publication 20250030722A1 · Jan 23, 2025
References Cited (31)
US 8561180B1 · Nachenberg · 2013 [cited by examiner]
US 9753834B1 · Tang · 2017 [cited by examiner]
US 10379966B2 · Gangadharappa et al. · 2019 [cited by applicant]
US 10432651B2 · Pangeni et al. · 2019 [cited by applicant]
US 10796017B1 · Azaroff · 2020 [cited by examiner]
US 10958556B2 · Rajalingam · 2021 [cited by examiner]
US 11113177B1 · Chitnis · 2021 [cited by examiner]
US 11397808B1 · Prabhu · 2022 [cited by examiner]
US 12355626B1 · Varakantam · 2025 [cited by examiner]
US 20040128653A1 · Arcand · 2004 [cited by examiner]
US 20060048224A1 · Duncan · 2006 [cited by examiner]
US 20170359220A1 · Weith et al. · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann · 2018 [cited by examiner]
US 20200162497A1 · Iyer · 2020 [cited by examiner]
US 20210126949A1 · Nadgowda · 2021 [cited by examiner]
US 20210336934A1 · Deshmukh et al. · 2021 [cited by applicant]
US 20220046059A1 · Pandurangi et al. · 2022 [cited by applicant]
US 20220094810A1 · Tajima · 2022 [cited by examiner]
US 20220129417A1 · Diaz · 2022 [cited by examiner]
US 20220329442A1 · Bulusu et al. · 2022 [cited by applicant]
US 20220393941A1 · Singh · 2022 [cited by applicant]
US 20220393943A1 · Pangeni et al. · 2022 [cited by applicant]
US 20220394083A1 · Pangeni et al. · 2022 [cited by applicant]
US 20230015603A1 · Smith · 2023 [cited by applicant]
US 20230019448A1 · Deshmukh et al. · 2023 [cited by applicant]
US 20240086157A1 · Patil · 2024 [cited by examiner]
US 20240171466A1 · Kandasamy · 2024 [cited by examiner]
US 20240250970A1 · Lai · 2024 [cited by examiner]
US 20240281248A1 · Shah · 2024 [cited by examiner]
US 20240388600A1 · Du · 2024 [cited by examiner]
US 20240430303A1 · Lu · 2024 [cited by examiner]