IP Library › Granted Patent US 12,619,470
Granted Patent B2
US 12,619,470 · App. 17/662,459 · Granted May 5, 2026

Assessing security vulnerabilities in cloud-native applications

Inventors: Hendrikus G.P. Bosch (Aalsmeer, NL); Randy Birdsall (Fulton, MD); Alessandro Duminuco (Milan, IT); Zohar Kaufman (South Natanya, IL); Sape Jurriën Mullender (Amsterdam, NL)
Assignee: Cisco Technology, Inc.
G06F9/5072G06F9/505G06F9/541G06F9/547
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,470
App. No.
17/662,459
Granted
May 5, 2026
Kind
B2
Abstract

According to some embodiments, a method is performed by a distributed cloud-native application. The method comprises receiving a request from a user to perform an operation. The user is associated with a risk profile. The method further comprises determining a call path through the distributed cloud-native application to perform the operation and classifying a risk level associated with the determined call path based on a distributed call graph. The distributed call graph comprises a risk value for each call path through the distributed cloud-native application and each call path comprises one or more distributed cloud-native application components. The risk value is based on a weakness rating associated with each component in the call path. The method further comprises determining the risk level associated with the determined call path is acceptable based on the risk profile associated with the user and performing the operation.

Claims (37)

1 . A method performed by a distributed cloud-native application, the method comprising:

testing one or more distributed cloud-native application components of the distributed cloud-native application;

receiving a request from a user to perform an operation, wherein the user is associated with a risk profile;

determining, based on the request, a call path through the distributed cloud-native application to perform the operation;

classifying a risk level associated with the determined call path based on a distributed call graph, wherein the distributed call graph is generated prior to receiving the request and comprises a risk value for each call path of a plurality of call paths through the distributed cloud-native application and the risk value is determined after the testing and is based on a weakness rating associated with each component of the one or more distributed cloud-native application components in the call path;

determining whether the risk level associated with the determined call path is acceptable based on the risk profile associated with the user; and

upon determining the risk level associated with the determined call path is acceptable based on the risk profile associated with the user, performing the operation.

2 . The method of claim 1 , wherein the weakness rating associated with each component of the one or more distributed cloud-native application components is based on a mapping of known vulnerabilities to image layers, images or libraries used to build the component.

3 . The method of claim 1 , wherein the weakness rating associated with each component of the one or more distributed cloud-native application components is based on vulnerabilities discovered during the testing of the component.

4 . The method of claim 3 , wherein testing of the component comprises integration testing.

5 . The method of claim 3 , wherein testing of the component comprises at least one of chaos-testing and fuzz-testing.

6 . The method of claim 1 , wherein the weakness rating associated with each component of the one or more distributed cloud-native application components is based on anomalies observed by external telemetry providers.

7 . The method of claim 6 , wherein the anomalies include at least one of a compromised transport layer security implementation, expired certification, reputation of a service provider, service usage amount, known adware or malware, and domain name.

8 . The method of claim 1 , wherein the distributed call graph is determined statistically.

9 . The method of claim 1 , wherein the request comprises input parameters and determining whether the risk level associated with the determined call path is acceptable is based on the input parameters.

10 . The method of claim 1 , further comprising:

upon determining the risk level associated with the determined call path is not acceptable based on the risk profile associated with the user, blocking the operation.

11 . The method of claim 1 , further comprising obtaining updates to the distributed call graph.

12 . A cloud-native application host server comprises:

a memory comprising instructions and a distributed call graph comprising a risk value for each call path of a plurality of call paths through a distributed cloud-native application and wherein each call path comprises one or more distributed cloud-native application components and the risk value is based on a weakness rating associated with each component of the one or more distributed cloud-native application components in the call path;

a hardware processor;

wherein the cloud-native application host server, when executing the instructions at the hardware processor, is configured to:

test the one or more distributed cloud-native application components, wherein the risk value for each call path of the plurality of call paths is determined after the testing;

receive a request from a user to perform an operation, wherein the user is associated with a risk profile;

determine, based on the request, a call path through the distributed cloud-native application to perform the operation;

classify a risk level associated with the determined call path based on the distributed call graph, wherein the distributed call graph is generated prior to receiving the request;

determine whether the risk level associated with the determined call path is acceptable based on the risk profile associated with the user; and

upon determining the risk level associated with the determined call path is acceptable based on the risk profile associated with the user, perform the operation.

13 . The cloud-native application host server of claim 12 , wherein the weakness rating associated with each component of the one or more distributed cloud-native application components is based on a mapping of known vulnerabilities to image layers, images or libraries used to build the component.

14 . The cloud-native application host server of claim 13 , wherein the weakness rating associated with each component of the one or more distributed cloud-native application components is based on vulnerabilities discovered during the testing of the component.

15 . The cloud-native application host server of claim 12 , wherein the weakness rating associated with each component of the one or more distributed cloud-native application components is based on anomalies observed by external telemetry providers.

16 . The cloud-native application host server of claim 15 , wherein the anomalies include at least one of a compromised transport layer security implementation, expired certification, reputation of a service provider, service usage amount, known adware or malware, and domain name.

17 . The cloud-native application host server of claim 12 , wherein the distributed call graph is determined statistically.

18 . The cloud-native application host server of claim 12 , wherein the request comprises input parameters and determining whether the risk level associated with the determined call path is acceptable is based on the input parameters.

19 . The cloud-native application host server of claim 12 , wherein the cloud-native application host server is further configured to:

upon determining the risk level associated with the determined call path is not acceptable based on the risk profile associated with the user, block the operation.

20 . The cloud-native application host server of claim 12 , wherein the cloud-native application host server is further configured to obtain updates to the distributed call graph.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE 4TH ASSIGNOR'S NAME PREVIOUSLY RECORDED AT REEL: 059868 FRAME: 0404. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded May 16, 2022
From: BOSCH, HENDRIKUS G.P.; BIRDSALL, RANDY; DUMINUCO, ALESSANDRO; KAUFMAN, ZOHAR; MULLENDER, SAPE JURRIËN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060072/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: BOSCH, HENDRIKUS G.P.; BIRDSALL, RANDY; DUMINUCO, ALESSANDRO; KAUFMAN, KOHAR; MULLENDER, SAPE JURRIËN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059868/0404 →
Continuity (2)
Provisional Application 63217045 · Jun 30, 2021
Related Publication 20230004445A1 · Jan 5, 2023
References Cited (12)
US 11030068B1 · Agarwal · 2021 [cited by applicant]
US 20170337123A1 · Wang · 2017 [cited by applicant]
US 20200082095A1 · Mcallister · 2020 [cited by applicant]
US 20200097662A1 · Hufsmith · 2020 [cited by applicant]
US 20200327044A1 · Pi · 2020 [cited by examiner]
US 20210073107A1 · Sharma · 2021 [cited by applicant]
US 20210377217A1 · Antoche Albisor · 2021 [cited by examiner]
US 20220100852A1 · Cervantez · 2022 [cited by examiner]
CN 110955899A · 2020 [cited by examiner]
Market Insight Report Reprint, Liam Rogers, “Observability primer: Is it just monitoring 2.0?” S&P Global Market Intelligence, Oct. 5, 2021, 5 pgs. [cited by applicant]
Stephen Elliot, Mark Leary, “Full-Stack Observability: Expanding the Digital Experience and Impact with Advanced Business Context,” , IDC, Nov. 2021, 19 pgs. [cited by applicant]
International Search Report corresponding to PCT/US2022/073069 dated Sep. 29, 2022, 15 pages. [cited by applicant]