IP Library › Granted Patent US 12,619,720
Granted Patent B2
US 12,619,720 · App. 19/058,836 · Granted May 5, 2026

Systems and methods for cybersecurity alert deduplication, grouping, and prioritization

Inventors: Oren Yona (Tel Aviv, IL); Eyal Golombek (Tel Aviv, IL); Tomer Schwartz (Tel Aviv, IL); Eshel Yaron (Amsterdam, NL); Pavel Resnianski (Tel Aviv, IL)
Assignee: Wiz, Inc.
G06F21/554G06F21/54G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,720
App. No.
19/058,836
Granted
May 5, 2026
Kind
B2
Abstract

Systems and methods for alert deduplication. A method includes querying a software component associations database based on a plurality of software containers indicated by a plurality of alerts in order to identify a plurality of correlations between software containers among the plurality of software containers, wherein the software component associations database stores at least associations between configuration files of the plurality of software containers and build files used to build the plurality of software containers; identifying at least one set of duplicate alerts among the plurality of alerts based on the identified plurality of correlations, wherein each set of duplicate alerts includes at least two alerts of the plurality of alerts which indicate correlated software containers among the plurality of software containers; and deduplicating the plurality of alerts based on the identified at least one set of duplicate alerts in order to produce a deduplicated set of alerts.

Claims (44)

1 . A method for alert deduplication, comprising:

querying a software component associations database based on a plurality of software containers indicated by a plurality of alerts in order to identify a plurality of correlations between software containers among the plurality of software containers, wherein the plurality of correlations is based on stored associations in the software component associations database, the stored associations are between a configuration file of each software container of the plurality of software containers and at least one build file used to build the software container of the plurality of software containers;

identifying at least one set of duplicate alerts among the plurality of alerts based on the identified plurality of correlations, wherein each set of duplicate alerts includes at least two alerts of the plurality of alerts corresponding to correlated software containers among the plurality of software containers; and

deduplicating the plurality of alerts based on the identified at least one set of duplicate alerts in order to produce a deduplicated set of alerts.

2 . The method of claim 1 , wherein deduplicating the plurality of alerts further comprises:

removing at least one redundant alert such that the deduplicated set of alerts includes only one instance of each unique alert.

3 . The method of claim 1 , further comprising:

mitigating at least one threat based on the deduplicated set of alerts.

4 . The method of claim 1 , wherein the at least two alerts of each set of duplicate alerts further indicate a same common vulnerability and exposure (CVE) among a plurality of predetermined CVEs.

5 . The method of claim 1 , wherein a first build file indicated by a first alert of each set of duplicate alerts is associated with a first configuration file indicated by a second alert of the set of duplicate alerts.

6 . The method of claim 5 , wherein the first build file indicated by the first alert of each set of duplicate alerts is used to build a container image corresponding to the first configuration file indicated by the second alert of the set of duplicate alerts.

7 . The method of claim 1 , wherein the at least two alerts of each set of duplicate alerts includes alerts from different detection tools.

8 . The method of claim 1 , further comprising:

de-compiling the configuration file of each software container of the plurality of software containers in order to produce a plurality of de-compiled configuration files;

identifying at least one candidate build file in each of the plurality of de-compiled configuration files;

associating each de-compiled configuration file with one of the at least one candidate build file which meets at least one matching condition for the de-compiled configuration file; and

populating the software component associations database based on the association.

9 . The method of claim 8 , wherein identifying the at least one candidate build file in each of the plurality of de-compiled configuration files further comprises:

matching each de-compiled configuration file of the plurality of de-compiled configuration files to each of the at least one candidate build file for the de-compiled configuration file based on the at least one matching command between the de-compiled configuration file and each of the at least one candidate build file for the de-compiled configuration file.

10 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for software containers attribution, the process comprising:

querying a software component associations database based on a plurality of software containers indicated by a plurality of alerts in order to identify a plurality of correlations between software containers among the plurality of software containers, wherein the plurality of correlations is based on stored associations in the software component associations database, the stored associations are between a configuration file of each software container of the plurality of software containers and at least one build file used to build the software container of the plurality of software containers;

identifying at least one set of duplicate alerts among the plurality of alerts based on the identified plurality of correlations, wherein each set of duplicate alerts includes at least two alerts of the plurality of alerts corresponding to correlated software containers among the plurality of software containers; and

deduplicating the plurality of alerts based on the identified at least one set of duplicate alerts in order to produce a deduplicated set of alerts.

11 . A system for alert deduplication, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

query a software component associations database based on a plurality of software containers indicated by a plurality of alerts in order to identify a plurality of correlations between software containers among the plurality of software containers, wherein the plurality of correlations is based on stored associations in the software component associations database, the stored associations are between a configuration file of each software container of the plurality of software containers and at least one build file used to build the software container of the plurality of software containers;

identify at least one set of duplicate alerts among the plurality of alerts based on the identified plurality of correlations, wherein each set of duplicate alerts includes at least two alerts of the plurality of alerts corresponding to correlated software containers among the plurality of software containers; and

deduplicate the plurality of alerts based on the identified at least one set of duplicate alerts in order to produce a deduplicated set of alerts.

12 . The system of claim 11 , wherein the system is further configured to:

remove at least one redundant alert such that the deduplicated set of alerts includes only one instance of each unique alert.

13 . The system of claim 11 , wherein the system is further configured to:

mitigate at least one threat based on the deduplicated set of alerts.

14 . The system of claim 11 , wherein the at least two alerts of each set of duplicate alerts further indicate a same common vulnerability and exposure (CVE) among a plurality of predetermined CVEs.

15 . The system of claim 11 , wherein a first build file indicated by a first alert of each set of duplicate alerts is associated with a first configuration file indicated by a second alert of the set of duplicate alerts.

16 . The system of claim 15 , wherein the first build file indicated by the first alert of each set of duplicate alerts is used to build a container image corresponding to the first configuration file indicated by the second alert of the set of duplicate alerts.

17 . The system of claim 11 , wherein the at least two alerts of each set of duplicate alerts includes alerts from different detection tools.

18 . The system of claim 11 , wherein the system is further configured to:

de-compile the configuration file of each software container of the plurality of software containers in order to produce a plurality of de-compiled configuration files;

identify at least one candidate build file in each of the plurality of de-compiled configuration files;

associate each de-compiled configuration file with one of the at least one candidate build file which meets at least one matching condition for the de-compiled configuration file; and

populate the software component associations database based on the association.

19 . The system of claim 18 , wherein the system is further configured to:

match each de-compiled configuration file of the plurality of de-compiled configuration files to each of the at least one candidate build file for the de-compiled configuration file based on the at least one matching command between the de-compiled configuration file and each of the at least one candidate build file for the de-compiled configuration file.

Continuity (3)
Continuation 17816161 · Jul 29, 2022
Continuation In Part 17656914 · Mar 29, 2022
Related Publication 20250190556A1 · Jun 12, 2025
References Cited (79)
US 8806425B1 · Willis et al. · 2014 [cited by applicant]
US 9052961B2 · Mangtani et al. · 2015 [cited by applicant]
US 9195674B1 · Dukes et al. · 2015 [cited by applicant]
US 9449042B1 · Evans et al. · 2016 [cited by applicant]
US 9516064B2 · Lietz et al. · 2016 [cited by applicant]
US 9692778B1 · Mohanty · 2017 [cited by applicant]
US 10108803B2 · Chari et al. · 2018 [cited by applicant]
US 10313382B2 · Noel et al. · 2019 [cited by applicant]
US 10346229B2 · Tee et al. · 2019 [cited by applicant]
US 10454935B2 · Parimi et al. · 2019 [cited by applicant]
US 11429353B1 · Liguori et al. · 2022 [cited by applicant]
US 11893106B2 · Kim et al. · 2024 [cited by applicant]
US 20030131284A1 · Flanagan et al. · 2003 [cited by applicant]
US 20040015816A1 · Hines et al. · 2004 [cited by applicant]
US 20040044990A1 · Schloegel et al. · 2004 [cited by applicant]
US 20090222479A1 · Burukhin et al. · 2009 [cited by applicant]
US 20100070448A1 · Omoigui · 2010 [cited by examiner]
US 20130167241A1 · Siman · 2013 [cited by applicant]
US 20150341214A1 · Croy et al. · 2015 [cited by applicant]
US 20150347759A1 · Cabrera et al. · 2015 [cited by applicant]
US 20150363197A1 · Carback et al. · 2015 [cited by applicant]
US 20150363294A1 · Carback, III et al. · 2015 [cited by applicant]
US 20160379480A1 · OlmstedThompson · 2016 [cited by examiner]
US 20170026416A1 · Carpenter et al. · 2017 [cited by applicant]
US 20170075749A1 · Ambichl et al. · 2017 [cited by applicant]
US 20170185785A1 · Vorona et al. · 2017 [cited by applicant]
US 20170249128A1 · Fojtik et al. · 2017 [cited by applicant]
US 20170286692A1 · Nakajima et al. · 2017 [cited by applicant]
US 20180025160A1 · Hwang · 2018 [cited by examiner]
US 20180129479A1 · McPherson et al. · 2018 [cited by applicant]
US 20180285199A1 · Mitkar et al. · 2018 [cited by applicant]
US 20180321918A1 · Mcclory et al. · 2018 [cited by applicant]
US 20180373507A1 · Mizrahi et al. · 2018 [cited by applicant]
US 20190007290A1 · He et al. · 2019 [cited by applicant]
US 20190068622A1 · Lin · 2019 [cited by examiner]
US 20190294477A1 · Koppes et al. · 2019 [cited by applicant]
US 20190303579A1 · Reddy · 2019 [cited by examiner]
US 20190354389A1 · Du et al. · 2019 [cited by applicant]
US 20200097662A1 · Hufsmith et al. · 2020 [cited by applicant]
US 20200183766A1 · Kumar-Mayernik et al. · 2020 [cited by applicant]
US 20200296117A1 · Karpovsky · 2020 [cited by examiner]
US 20210042096A1 · White, III et al. · 2021 [cited by applicant]
US 20210168165A1 · Alsaeed et al. · 2021 [cited by applicant]
US 20210182387A1 · Zhu et al. · 2021 [cited by applicant]
US 20210208934A1 · Jadhav et al. · 2021 [cited by applicant]
US 20210311855A1 · Khan et al. · 2021 [cited by applicant]
US 20210382997A1 · Yi et al. · 2021 [cited by applicant]
US 20220043702A1 · Haines · 2022 [cited by applicant]
US 20220114023A1 · Choksi et al. · 2022 [cited by applicant]
US 20220129539A1 · Walsh et al. · 2022 [cited by applicant]
US 20220311794A1 · Maya et al. · 2022 [cited by applicant]
US 20220327220A1 · Sharma et al. · 2022 [cited by applicant]
US 20220353341A1 · Östrand et al. · 2022 [cited by applicant]
US 20230036739A1 · Deppisch et al. · 2023 [cited by applicant]
US 20230118065A1 · Kumar · 2023 [cited by applicant]
US 20230229781A1 · Stolbikov et al. · 2023 [cited by applicant]
US 20230297366A1 · Wigglesworth et al. · 2023 [cited by applicant]
US 20230333845A1 · Zand et al. · 2023 [cited by applicant]
US 20240281362A1 · Alshawabkeh et al. · 2024 [cited by applicant]
US 20250013442A1 · Hempstead et al. · 2025 [cited by applicant]
US 20250190575A1 · Kirat et al. · 2025 [cited by applicant]
EP 3208996A1 · 2017 [cited by applicant]
EP 3494506A1 · 2019 [cited by applicant]
WO 2020091591A1 · 2020 [cited by applicant]
WO 2023067423A1 · 2023 [cited by applicant]
Doan TP, Jung S. Davs: Dockerfile Analysis for Container Image Vulnerability Scanning. CMC-Computers Materials & Continua. Jan. 1, 2022;72(1):1699-711. Doan TP, Jung S Jan. 31, 2022. [cited by applicant]
International Search Report for PCT Application No. PCT/IB2022/059483. The International Bureau of WIPO. [cited by applicant]
International Search Report for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
International Search Report for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
International Search Report, PCT/IB2023/052415; Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the International Searching Authority for PCT Application No. PCT/IB2022/059483 dated Jan. 8, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the International Searching Authority, PCT/IB2023/052415. Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the Searching Authority for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
International Search Report for PCT/IB2025/051650, dated May 26, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2025/051650, dated May 26, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Alrabaee, “A Survey of Binary Code Fingerprinting Approaches: Taxonomy, Methodologies, and Features”, 2022, ACM (Year: 2022). [cited by applicant]
Liu, “Vfdetect: A Vulnerable Code Clone Detection System Based on Vulnerability Fingerprint”, 2017, IEEE (Year: 2017). [cited by applicant]
Extended European Search Report and Opinion for application No. EP 23845793.1, dated Feb. 25, 2026. European Patent Office, Munich, Germany. [cited by applicant]