IP Library Granted Patent US 12,634,310
Granted Patent B2
US 12,634,310 · App. 17/504,053 · Granted May 19, 2026

Detection of escalation paths in cloud environments

Inventors: Ami Luttwak (Binyamina, IL); Yinon Costica (Tel Aviv, IL); Assaf Rappaport (Tel Aviv, IL); Avi Tal Lichtenstein (Tel Aviv, IL); Roy Reznik (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,310
App. No.
17/504,053
Granted
May 19, 2026
Kind
B2
Abstract

A method for detecting escalation paths in a cloud environment is provided. The method includes accessing a security graph representing cloud objects and their connections in the cloud environment; analyzing each cloud object to detect an escalation hop from a current cloud object to a next cloud object, wherein the analysis is based, in part, on a plurality of risk factors and reachability parameters determined for each cloud object; and marking the security graph with each identified escalation path in the security graph, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object.

Claims (60)

1 . A method for detecting escalation paths in a cloud environment, comprising:

accessing a security graph representing all cloud objects and their connections in the cloud environment, each cloud object being represented with an enriched data set (EDS) stored in the security graph;

determining for each cloud object a plurality of reachability parameters;

storing the plurality of reachability parameters that are determined for each cloud object in the EDS of the respective cloud object for which the plurality of reachability parameters were determined;

analyzing each cloud object of the security graph utilizing static analysis based on (i) a plurality of risk factors that are generated by performing a risk analysis for each individual one of the cloud objects and (ii) the reachability parameters of the each individual one of the cloud objects;

detecting, based on the analysis, an escalation hop from a current cloud object to a next cloud object; and

recording for each cloud object of an escalation path a data feature in the security graph indicating the escalation path, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object having a higher privilege than the source cloud object.

2 . The method of claim 1 , further comprising:

traversing the security graph from the source cloud object to analyze all available paths from the source cloud object.

3 . The method of claim 1 , wherein a detected escalation hop is an exploitation of a current analyzed cloud object to a cloud object connected thereto.

4 . The method of claim 3 , wherein a connection between two cloud objects includes any one of: a role connection, a network connection, a control connection, and a data connection.

5 . The method of claim 1 , wherein each of the plurality of risk factors is an available privilege escalation realizable due to by a vulnerability detected within a cloud object, wherein the plurality of risk factors are maintained in an enriched data set (EDS) associated with each cloud object.

6 . The method of claim 5 , wherein the vulnerability includes any one of: an exposed secret vulnerability, a network vulnerability, a known vulnerability, an unknown vulnerability, an identity vulnerability, and a technology product vulnerability.

7 . The method of claim 1 , wherein analyzing each cloud object to detect an escalation hop further comprises:

determining, for a current cloud object, if a combination of each of the plurality of risk factors and at least one of the reachability parameters leads to a privilege escalation to a cloud object having a different role than the current cloud object.

8 . The method of claim 1 , wherein the escalation is a secret escalation, and wherein analyzing each cloud object to detect an escalation hop further comprises:

determining if a secret noted in a risk factor of the plurality of risk factors provides access to the next cloud object, wherein the secret is included in an EDS of the current cloud object.

9 . The method of claim 1 , wherein analyzing each cloud object to detect an escalation hop further comprises:

detecting an escalation path leveraging multiple hops across identity and network access.

10 . The method of claim 1 , wherein analyzing each cloud object to detect an escalation hop further comprises:

detecting an escalation path leveraging multiple hops across different cloud computing platforms in the cloud environment.

11 . The method of claim 1 , wherein analyzing each cloud object includes performing static analysis of each cloud object.

12 . The method of claim 1 , wherein each cloud object is a node in the security graph.

13 . The method of claim 1 , wherein detecting the escalation paths includes any one of: deterministic detection and un-deterministic detection.

14 . The method of claim 1 , further comprising:

generating a severity ranking for each detected escalation path, based on any one of: a type of object, a type of accessible data, an internal network access, an external network access, and a combination thereof.

15 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for detecting escalation paths in a cloud environment, the process comprising:

accessing a security graph representing all cloud objects and their connections in the cloud environment, each cloud object being represented with an enriched data set (EDS) stored in the security graph;

determining for each cloud object a plurality of reachability parameters;

storing the plurality of reachability parameters that are determined for each cloud object in the EDS of the respective cloud object for which the plurality of reachability parameters were determined;

analyzing each cloud object of the security graph utilizing static analysis based on (i) a plurality of risk factors that are generated by performing a risk analysis for each individual one of the cloud objects and (ii) the reachability parameters of the each individual one of the cloud objects;

detecting, based on the analysis, an escalation hop from a current cloud object to a next cloud object; and

recording for each cloud object of an escalation path a data feature in the security graph indicating the escalation path, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object having a higher privilege than the source cloud object.

16 . A system for detecting escalation paths in a cloud environment, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

access a security graph representing all cloud objects and their connections in the cloud environment, each cloud object being represented with an enriched data set (EDS) stored in the security graph;

determine for each cloud object a plurality of reachability parameters;

store the plurality of reachability parameters that are determined for each cloud object in the EDS of the respective cloud object for which the plurality of reachability parameters were determined;

analyze each cloud object of the security graph utilizing static analysis based on (i) a plurality of risk factors that are generated by performing a risk analysis for each individual one of the cloud objects and (ii) the reachability parameters of the each individual one of the cloud objects;

detect an escalation hop from a current cloud object to a next cloud object; and

recording for each cloud object of an escalation path a data feature in the security graph indicating the escalation path, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object having a higher privilege than the source cloud object.

17 . The system of claim 16 , wherein the system is further configured to:

traverse the security graph from the source cloud object to analyze all available paths from the source cloud object.

18 . The system of claim 16 , wherein a detected escalation hop is an exploitation of a current analyzed cloud object to a cloud object connected thereto.

19 . The system of claim 18 , wherein a connection between two cloud objects includes any one of: a role connection, a network connection, a control connection, and a data connection.

20 . The system of claim 16 , wherein each of the plurality of risk factors is an available privilege escalation realizable due to by a vulnerability detected with a cloud object, wherein the risk factors are maintained in an enriched data set (EDS) associated with each cloud object.

21 . The system of claim 20 , wherein the vulnerability includes any one of: an exposed secret vulnerability, a network vulnerability, a known vulnerability, an unknown vulnerability, an identity vulnerability, and a technology product vulnerability.

22 . The system of claim 16 , wherein the system is further configured to:

determine, for a current cloud object, if a combination of each of the plurality of risk factors and at least one of the reachability parameters leads to a privilege escalation to a cloud object having a different role than the current cloud object.

23 . The system of claim 22 , wherein the privileged escalation is secrets escalation, and wherein the system is further configured to:

determine if a secret noted in a risk factor of the plurality of risk factors provides access to the next cloud object, wherein the secret is included in an EDS of the current cloud object.

24 . The system of claim 16 , wherein the system is further configured to:

detect an escalation path leveraging multiple hops across identity and network access.

25 . The system of claim 16 , wherein the system is further configured to:

detect an escalation path leveraging multiple hops across different cloud computing platforms in the cloud environment.

26 . The system of claim 16 , wherein the system is further configured to:

perform a static analysis of each cloud object.

27 . The system of claim 16 , wherein each cloud object is a node in the security graph.

28 . The system of claim 16 , wherein detecting the escalation paths includes any one of: deterministic detection and un-deterministic detection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: LUTTWAK, AMI; COSTICA, YINON; RAPPAPORT, ASSAF; LICHTENSTEIN, AVI TAL; REZNIK, ROY
To: WIZ, INC.
Reel/Frame 057824/0487 →
Continuity (1)
Related Publication 20230123477A1 · Apr 20, 2023
References Cited (43)
US 9462010B1 · Stevenson · 2016 [cited by applicant]
US 10108803B2 · Chari · 2018 [cited by examiner]
US 10681074B2 · Crabtree et al. · 2020 [cited by applicant]
US 10963583B1 · Shimony · 2021 [cited by applicant]
US 11606378B1 · Delpont · 2023 [cited by examiner]
US 11777948B2 · Agarwwal · 2023 [cited by examiner]
US 11785051B1 · Rossman et al. · 2023 [cited by applicant]
US 20080104665A1 · Naldurg et al. · 2008 [cited by applicant]
US 20090271863A1 · Govindavajhala et al. · 2009 [cited by applicant]
US 20090276853A1 · Govindavajhala · 2009 [cited by applicant]
US 20090300532A1 · Cowan · 2009 [cited by applicant]
US 20120151185A1 · Bybell et al. · 2012 [cited by applicant]
US 20120198557A1 · Pistoia et al. · 2012 [cited by applicant]
US 20120272322A1 · Pistoia et al. · 2012 [cited by applicant]
US 20130067582A1 · Donovan et al. · 2013 [cited by applicant]
US 20130067583A1 · Naldurg et al. · 2013 [cited by applicant]
US 20130332726A1 · Galehouse et al. · 2013 [cited by applicant]
US 20140089039A1 · McClellan · 2014 [cited by applicant]
US 20140337618A1 · Galehouse et al. · 2014 [cited by applicant]
US 20150143525A1 · Naldurg et al. · 2015 [cited by applicant]
US 20160164904A1 · Alamuri · 2016 [cited by applicant]
US 20160381026A1 · Pinto et al. · 2016 [cited by applicant]
US 20170048266A1 · Hovor et al. · 2017 [cited by applicant]
US 20170161495A1 · Viswanath et al. · 2017 [cited by applicant]
US 20180234459A1 · Kung et al. · 2018 [cited by applicant]
US 20180241768A1 · Seiver et al. · 2018 [cited by applicant]
US 20180276383A1 · Venkataramani · 2018 [cited by applicant]
US 20180367548A1 · Stokes, III et al. · 2018 [cited by applicant]
US 20190260754A1 · Hecht · 2019 [cited by applicant]
US 20190311115A1 · Lavi et al. · 2019 [cited by applicant]
US 20190387009A1 · Kondaveeti · 2019 [cited by applicant]
US 20200204465A1 · Baker et al. · 2020 [cited by applicant]
US 20200213338A1 · Lotem · 2020 [cited by examiner]
US 20200351298A1 · Paturi et al. · 2020 [cited by applicant]
US 20200356663A1 · Paturi et al. · 2020 [cited by applicant]
US 20200396244A1 · Paturi et al. · 2020 [cited by applicant]
US 20210203684A1 · Maor et al. · 2021 [cited by applicant]
US 20210218770A1 · Ben-Yosef · 2021 [cited by examiner]
US 20210234889A1 · Burle · 2021 [cited by examiner]
US 20220060507A1 · Crabtree · 2022 [cited by examiner]
International Search Report for PCT Application No. PCT/IB2022/060012 dated Feb. 1, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the International Searching Authority for PCT Application No. PCT/IB2022/060012 dated Feb. 1, 2023. The International Bureau of WIPO. [cited by applicant]
Extended European search report for EP application 22883069.1, dated Feb. 24, 2025. European Patent Office, Munich, Germany. [cited by applicant]