IP Library › Granted Patent US 12,634,323
Granted Patent B2
US 12,634,323 · App. 18/203,045 · Granted May 19, 2026

Methods and systems for attack generation on data lakes

Inventors: Navindra Yadav (Cupertino, CA); Supreeth Hosur Nagesh Rao (Cupertino, CA); Ravi Kanth Sankuratri (Cupertino, CA); Danesh S. Irani (San Carlos, CA); Alok Lalit Wadhwa (Milipitas, CA); Vasil Dochkov Yordanov (San Jose, CA); Venkateshu Cherukupalli (West Windsor, NJ); Yiwei Wang (San Jose, CA); Zhiwen Zhang (San Jose, CA); Udayan Pramod Joshi (Cupertino, CA)
Assignee: Theom, Inc.
H04L63/1433H04L63/1466H04L63/1475
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,323
App. No.
18/203,045
Granted
May 19, 2026
Kind
B2
Abstract

In one aspect, a computerized method for attack generation on a data lake, comprises: for a data lake repository: providing an attack generation mimicry tool; with the attack generation mimicry tool: implementing a reconnaissance phase attack generation; implementing an infiltration phase attack generation on the data lake repository; implementing a hiding and data intelligence collection phase of the attack by hiding from any monitoring or notification system of the data lake repository and surveying the data lake repository to determine what data is worth abusing or exfiltrating from the data lake repository; implementing data gathering phase of the attack that gathers data about other objects, attributes, and relationships in the data lake repository; and implementing the exfiltration of the data or the abuse of the data.

Claims (61)

1 . A computerized method for attack generation on a data lake, comprising:

for a data lake repository:

providing an attack generation mimicry tool; and

with the attack generation mimicry tool:

implementing a reconnaissance phase attack generation;

implementing an infiltration phase attack generation on the data lake repository;

implementing a hiding and data intelligence collection phase of an attack by hiding from a monitoring or notification system of the data lake repository and surveying the data lake repository to determine data to target for exfiltration from the data lake repository;

implementing data gathering phase of the attack that gathers data about objects, attributes, and relationships in the data lake repository other than the data targeted for exfiltration; and

implementing the exfiltration of the data to target for exfiltration.

2 . The computerized method of claim 1 , wherein a data lake comprises a computerized repository of data stored in a raw format.

3 . The computerized method of claim 1 , wherein the data lake comprises a plurality of object blobs.

4 . The computerized method of claim 1 , wherein implementing the reconnaissance phase attack generation further comprises:

generating a probe and a network access controls, a network authentication, and a network authorization setting.

5 . The computerized method of claim 4 , wherein implementing the reconnaissance phase attack generation further comprises:

probing the network access controls, the network authentication and the network authorization setting; and

generating a variance in machine and human identity behaviors.

6 . The computerized method of claim 1 , wherein implementing the infiltration phase attack generation on the data lake repository further comprises:

generating a privilege escalation by creating and escalating into a privileged access role.

7 . The computerized method of claim 6 , wherein implementing the infiltration phase attack generation on the data lake repository further comprises:

gaining access inside a data store of the data lake repository.

8 . The computerized method of claim 1 , wherein generating a hiding and data intelligence collection phase of the attack further comprises:

generating a plurality of defense evasion signals.

9 . The computerized method of claim 8 , wherein generating a hiding and data intelligence collection phase of the attack further comprises:

discovering a plurality of stores, a plurality of credentials and a plurality of integrations so that the attack generation tools hide from the monitoring tool of the data lake repository.

10 . The computerized method of claim 1 , wherein implementing data gathering phase of the attack that gathers data about objects, attributes, and relationships in the data lake repository further comprises:

collecting data to target for exfiltration stored inside the data lake repository and preparing the data to target for exfiltration for an exfiltration operation.

11 . The computerized method of claim 1 further comprising:

deleting the exfiltrated data.

12 . The computerized method of claim 11 , wherein the deletion of the exfiltrated data impacts a CIA (confidentiality, integrity, availability) triad of the data.

13 . A non-transitory machine-readable medium including a program that, when performed by a computer system, enables the computer system to:

for a data lake repository:

provide an attack generation mimicry tool; and

with the attack generation mimicry tool:

implement a reconnaissance phase attack generation;

implement an infiltration phase attack generation on the data lake repository;

implement a hiding and data intelligence collection phase of an attack by hiding from a monitoring or notification system of the data lake repository and surveying the data lake repository to determine what data to target for exfiltration from the data lake repository;

implement a data gathering phase of the attack that gathers data about objects, attributes, and relationships in the data lake repository other than the data targeted for exfiltration; and

implement the exfiltration of the data to target for exfiltration.

14 . The non-transitory machine-readable medium of claim 13 , wherein to implement the reconnaissance phase attack generation, the program further enables the computer system to:

generate a probe and a network access control, a network authentication, and a network authorization setting.

15 . The non-transitory machine-readable medium of claim 13 , wherein to implement the infiltration phase attack generation on the data lake repository, the program further enables the computer system to:

generate a privilege escalation by creating and escalating into a privileged access role.

16 . The non-transitory machine-readable medium of claim 13 , wherein to implement the hiding and data intelligence collection phase of the attack, the program further enables the computer system to:

generate a plurality of defense evasion signals.

17 . A system for attack generation on a data lake, comprising:

one or more processors; and

one or more memories connected to the one or more processors, the one or more memories including a program that, when executed by the one or more processors, enables the system to:

for a data lake repository:

provide an attack generation mimicry tool; and

with the attack generation mimicry tool:

implement a reconnaissance phase attack generation;

implement an infiltration phase attack generation on the data lake repository;

implement a hiding and data intelligence collection phase of an attack by hiding from a monitoring or notification system of the data lake repository and surveying the data lake repository to determine what data to target for exfiltration from the data lake repository;

implement a data gathering phase of the attack that gathers data about objects, attributes, and relationships in the data lake repository other than the data targeted for exfiltration; and

implement the exfiltration of the data targeted for exfiltration.

18 . The system of claim 17 , wherein the program further enables the system to:

delete the exfiltrated data.

19 . The system of claim 17 , wherein to implement the infiltration phase attack generation on the data lake repository, the program further enables the system to:

generate a privilege escalation by creating and escalating into a privileged access role.

20 . The system of claim 17 , wherein to implement the hiding and data intelligence collection phase of the attack, the program further enables the system to:

generate a plurality of defense evasion signals.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2025
From: YADAV, NAVINDRA; RAO, SUPREETH HOSUR NAGESH; SANKURATRI, RAVI; WADHWA, ALOK LALIT; IRANI, DANESH; CHERUKUPALLI, VENKATESHU; YORDANOV, VASIL DOCHKOV; WANG, YIWEI; ZHAN, ZHIWEN; JOSHI, UDAYAN
To: THEOM, INC.
Reel/Frame 071761/0634 →
Continuity (4)
Continuation In Part 17335932 · Jun 1, 2021
Provisional Application 63439579 · Jan 18, 2023
Provisional Application 63153362 · Feb 24, 2021
Related Publication 20250373641A1 · Dec 4, 2025
References Cited (3)
US 10769045B1 · Sharifi Mehr · 2020 [cited by examiner]
US 10826928B2 · Carey · 2020 [cited by examiner]
US 20070142030A1 · Sinha · 2007 [cited by examiner]