IP Library Granted Patent US 12,744,818
Granted Patent B2
US 12,744,818 · App. 18/651,470 · Granted Sep 22, 2026

Identifying serverless functions with over-permissive roles

Inventors: Avraham Shulman (Tel Aviv, IL); Ory Segal (Tel Aviv, IL); Shaked Yosef Zin (Tel Aviv-Jaffa, IL)
Assignee: Palo Alto Networks, Inc.
H04L63/20H04L63/1433H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,818
App. No.
18/651,470
Granted
Sep 22, 2026
Kind
B2
Abstract

Based on analyzing a serverless function associated with a first role, a set of security permissions granted to the serverless function is identified based on the first role and a first attribute of the serverless function. A least privilege role indicating a set of least privilege security permissions for the serverless function is generated based, at least in part, on the first attribute. Based on comparing the least privilege role with the first role, it is determined if the set of security permissions granted to the serverless function is more permissive than the set of least privilege security permissions. Based on determining that the set of security permissions granted to the serverless function is more permissive than the set of least privilege security permissions, the first role is reported as over-permissive.

Claims (32)

1 . A method comprising:

analyzing one or more serverless functions for at least one of vulnerabilities and insecure configurations, wherein analyzing the one or more serverless functions comprises,

based on receiving a request to scan the one or more serverless functions, scanning the one or more serverless functions for at least one of vulnerabilities and insecure configurations and scanning one or more resources related to the one or more serverless functions for misconfigurations;

detecting at least one of a vulnerability and an insecure configuration in at least one of a first of the one or more serverless functions and in a first of the one or more resources related to the one or more serverless functions based on scanning the one or more serverless functions and the one or more resources; and

reporting the at least one of the vulnerability and the insecure configuration in the first serverless function and/or the misconfiguration in the first resource.

2 . The method of claim 1 , wherein scanning the one or more serverless functions comprises obtaining a copy of each of the one or more serverless functions and scanning the copy of each of the one or more serverless functions or scanning the one or more serverless functions remotely.

3 . The method of claim 1 , wherein the at least one of the vulnerability and the insecure configuration comprises sensitive data insecurely stored in at least one of code and a configuration of the first serverless function.

4 . The method of claim 1 , wherein at least one of the vulnerability and the insecure configuration comprise at least one of known vulnerabilities in third-party libraries, an overprivileged role, weak encryption, improper exception handling, a potential data leakage source, and usage of an insecure third-party service.

5 . The method of claim 1 , further comprising preventing building or deployment of the first serverless function based on detecting at least one of the vulnerability and the insecure configuration of the first serverless function.

6 . The method of claim 1 , further comprising preventing or stopping execution of the first serverless function based on detecting at least one of the vulnerability and the insecure configuration of the first serverless function.

7 . The method of claim 1 , wherein the request indicates at least one of the one or more serverless functions, an application that comprises the one or more serverless functions, and a cloud provider with which the one or more serverless functions are associated.

8 . The method of claim 1 , wherein analyzing the one or more serverless functions is triggered based on deployment of the one or more serverless functions or based on an update to the one or more serverless functions.

9 . One or more non-transitory machine-readable media having program code for analyzing a serverless function stored thereon, the program code comprising instructions to:

based on receipt of a request that indicates the serverless function, scan the serverless function and one or more resources related to the serverless function, wherein the instructions to scan the serverless function comprise instructions to scan the serverless function to detect at least one of vulnerabilities and insecure configurations of the serverless function, wherein the instructions to scan the one or more resources related to the serverless function comprise instructions to scan the one or more resources to detect misconfigurations of the one or more resources;

detect at least one of a vulnerability and an insecure configuration of the serverless function and/or a misconfiguration of a first of the one or more resources based on the scan of the serverless function and the scan of the one or more resources; and

report the at least one of the vulnerability and the insecure configuration of the serverless function and/or the misconfiguration of the first resource related to the serverless function.

10 . The non-transitory machine-readable media of claim 9 , wherein the instructions to scan the serverless function comprise instructions to obtain a copy of the serverless function and scan the copy of the serverless function or instructions to scan the serverless function remotely.

11 . The non-transitory machine-readable media of claim 9 , wherein the program code further comprises instructions to prevent building or deployment of the serverless function based on detection of at least one of the vulnerability and the insecure configuration of the serverless function.

12 . The non-transitory machine-readable media of claim 9 , wherein the program code further comprises instructions to prevent or stop execution of the serverless function based on detection of at least one of the vulnerability and the insecure configuration of the serverless function.

13 . The non-transitory machine-readable media of claim 9 , wherein the at least one of the vulnerability and the insecure configuration comprises at least one of sensitive data insecurely stored in at least one of code and a configuration of the serverless function, known vulnerabilities in third-party libraries, an overprivileged role, weak encryption, improper exception handling, a potential data leakage source, and usage of an insecure third-party service.

14 . An apparatus comprising:

a processor; and

a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to,

based on receipt of a request to scan one or more serverless functions, scan the one or more serverless functions for at least one of vulnerabilities and insecure configurations and scan one or more resources related to the one or more serverless functions for misconfigurations;

detect at least one of a vulnerability and an insecure configuration of a first serverless function of the one or more serverless functions and/or a misconfiguration of a first of the one or more resources related to the one or more serverless functions based on the scan of the one or more serverless functions and the scan of the one or more resources; and

report the at least one of the vulnerability and the insecure configuration of the first serverless function and/or the misconfiguration of the first resource.

15 . The apparatus of claim 14 , wherein the instructions executable by the processor to cause the apparatus to scan the one or more serverless functions comprise instructions executable by the processor to cause the apparatus to obtain a copy of each of the one or more serverless functions and scan the copy of each of the one or more serverless functions or instructions executable by the processor to cause the apparatus to scan the one or more serverless functions remotely.

16 . The apparatus of claim 14 , further comprising instructions executable by the processor to cause the apparatus to prevent building or deployment of the first serverless function based on detection of at least one of the vulnerability and the insecure configuration of the first serverless function.

17 . The apparatus of claim 14 , further comprising instructions executable by the processor to cause the apparatus to prevent or stop execution of the first serverless function based on detection of at least one of the vulnerability and the insecure configuration of the first serverless function.

18 . The apparatus of claim 14 , wherein the receipt of the request to scan the one or more serverless functions is based on deployment of or update to of the one or more serverless functions.

19 . The apparatus of claim 14 , wherein the request indicates at least one of the one or more serverless functions, an application that comprises the one or more serverless functions, and a cloud provider with which the one or more serverless functions are associated.

20 . The apparatus of claim 14 , wherein the at least one of the vulnerability and the insecure configuration comprises at least one of sensitive data insecurely stored in at least one of code and a configuration of the first serverless function, known vulnerabilities in third-party libraries, an overprivileged role, weak encryption, improper exception handling, a potential data leakage source, and usage of an insecure third-party service.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2024
From: TWISTLOCK LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 068685/0195 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2024
From: SHULMAN, AVRAHAM; SEGAL, ORY; ZIN, SHAKED YOSEF
To: TWISTLOCK LTD.
Reel/Frame 067275/0597 →
Continuity (4)
Continuation 16024863 · Jul 1, 2018
Provisional Application 62528244 · Jul 3, 2017
Provisional Application 62528235 · Jul 3, 2017
Related Publication 20240291868A1 · Aug 29, 2024
References Cited (54)
US 7113994B1 · Swift et al. · 2006 [cited by applicant]
US 7912971B1 · Dunn · 2011 [cited by applicant]
US 8024186B1 · De Bonet · 2011 [cited by applicant]
US 8474018B2 · Mardikar et al. · 2013 [cited by applicant]
US 10255422B1 · Last et al. · 2019 [cited by applicant]
US 10430727B1 · Fusillo et al. · 2019 [cited by applicant]
US 10649861B1 · Natanzon et al. · 2020 [cited by applicant]
US 10715542B1 · Wei et al. · 2020 [cited by applicant]
US 10771468B1 · Walker et al. · 2020 [cited by applicant]
US 10782934B1 · Chawda et al. · 2020 [cited by applicant]
US 10860433B1 · Lieberman et al. · 2020 [cited by applicant]
US 11144513B1 · Padisetty et al. · 2021 [cited by applicant]
US 20040168082A1 · Foster et al. · 2004 [cited by applicant]
US 20050108678A1 · Goodwin et al. · 2005 [cited by applicant]
US 20060288404A1 · Kirshnan et al. · 2006 [cited by applicant]
US 20080127292A1 · Cooper et al. · 2008 [cited by applicant]
US 20080313716A1 · Park · 2008 [cited by applicant]
US 20090177721A1 · Mimatsu et al. · 2009 [cited by applicant]
US 20090222894A1 · Kenny et al. · 2009 [cited by applicant]
US 20090249063A1 · Sakurai et al. · 2009 [cited by applicant]
US 20110055918A1 · Keefe et al. · 2011 [cited by applicant]
US 20110162046A1 · Forster et al. · 2011 [cited by applicant]
US 20120060142A1 · Fliess et al. · 2012 [cited by applicant]
US 20120102539A1 · Robb et al. · 2012 [cited by applicant]
US 20120259877A1 · Raghunathan et al. · 2012 [cited by applicant]
US 20120324540A1 · Wu · 2012 [cited by applicant]
US 20130133024A1 · Macleod et al. · 2013 [cited by applicant]
US 20130219372A1 · Li et al. · 2013 [cited by applicant]
US 20140282889A1 · Ishaya et al. · 2014 [cited by applicant]
US 20140359692A1 · Chari · 2014 [cited by examiner]
US 20140359695A1 · Chari et al. · 2014 [cited by applicant]
US 20150095968A1 · Steiner et al. · 2015 [cited by applicant]
US 20170295181A1 · Parimi et al. · 2017 [cited by applicant]
US 20180113793A1 · Fink et al. · 2018 [cited by applicant]
US 20180115551A1 · Cole · 2018 [cited by examiner]
US 20180121659A1 · Sawhney et al. · 2018 [cited by applicant]
US 20180173806A1 · Forstmann et al. · 2018 [cited by applicant]
US 20180227323A1 · Jevans et al. · 2018 [cited by applicant]
US 20180255102A1 · Ward · 2018 [cited by applicant]
US 20180302277A1 · Shimamura · 2018 [cited by applicant]
US 20190007458A1 · Shulman et al. · 2019 [cited by applicant]
US 20190014171A1 · Stein et al. · 2019 [cited by applicant]
US 20190028552A1 · Johnson, II · 2019 [cited by applicant]
US 20190079744A1 · Bosch · 2019 [cited by applicant]
US 20190188049A1 · Choudhary et al. · 2019 [cited by applicant]
US 20190205186A1 · Zhang et al. · 2019 [cited by applicant]
US 20190332366A1 · Natanzon et al. · 2019 [cited by applicant]
US 20190332781A1 · Natanzon · 2019 [cited by applicant]
US 20190334886A1 · Lelcuk et al. · 2019 [cited by applicant]
US 20190334905A1 · Lelcuk et al. · 2019 [cited by applicant]
US 20190384726A1 · Murphy · 2019 [cited by applicant]
US 20190384912A1 · Branson et al. · 2019 [cited by applicant]
Baldini, et al., “The Serverless Trilemma: Function Composition for Serverless Computing”, Onward! The 2017 ACM SIGPLAN International Symposium on New Ideas, New Paradigms, and Reflections on programming and Software, V… [cited by applicant]
Hall, et al., “An Execution Model for Severless Functions at the Edge”, IoTDI '19: International Conference on Internet of Things Design and Implementation, Montreal QC Canada, retrieved on Apr. 17, 2020 from https://ww… [cited by applicant]