- 专利标题: Cloud security platform with contextual hot-spot permissions analytics
-
申请号: US18132130申请日: 2023-04-07
-
公开(公告)号: US11930017B1公开(公告)日: 2024-03-12
- 发明人: Veranika Hadun , William Bird , Ben Wuest
- 申请人: Sonrai Security Inc.
- 申请人地址: US NY New York
- 专利权人: Sonrai Security Inc.
- 当前专利权人: Sonrai Security Inc.
- 当前专利权人地址: US NY New York
- 代理商 David H. Judson
- 主分类号: H04L9/40
- IPC分类号: H04L9/40
摘要:
A network-accessible service provides an enterprise with a view of identity and data activity in the enterprise's cloud accounts. The service enables distinct cloud provider management models to be normalized with centralized analytics and views across large numbers of cloud accounts. Based on identity and audit data received from a set of cloud deployments, and according to a cloud intelligence model, a set of permissions associated with each of a set of identities are determined. For each identity, and based on a set of identity chains extracted from the cloud intelligence model, a set of identity account action paths (IAAPs) are then determined. An IAAP defines how the identity obtains an ability to perform a given action in a given account. Using the identity account action paths together with context information, one or more roles, groups and accounts in the enterprise that are propagating permissions within the public cloud environment are then identified.
信息查询