Invention Grant
- Patent Title: Cloud data attack detection based on network vulnerability signatures in traced resource network paths
-
Application No.: US18090195Application Date: 2022-12-28
-
Publication No.: US11943240B2Publication Date: 2024-03-26
- Inventor: Ravishankar Ganesh Ithal , Yang Zhang , Mummoorthy Murugesan
- Applicant: Normalyze, Inc.
- Applicant Address: US CA Los Altos
- Assignee: Normalyze, Inc.
- Current Assignee: Normalyze, Inc.
- Current Assignee Address: US CA Los Altos
- Agency: Flagship Patents
- Agent Sikander M. Khan; Chris Volkmann
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F9/451 ; G06F16/21 ; G06F16/245 ; G06F16/35 ; G06F16/95 ; G06F21/57 ; G06F21/62

Abstract:
The technology disclosed relates to streamlined analysis of security posture of a cloud environment. In particular, the disclosed technology relates to accessing permissions data and access control data for pairs of compute resources and storage resources in the cloud environment, tracing network communication paths between the pairs of the compute resources and the storage resources based on the permissions data and the access control data, accessing sensitivity classification data for objects in the storage resources, qualifying a subset of the pairs of the compute resources and the storage resources as vulnerable to breach attack based on an evaluation of the permissions data, the access control data, and the sensitivity classification data against a set risk criterion, and generating a representation of propagation of the breach attack along the network communication paths, the representation identifying relationships between the subset of the pairs of the compute resources and the storage resources.
Public/Granted literature
- US20230134945A1 CLOUD DATA ATTACK DETECTION BASED ON NETWORK VULNERABILITY SIGNATURES IN TRACED RESOURCE NETWORK PATHS Public/Granted day:2023-05-04
Information query