Detection of escalation paths in cloud environments
Abstract
A method for detecting escalation paths in a cloud environment is provided. The method includes accessing a security graph representing cloud objects and their connections in the cloud environment; analyzing each cloud object to detect an escalation hop from a current cloud object to a next cloud object, wherein the analysis is based, in part, on a plurality of risk factors and reachability parameters determined for each cloud object; and marking the security graph with each identified escalation path in the security graph, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for detecting escalation paths in a cloud environment, comprising:
determining that a first object deployed in a cloud computing environment is exposed to an external network; detecting a vulnerability on the first object; and detecting a potential lateral movement path to a second object, based on the exposure and the vulnerability.
2 . The method of claim 1 , further comprising:
detecting a permission associated with the first object; and detecting the potential lateral movement path further based on the detected permission.
3 . The method of claim 1 , wherein the vulnerability is a known exploit.
4 . The method of claim 1 , wherein the vulnerability is associated with a software version.
5 . The method of claim 1 , further comprising:
detecting sensitive data accessible by any one of: the first object, the second object, and a combination thereof.
6 . The method of claim 1 , wherein the vulnerability is a wildcard permission.
7 . The method of claim 1 , wherein the vulnerability is a cloud object configured with a cluster admin role.
8 . The method of claim 1 , wherein the vulnerability is a cloud access key on a disk of the first object.
9 . The method of claim 1 , wherein the second object is deployed in a second cloud computing environment.
10 . The method of claim 9 , wherein the second cloud computing environment is deployed on a second cloud computing infrastructure and the cloud computing environment is deployed on a first cloud computing infrastructure.
11 . A non-transitory computer-readable medium storing a set of instructions for detecting escalation paths in a cloud environment, the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a device, cause the device to: determine that a first object deployed in a cloud computing environment is exposed to an external network; detect a vulnerability on the first object; and detect a potential lateral movement path to a second object, based on the exposure and the vulnerability.
12 . A system for detecting escalation paths in a cloud environment comprising:
a processing circuitry; and a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to: determine that a first object deployed in a cloud computing environment is exposed to an external network; detect a vulnerability on the first object; and detect a potential lateral movement path to a second object, based on the exposure and the vulnerability.
13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect a permission associated with the first object; and detect the potential lateral movement path further based on the detected permission.
14 . The system of claim 12 , wherein the vulnerability is a known exploit.
15 . The system of claim 12 , wherein the vulnerability is associated with a software version.
16 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect sensitive data accessible by any one of: the first object, the second object, and a combination thereof.
17 . The system of claim 12 , wherein the vulnerability is a wildcard permission.
18 . The system of claim 12 , wherein the vulnerability is a cloud object configured with a cluster admin role.
19 . The system of claim 12 , wherein the vulnerability is a cloud access key on a disk of the first object.
20 . The system of claim 12 , wherein the second object is deployed in a second cloud computing environment.
21 . The system of claim 20 , wherein the second cloud computing environment is deployed on a second cloud computing infrastructure and the cloud computing environment is deployed on a first cloud computing infrastructure.Join the waitlist — get patent alerts
Track US2024048580A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.