US2024048580A1PendingUtilityA1

Detection of escalation paths in cloud environments

Assignee: WIZ INCPriority: Oct 18, 2021Filed: Oct 10, 2023Published: Feb 8, 2024
Est. expiryOct 18, 2041(~15.2 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 67/10G06F 21/577H04L 63/1433H04L 63/20
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for detecting escalation paths in a cloud environment is provided. The method includes accessing a security graph representing cloud objects and their connections in the cloud environment; analyzing each cloud object to detect an escalation hop from a current cloud object to a next cloud object, wherein the analysis is based, in part, on a plurality of risk factors and reachability parameters determined for each cloud object; and marking the security graph with each identified escalation path in the security graph, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for detecting escalation paths in a cloud environment, comprising:
 determining that a first object deployed in a cloud computing environment is exposed to an external network;   detecting a vulnerability on the first object; and   detecting a potential lateral movement path to a second object, based on the exposure and the vulnerability.   
     
     
         2 . The method of  claim 1 , further comprising:
 detecting a permission associated with the first object; and   detecting the potential lateral movement path further based on the detected permission.   
     
     
         3 . The method of  claim 1 , wherein the vulnerability is a known exploit. 
     
     
         4 . The method of  claim 1 , wherein the vulnerability is associated with a software version. 
     
     
         5 . The method of  claim 1 , further comprising:
 detecting sensitive data accessible by any one of: the first object, the second object, and a combination thereof.   
     
     
         6 . The method of  claim 1 , wherein the vulnerability is a wildcard permission. 
     
     
         7 . The method of  claim 1 , wherein the vulnerability is a cloud object configured with a cluster admin role. 
     
     
         8 . The method of  claim 1 , wherein the vulnerability is a cloud access key on a disk of the first object. 
     
     
         9 . The method of  claim 1 , wherein the second object is deployed in a second cloud computing environment. 
     
     
         10 . The method of  claim 9 , wherein the second cloud computing environment is deployed on a second cloud computing infrastructure and the cloud computing environment is deployed on a first cloud computing infrastructure. 
     
     
         11 . A non-transitory computer-readable medium storing a set of instructions for detecting escalation paths in a cloud environment, the set of instructions comprising:
 one or more instructions that, when executed by one or more processors of a device, cause the device to:   determine that a first object deployed in a cloud computing environment is exposed to an external network;   detect a vulnerability on the first object; and   detect a potential lateral movement path to a second object, based on the exposure and the vulnerability.   
     
     
         12 . A system for detecting escalation paths in a cloud environment comprising:
 a processing circuitry; and   a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:   determine that a first object deployed in a cloud computing environment is exposed to an external network;   detect a vulnerability on the first object; and   detect a potential lateral movement path to a second object, based on the exposure and the vulnerability.   
     
     
         13 . The system of  claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
 detect a permission associated with the first object; and   detect the potential lateral movement path further based on the detected permission.   
     
     
         14 . The system of  claim 12 , wherein the vulnerability is a known exploit. 
     
     
         15 . The system of  claim 12 , wherein the vulnerability is associated with a software version. 
     
     
         16 . The system of  claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
 detect sensitive data accessible by any one of: the first object, the second object, and a combination thereof.   
     
     
         17 . The system of  claim 12 , wherein the vulnerability is a wildcard permission. 
     
     
         18 . The system of  claim 12 , wherein the vulnerability is a cloud object configured with a cluster admin role. 
     
     
         19 . The system of  claim 12 , wherein the vulnerability is a cloud access key on a disk of the first object. 
     
     
         20 . The system of  claim 12 , wherein the second object is deployed in a second cloud computing environment. 
     
     
         21 . The system of  claim 20 , wherein the second cloud computing environment is deployed on a second cloud computing infrastructure and the cloud computing environment is deployed on a first cloud computing infrastructure.

Join the waitlist — get patent alerts

Track US2024048580A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.