CNIPA.AI
返回搜索
档案

TECHNIQUES FOR DETECTING CLOUD IDENTITY MISUSE BASED ON RUNTIME CONTEXT AND STATIC ANALYSIS

发明专利审中
21权利要求 · 3 独立
§ Ⅰ

卷宗概要

发明人

Ami LUTTWAK; Alon SCHINDEL; Shir TAMARI; Ron COHEN

IPC 分类

G6F 21/56G6F 21/55

CPC 分类

G6F21/568G6F21/552G6F21/563

A system and method for identifying cloud identity misuse based on run-time time data and static analysis is presented. The method includes: detecting a workload in a cloud computing environment; configuring the workload to deploy a sensor configured to detect data respective of a runtime process executed on the workload; detecting an original disk associated with the workload; generating an inspectable disk based on the original disk; inspecting the inspectable disk for a cybersecurity object; detecting in a log of the cloud computing environment an event based on an identifier of the workload; inspecting a code object for an identity object, the code object utilized in deploying the workload in the cloud computing environment; associating the runtime process with the event based on: an identifier of the workload, the identity object, and the cybersecurity object; and generating an enriched log inc

原文(中文)

A system and method for identifying cloud identity misuse based on run-time time data and static analysis is presented. The method includes: detecting a workload in a cloud computing environment; configuring the workload to deploy a sensor configured to detect data respective of a runtime process executed on the workload; detecting an original disk associated with the workload; generating an inspectable disk based on the original disk; inspecting the inspectable disk for a cybersecurity object; detecting in a log of the cloud computing environment an event based on an identifier of the workload; inspecting a code object for an identity object, the code object utilized in deploying the workload in the cloud computing environment; associating the runtime process with the event based on: an identifier of the workload, the identity object, and the cybersecurity object; and generating an enriched log inc