Techniques and methods for detecting and displaying cloud environment network security risk context

By detecting identifiers in the cloud environment in a web page and querying a secure database, non-invasive scanning and displaying network security risks in the cloud environment, the difficulties of asset management and risk identification in the cloud environment are solved, reducing costs and improving efficiency.

CN119921970APending Publication Date: 2025-05-02WIZ INC
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202411539246.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-31
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

In a cloud environment, it is difficult for organizations to accurately identify and maintain asset registrations and their interconnected communication points, and the prior art requires intrusive measures, resulting in high costs and maintenance burdens.

Method used

By detecting multiple identifiers in the web page, starting a query to a secure database, returning a network security risk response, and presenting a representation of network security risks on the display, realizing non-invasive scanning and displaying network security risks in a cloud environment.

Benefits of technology

This method does not require intrusive measures, reduces costs and maintenance burdens, and can effectively detect and display network security risks in cloud environments, helping organizations identify and resolve potential problems in a timely manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119921970A_ABST
    Figure CN119921970A_ABST
Patent Text Reader

Abstract

Techniques and methods for detecting and displaying a cyber-security risk context of a cloud environment utilize a detection environment to initiate detection of cyber-security objects within the cloud environment and store information related to cyber-security objects found within the detected cloud environment in a storage environment. The techniques and methods also generate a cyber-security risk context for the detected cloud environment based on observation of cyber-security objects included in the detected cloud environment. The techniques and methods also configure a web browser running on the client device to enable cloud environment detection through a web page overlay or through a toolbar plug-in installed in the web browser and configured to enable cloud environment detection after the user has navigated to a web page containing a cyber-secure object identifier. And automatically displaying the generated network security risk background to a user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates generally to network security, and more particularly to utilizing non-intrusive scanning techniques to detect and display network security risks in cloud environments. Background Art

[0002] The ability of cloud environments to scale to accommodate an indeterminate amount of deployed assets makes them attractive to organizations that want to maintain flexibility in asset provisioning and realize cost savings by utilizing only the hardware and software they need, when they need it. Azure, Web Services (AWS), Infrastructure provided by CloudPlatform (GCP) and others.

[0003] Due to this dynamic nature, it is difficult to fully grasp the scope of assets deployed in a cloud environment; in particular, the interconnectedness of deployed assets and the network paths formed by them.

[0004] As a result, organizations often struggle to identify the risk profile associated with a specific cloud environment.

[0005] Due to the dynamic nature of cloud-based hardware and software, it is difficult for humans to accurately maintain a registry of assets that already exist in a cloud environment and their various interconnected communication points.

[0006] Furthermore, current techniques for assisting humans in identifying asset risks associated with an organization's cloud environment often require invasive measures; these measures include installing persistent agents, running resource-intensive monitoring tools as services or daemons, configuring systems, processes or services responsible for generating security alerts and incident reports when appropriate, and combinations of the above.

[0007] These various risk mitigation measures often have additional costs; they are themselves expensive to maintain from both a financial and human capital perspective, and are often deployed as SaaS solutions, which can quickly increase monthly infrastructure expenditures.

[0008] Therefore, it would be highly advantageous to provide a solution that overcomes the above challenges. Summary of the invention

[0009] The following is a summary of several example embodiments of the present disclosure. This summary is intended to facilitate the reader to have a basic understanding of these embodiments and does not completely limit the scope of the present disclosure. This summary is not an extensive overview of all contemplated embodiments, and is neither intended to identify the key or important elements of all embodiments nor to describe the scope of any or all aspects. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to a more detailed description presented later. For convenience, the term "some embodiments" or "certain embodiments" may be used herein to refer to a single embodiment or multiple embodiments of the present disclosure.

[0010] A system of one or more computers may be configured to perform specific operations or actions by installing software, firmware, hardware, or a combination thereof on the system that, when in operation, causes the system to perform those actions. One or more computer programs may be configured to perform specific operations or actions by including instructions that, when executed by data processing devices, cause those data processing devices to perform those actions.

[0011] In a general aspect, the method may include detecting a plurality of identifiers in a web page, each identifier corresponding to a cloud entity deployed in a cloud computing environment. The method may also include initiating a query to a security database based on one of the plurality of identifiers, wherein the security database includes a representation of the cloud computing environment. The method may also include executing the query on the security database to return a response, wherein the response includes a cybersecurity risk. The method may also include presenting a representation of the cybersecurity risk on a display associated with the web page based on the response. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0012] Implementations may include one or more of the following features. The method may also include presenting a representation of a cybersecurity risk on a security toolbar. The method may include presenting the representation of a cybersecurity risk as a web page overlay. The method may include determining a remedial action based on the cybersecurity risk. The method may include initiating a remedial action in a cloud computing environment. The method may include extracting a data field value associated with one of a plurality of identifiers. The method may include generating a query based on the extracted data field value. The method may include configuring a client device displaying a web page to install an extension, wherein the extension is configured to perform detection of a plurality of identifiers in the web page. The method may include generating a query based on a first identifier of a plurality of identifiers, wherein the query includes filtering based on a second identifier of a plurality of identifiers. Implementations of the described technology may include hardware, methods, or programs, or computer tangible media.

[0013] In a general aspect, a non-transitory computer-readable medium may include one or more instructions that, when executed by one or more processors of a device, cause the device to: detect multiple identifiers in a web page, each identifier corresponding to a cloud entity deployed in a cloud computing environment. The medium may also initiate a query to a security database based on one of the multiple identifiers, wherein the security database includes a representation of the cloud computing environment. In addition, the medium may perform a query on the security database to return a response, wherein the response includes a cybersecurity risk. In addition, the medium may present a representation of the cybersecurity risk on a display associated with the web page based on the response. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0014] In a general aspect, a system may include a processing circuit. The system may also include a memory including instructions that, when executed by the processing circuit, configure the system to: detect multiple identifiers in a web page, each identifier corresponding to a cloud entity deployed in a cloud computing environment. In addition, the system may initiate a query to a security database based on one of the multiple identifiers, wherein the security database includes a representation of the cloud computing environment. In addition, the system may perform a query on the security database to return a response, wherein the response includes a cybersecurity risk. The system may also present a representation of the cybersecurity risk on a display associated with the web page based on the response. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0015] Implementations may include one or more of the following features. The memory in the system includes further instructions that, when executed by the processing circuit, further configure the system to present a representation of the cybersecurity risk on a security toolbar. The memory in the system includes further instructions that, when executed by the processing circuit, further configure the system to present the representation of the cybersecurity risk as a web page overlay. The memory in the system includes further instructions that, when executed by the processing circuit, further configure the system to determine a remedial action based on the cybersecurity risk. The memory in the system includes further instructions that, when executed by the processing circuit, further configure the system to initiate a remedial action in a cloud computing environment. The memory in the system includes further instructions that, when executed by the processing circuit, further configure the system to extract a data field value associated with one of the plurality of identifiers. The memory in the system includes further instructions that, when executed by the processing circuit, further configure the system to generate a query based on the extracted data field value. The memory in the system includes further instructions that, when executed by the processing circuit, further configure the system to: configure a client device displaying a web page to install an extension, wherein the extension is configured to perform detection of a plurality of identifiers in the web page. The memory in the system includes further instructions that, when executed by the processing circuit, further configure the system to: generate a query based on a first identifier in the plurality of identifiers, wherein the query includes filtering based on a second identifier in the plurality of identifiers. Implementations of the described technology may include hardware, methods, or programs or computer tangible media. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The subject matter disclosed in this specification is particularly pointed out and clearly set forth in the claims at the end of this specification. The above and other objects, features and advantages of the disclosed embodiments are apparent from the following detailed description in conjunction with the accompanying drawings.

[0017] Figure 1 is an example schematic diagram illustrating a system for displaying cybersecurity risk context of a first cloud environment for describing an embodiment.

[0018] Figure 2 is an example graphical representation of a browser including a security toolbar 201 for describing an embodiment.

[0019] Figure 3 The following is a flow chart for describing a method for detecting network security objects in a cloud computing environment according to an embodiment of the present invention.

[0020] Figure 4 The following is a flow example for describing a method for detecting network security risks of a cloud environment according to an embodiment.

[0021] Figure 5A is an example flow of a method for presenting cybersecurity risk context via a toolbar plug-in according to an embodiment.

[0022] Figure 5B The following is an example process of a method for presenting cybersecurity risk context via updating a web page display according to an embodiment.

[0023] Figure 6 is an example flow of a method for initiating an action through a browser extension according to an embodiment.

[0024] Figure 7 is an example graphical interface of a web page including a web security toolbar extension implemented according to an embodiment.

[0025] Figure 8 is an example schematic diagram of a system according to an embodiment. DETAILED DESCRIPTION

[0026] It is important to note that the embodiments disclosed herein are merely examples of multiple advantageous uses of the innovative teachings herein. In general, statements in the specification of this application do not necessarily limit any of the various claimed embodiments. In addition, some statements may apply to some inventive features but not to other features. In general, unless otherwise indicated, singular elements may be plural and vice versa without loss of generality. In the accompanying drawings, the same numbers refer to the same parts in different views.

[0027] Various disclosed embodiments include techniques and methods for detecting and displaying cybersecurity risk context of a cloud environment using a non-intrusive scanning process.

[0028] Figure 1 1 is an example schematic diagram showing a system for displaying a cybersecurity risk context of a first cloud environment for describing an embodiment. In an embodiment, a cloud computing environment 100 includes cloud entities, such as resources, clients, etc. In an embodiment, resources include access to hardware resources of the environment, such as processors, memory, storage devices, combinations thereof, etc.

[0029] In some embodiments, a principal refers to an entity that is authorized to take actions on a resource. For example, in an embodiment, a principal refers to a user account, a service account, a role, a combination thereof, and the like.

[0030] In an embodiment, the cloud computing environment 100 is a virtual private cloud (VPC), a virtual network (VNet), a combination thereof, and the like. Web Services (AWS), Azure, The cloud computing environment 100 is implemented on a cloud computing infrastructure such as Cloud Platform (GCP) and combinations thereof.

[0031] According to an embodiment, cloud computing environment 100 includes resources such as virtual machines 102, serverless functions 103, and software containers 104. In an embodiment, virtual machines 102 are implemented as In some embodiments, the serverless function 103 is Functions, etc. In an embodiment, the software container 104 is implemented as engine, Platforms and their combinations, etc.

[0032] In an embodiment, the computing environment 100 is a cloud computing environment, a network computing environment, a hybrid computing environment, a pre-built computing environment, a combination thereof, and the like.

[0033] According to an embodiment, the cloud computing environment 100 is monitored, detected, etc. through the detection environment 101. In an embodiment, the detection environment 101 is configured to detect the computing environment 100 for network security objects, network security threats, and combinations thereof. For example, according to an embodiment, network security threats include network security risks, configuration errors, vulnerabilities, exposures, and combinations thereof.

[0034] In some embodiments, the network security object is a software component, software code, application, operating system, image, certificate, password, malware, combination thereof, or the like.

[0035] In some embodiments, the detection environment 101 includes multiple detectors, such as a detector 105, a detection controller 106, and a security database 107. In an embodiment, the detector 105 is implemented as a workload, a resource, etc., and is configured to detect a network security object. According to an embodiment, the detector 105 is configured to detect a network security object, multiple network security objects, etc.

[0036] In some embodiments, the detection controller 106 is implemented as a workload, a resource, etc., and is configured to: detect the workload, the resource, etc. in the computing environment 100, generate a request to provide a detector workload, allocate the detector 105 to detect the workload of the computing environment 100, and combinations thereof, etc.

[0037] In some embodiments, secure database 107 includes a representation of computing environment 100. For example, according to an embodiment, secure database 107 is implemented as a graph database, such as And includes database constraints, database schemas, data templates, etc., so as to be used to generate a representation of the computing environment 100.

[0038] For example, according to an embodiment, the representation includes generating nodes in a graph to represent resources, and generating connections between nodes to represent the relationship between a first resource and a second resource, the relationship between a first resource and a first principal, the relationship between a first principal and a second principal, etc.

[0039] In some embodiments, the security database 107 also includes enriched content, such as endpoint detection, public network access representation, network security risk representation, remediation action representation, and various combinations thereof, etc. In an embodiment, each representation is generated based on a predefined data schema, which provides a unified data model that represents multiple different cloud entities, entity types, etc. in a unified manner.

[0040] For example, according to an embodiment, each resource is represented as a resource entity, regardless of whether the resource is a virtual machine deployed in Azure, a virtual machine deployed in AWS, a software container using Docker, a software container using Kubernetes, etc.

[0041] In an embodiment, the client device 108 is configured to access a representation of the computing environment 100 stored in the secure database 107. In some embodiments, the client device 108 is a computing device, including an I / O interface (e.g., a mouse, keyboard, etc.), a display, a processor, memory, storage devices, etc. In an embodiment, the client device 108 is a personal computer, a laptop, a desktop, a tablet, a smartphone, etc.

[0042] According to an embodiment, the client device 108 includes a web browser 109. In an embodiment, the web browser 109 is configured to display web pages, hypertext markup language documents, etc. In an embodiment, the web browser also includes a plug-in 110 (also called an extension). In an embodiment, the plug-in 110 is implemented as software code, software module, etc., configured to communicate with the web browser 109 software and provide additional functions beyond the existing functions of the web browser 109.

[0043] For example, according to an embodiment, the plug-in 110 is configured to generate an overlay, a toolbar, a combination thereof, etc. In some embodiments, the overlay, the toolbar, etc. are generated based on a web page accessed by the web browser 109 .

[0044] In an embodiment, the plug-in 110 is configured to detect information from a web page requested by the web browser 109. In some embodiments, the plug-in 110 is configured to detect information only from web pages associated with a predetermined domain, a predetermined list of domains, a predetermined IP address, a predetermined list of IP addresses, combinations thereof, etc. For example, in an embodiment, the plug-in 110 is configured to read only web pages requested via a URL containing an "aws" field in the URL.

[0045] In an embodiment, the plug-in 110 is configured to parse the web page and detect the value of the predetermined data field. For example, in an embodiment, the value is a unique identifier of the virtual machine, and the predetermined data field is a data field indicating the name of the virtual machine, such as "VM name". Figure 6 This example is discussed in more detail.

[0046] For example, according to an embodiment, the plug-in 110 is configured to read a document object model (DOM), detect data fields in the DOM, and extract values ​​from the web page based on the detected data fields.

[0047] In some embodiments, the plug-in 110 is configured to provide values ​​from a web page, for example, to the detection environment 101. In other embodiments, the plug-in 110 is configured to generate a query for the security database 107 based on the detected value in the web page. In some embodiments, the plug-in 110 is configured to generate a query for the security database 107 based on a query template, wherein the query is generated based on the detected value.

[0048] In an embodiment, the plug-in 110 is configured to display, for example, a response received from the detection environment 101 based on the generated query in a display of the client device 108. For example, according to an embodiment, the plug-in 110 is configured to update a toolbar, an overlay, a combination thereof, etc. based on the results of executing the generated query on the security database 107.

[0049] In some embodiments, the plug-in 110 is further configured to request login credentials from the client device 108 in order to access the secure database 107. In an embodiment, the plug-in 110 is configured to send a query to the detection environment only in response to a successful validation of the login credentials provided to the plug-in 110. In some embodiments, the plug-in 110 configures the client device 108 to store a token, cookie, etc. thereon indicating that the user session includes successfully validated login credentials.

[0050] Figure 2 2 is an example graphical representation of a browser 200 including a security toolbar 201 for describing an embodiment. In an embodiment, the browser 200 is configured to navigate to a web page displaying various cloud entities associated with a cloud computing environment, such as the cloud computing environment 100. Figure 1 This is discussed in more detail.

[0051] In some embodiments, browser 200 is implemented as a software application running on an operating system, such as Browser, Browser, etc.

[0052] In other embodiments, the browser 200 is implemented by embedding an operating system, such as: Embedded in OS Browser, etc.

[0053] In an embodiment, the cloud entities displayed are cloud entities deployed in a cloud computing environment. For example, in an embodiment, a web page is displayed on a browser 200, including representations of multiple virtual machines 202-1 to 202-N, where "N" is an integer with a value of 2 or greater.

[0054] In some embodiments, the displayed web page also includes an image 204 from which the workload is deployed. In some embodiments, the web page includes representations of a plurality of serverless functions 205-1 through 205-M, where "M" is a value of 2 or greater.

[0055] According to an embodiment, the webpage also includes a representation of the logo 207, a representation of the virtual private cloud 208, a representation of the sub-network 209, and combinations thereof.

[0056] In some embodiments, the web page representation is a visual representation generated based on the value of the web page data field. In an embodiment, the plug-in, extension, etc. is configured to read the web page, detect the data field, extract the value from the detected data field, and generate a query to the security database using the extracted value.

[0057] In an embodiment, a plug-in, extension, or the like is configured to generate a visual representation, for example, in the security toolbar 201. For example, in an embodiment, an identifier of the virtual machine 202-1 and an identifier of the serverless function 205-1 are extracted from a web page.

[0058] According to an embodiment, the plug-in, extension, etc. is configured to generate a query to a secure database based on the extracted data field value (e.g., the extracted name). In some embodiments, the extracted value is provided to a secure database, which is configured to generate a query based on the extracted data field value sent.

[0059] In an embodiment, a query is performed in a secure database including values ​​extracted from the web page. In some embodiments, a response is received from the secure database, wherein the response includes the identified network security risk. For example, in an embodiment, the detector is configured to detect a network security risk of virtual machine 202-1.

[0060] According to an embodiment, in response to detecting a network security risk on virtual machine 202 - 1 , the detector is configured to update a representation of virtual machine 202 - 1 in a security database to indicate that virtual machine 202 - 1 includes a network security risk.

[0061] In an embodiment, a result is received from a security database to indicate that a network security risk is detected on virtual machine 202-1. In some embodiments, the plug-in, extension, etc. is also configured to display a total value. For example, in an embodiment, the security toolbar 201 includes a representation indicating the number of vulnerabilities detected with a high priority, the number of vulnerabilities detected with a medium priority, the number of vulnerabilities detected with a low priority, and combinations thereof.

[0062] According to an embodiment, when navigating to such a web page, the plug-in, extension, etc. is configured to update the security toolbar 201 to provide a network security context for the entire cloud environment represented by the relevant assets displayed on the web page (e.g., by detecting an entity identifier and querying a security database to detect issues indicated by the detected entity in the security database).

[0063] Generating toolbars, overlays, etc., to provide network security context for the representation of the cloud environment is advantageous because it provides a non-intrusive and engaging experience for the user. In addition, according to an embodiment, such a representation of network security context allows more information to be efficiently conveyed to the user.

[0064] Figure 3 The present invention is a flow example for describing a method for detecting network security objects in a cloud computing environment according to an embodiment. In an embodiment, detecting network security objects in resources, workloads, etc. of a cloud computing environment is an indication of network security risks, vulnerabilities, exposures, combinations thereof, etc.

[0065] At S301 , detection of workloads in a cloud environment is initiated. In an embodiment, a detection controller such as detection controller 106 configures a detector such as detector 105 to detect workloads, so that detector 105 can detect network security objects in a cloud computing environment (such as computing environment 100 ).

[0066] According to an embodiment, the workload is a virtual machine, a software container, a serverless function, a combination thereof, etc. In some embodiments, the network security object is a software application, a software application type, an operating system, an operating system type, a certificate, an encryption key, a password, a hash value, a user identifier, a registry file, a binary file, a library, a combination thereof, etc.

[0067] At S302, a network security object is detected. In an embodiment, a network security object is detected on a workload deployed in a cloud environment. For example, according to an embodiment, the detection controller is configured to generate a detectable disk based on, for example, a replica, a copy, a snapshot, etc. of a disk associated with the workload. In an embodiment, the detectable disk is detected for the network security object.

[0068] In an embodiment, the detector is configured to detect a single network security object, multiple network security objects, etc. In some embodiments, the first detector is configured to detect a first network security object in the workload and the second detector is configured to detect a second network security object in the workload that is not the first network security object.

[0069] At S303, a representation of the workload is stored in a secure database. According to an embodiment, the secure database utilizes, for example, Implemented as a security graphic.

[0070] In an embodiment, the security database can be implemented as security database 107. In some embodiments, a representation of the detection workload is stored in the security database, the representation including information detected in the detection workload, workload parameters (e.g., metadata), and combinations thereof, etc. In some embodiments, the representation is generated based on a predefined data pattern. For example, in an embodiment, a virtual machine is represented by a node in a security graph, where a node is used to represent a resource in the security graph.

[0071] According to an embodiment, elements constituting a security graph are represented as nodes and vertices, and a node represents a detected network security object of a plurality of network security objects already existing in the detected cloud environment.

[0072] For example, a first node representing a detection network security object is connected to a vertex that is connected at the other end to another node representing a different detection network security object that has a relationship with the network security object represented by the first node.

[0073] In this manner, a security graph showing relationships between network security objects in a cloud environment can be composed of a plurality of nodes and a plurality of vertices.

[0074] At S304, a representation of the detected network security object is stored in a security graph.

[0075] According to an embodiment, a representation of a detected network security object, for example an object detected in S302, is stored in the security graph. The representation of the detected network security object is associated with a representation of a workload on which the network security object was detected.

[0076] In an embodiment, the representation of a detected network security object includes: a unique identifier of the object in a cloud environment (e.g., a software application identifier, a version identifier, etc.), an intrinsic type attribute of the object (such as an executable, a readable file, etc.), metadata of the object, a hash signature of the object, and a combination thereof, etc.

[0077] In an embodiment, the security database includes a representation of a computing environment (such as a cloud computing environment), which can be queried to detect network security risks, vulnerabilities, exposures, etc. for specific workloads, specific sub-networks, entire computing environments, combinations thereof, and the like.

[0078] Figure 4 The following is a flow example for describing a method for detecting network security risks of a cloud environment according to an embodiment.

[0079] At S401, a network security object is detected on a workload. In an embodiment, the network security object is detected on a resource, a workload, etc. For example, according to an embodiment, a detector configured to detect the network security object detects the workload.

[0080] In some embodiments, the network security object is a software application, a software application type, an operating system, an operating system type, a certificate, an encryption key, a password, a hash value, a user identifier, a registry file, a binary file, a library, a combination thereof, or the like.

[0081] In an embodiment, the workload is used, for example, to Figure 3 The method described in detail detects a network security object. For example, in an embodiment, a detector workload is configured to detect a network security object on a detectable disk, wherein the detectable disk is generated based on a disk associated with the workload.

[0082] According to an embodiment, the detectable disk is generated based on a replica, copy, snapshot, etc. of a disk associated with the workload. In an embodiment, the detector is configured to release resources associated with the detectable disk in response to determining that the detection of the detectable disk is complete.

[0083] At S402, a network security risk is determined. In an embodiment, the network security risk is determined based on detecting a network security object. For example, according to an embodiment, a first object detected on the workload is a software application version. In an embodiment, the first object indicates that the workload is vulnerable to attack, where there is a known vulnerability associated with the software application version detected by the detector. For example, the known vulnerability is detected by utilizing a Common Vulnerabilities and Exposures (CVE) database.

[0084] In some embodiments, a network security risk is determined based on detecting a plurality of network security objects. For example, in an embodiment, a database executed on a workload and another software with a known vulnerability are detected, allowing together to provide unexpected access to the database, thereby creating an exposure. In an embodiment, a combination of network security objects indicates a network security risk, indicates a severity of a network security risk, and combinations thereof, etc.

[0085] In an embodiment, network security risk determination is a qualitative assessment of multiple network security object attributes, such as: the type of detection object, the connectivity of the object with other objects in the cloud environment, the criticality of the object to the stability of the entire cloud environment, and combinations thereof.

[0086] In some embodiments, a network security severity score is determined. For example, in an embodiment, a first class network security object and a second class network security object detected simultaneously on a single workload indicate a network security risk that is more severe than either network security object itself.

[0087] At S403, the network security risk is associated with the workload. In an embodiment, the network security risk is represented in a security database. For example, in an embodiment, the network security risk is represented as a node in a security graph, as a data field in a security database, a data field value, and a combination thereof.

[0088] In some embodiments, on a representation of a workload where a cybersecurity object is detected, a cybersecurity risk is represented as metadata associated with the representation of the workload where the cybersecurity risk is detected, or the like.

[0089] According to an embodiment, a security graph provides the ability to store a cybersecurity risk assessment as a node and connect the node via a vertex to another node already existing in the security graph, where the other node represents a detection workload, detects cybersecurity objects from the detection workload, and utilizes these cybersecurity objects to perform risk determination.

[0090] Figure 5A The present invention is an example process of a method for presenting cybersecurity risk context via a toolbar plug-in according to an embodiment. In an embodiment, plug-ins, extensions, add-ons, etc. are used to describe various software components, software codes, and combinations thereof, etc., which extend the basic functionality of another software application (such as a web browser).

[0091] For example, according to an embodiment, a web browser extension is configured to detect an identifier of a computing environment entity in a web page, initiate a query using a security graphic based on the detected identifier, and present the query results through the web browser, such as as a toolbar, the security graphic including a representation of the computing environment.

[0092] At S501A, a cloud entity identifier is detected. In an embodiment, the cloud entity identifier is detected on a web page. In some embodiments, the cloud entity is implemented as an entity name, a unique identifier, a hash, an alias, an IP address, etc.

[0093] According to an embodiment, the cloud entity identifier is detected using network crawling technology, page information analysis when the page is loaded, reading of markup language (e.g., HTML) documents, data packet detection, document object model (DOM) of web pages, and combinations thereof. In some embodiments, multiple different cloud identifiers are detected.

[0094] At S502A, a query is generated. According to an embodiment, the query is generated based on a query template. For example, in an embodiment, a pre-stored query template is modified based on the detected cloud entity identifier.

[0095] In an embodiment, a query is performed in a secure database, wherein the secure database includes a representation of a cloud computing environment in which a cloud entity associated with a cloud entity identifier is deployed.

[0096] In certain embodiments, the query is generated using structured query language, natural language processing, or the like.

[0097] According to an embodiment, a detected cloud entity identifier (such as the identifier detected at S501A) is used to construct, modify, adjust, etc. a query, which is then executed on the secure database.

[0098] In an embodiment, the performed query returns a query response. According to an embodiment, the query response includes information, data, etc. related to the detected cloud entity corresponding to the identifier used in the query.

[0099] In an embodiment, the query response includes a location of the entity in the cloud environment, exposure of the entity to other entities in the cloud environment, exposure of the entity, cybersecurity risks associated with the entity, cybersecurity objects associated with the entity, a total value indicating a number of cybersecurity risks, vulnerabilities, misconfigurations, exposures, etc., a total value indicating a number of workloads having a first severity score, a number of workloads having a second severity score, such as Figure 4 The calculated entity qualitative risk score described in S402, and combinations thereof, etc.

[0100] At S503A, the toolbar display is updated. In an embodiment, the display data in the toolbar of the client device displaying the web page is updated using the received query result.

[0101] In some embodiments, the toolbar includes a plurality of data fields, each data field corresponding to a predetermined metric. For example, according to an embodiment, the metric is the number of workloads with a particular vulnerability, the total number of workloads with a first vulnerability, the total number of workloads with a second vulnerability, the total number of workloads with a vulnerability of a first severity score, the total number of workloads with a vulnerability of a second severity score, and combinations thereof.

[0102] In an embodiment, the toolbar is configured to display a calculated risk profile of the cloud environment represented by the detected identifier on the currently displayed web page. In an embodiment, the calculated risk profile is a qualitative assessment generated by detecting network security objects detected in the cloud environment, such as Figure 3 shown.

[0103] In some embodiments, the toolbar displays periodic updates, continuous updates, etc. In some embodiments, the toolbar includes a link, URL, etc. that directs a web browser to a web page of the detection environment, wherein the web page of the detection environment is configured to display further information related to the network security issues detected on the specific workload.

[0104] Figure 5B The following is an example process of a method for presenting cybersecurity risk context via updating a web page display according to an embodiment.

[0105] At S501B, a cloud entity identifier is detected. In an embodiment, the cloud entity identifier is detected on a web page. In some embodiments, the cloud entity is implemented as an entity name, a unique identifier, a hash, an alias, an IP address, etc.

[0106] According to an embodiment, the cloud entity identifier is detected using network crawling technology, page information analysis when the page is loaded, reading of markup language (e.g., HTML) documents, data packet detection, document object model (DOM) of web pages, and combinations thereof. In some embodiments, multiple different cloud identifiers are detected.

[0107] At S502B, a query is generated. According to an embodiment, the query is generated based on a query template. For example, in an embodiment, a pre-stored query template is modified based on the detected cloud entity identifier.

[0108] In an embodiment, a query is performed in a secure database, wherein the secure database includes a representation of a cloud computing environment in which a cloud entity associated with a cloud entity identifier is deployed.

[0109] In certain embodiments, the query is generated using structured query language, natural language processing, or the like.

[0110] According to an embodiment, a detected cloud entity identifier (such as the identifier detected at S501B) is used to construct, modify, adjust, etc. a query, which is then executed on the secure database.

[0111] In an embodiment, the performed query returns a query response. According to an embodiment, the query response includes information, data, etc. related to the detected cloud entity corresponding to the identifier used in the query.

[0112] In an embodiment, the query response includes a location of the entity in the cloud environment, exposure of the entity to other entities in the cloud environment, exposure of the entity, cybersecurity risks associated with the entity, cybersecurity objects associated with the entity, a total value indicating a number of cybersecurity risks, vulnerabilities, misconfigurations, exposures, etc., a total value indicating a number of workloads having a first severity score, a number of workloads having a second severity score, such as Figure 4 The calculated entity qualitative risk score described in S402, and combinations thereof, etc.

[0113] At S503B, the web page display is updated. In an embodiment, the web page is updated using the received query result. For example, in an embodiment, updating the web page includes generating a new web page based on the received result of executing the query in the secure database, generating an iframe in an existing web page, generating an overlay on the existing web page, and combinations thereof.

[0114] In some embodiments, the updated web page display includes a plurality of data fields, each data field corresponding to a predetermined metric. For example, according to an embodiment, the metric is the number of workloads having a particular vulnerability, the total number of workloads having a first vulnerability, the total number of workloads having a second vulnerability, the total number of workloads having a vulnerability with a first severity score, the total number of workloads having a vulnerability with a second severity score, and combinations thereof.

[0115] In an embodiment, the updated web page display is configured to display the calculated risk profile of the cloud environment represented by the detected identifier on the currently displayed web page. In an embodiment, the calculated risk profile is a qualitative assessment generated by detecting network security objects detected in the cloud environment, such as Figure 3 shown.

[0116] In some embodiments, the updated web page display is updated periodically, continuously, etc. In some embodiments, the updated web page display includes a link, URL, etc. that directs a web browser to a web page of the detection environment, wherein the web page of the detection environment is configured to display further information related to the network security issue detected on the specific workload.

[0117] Figure 6 The following is an example flow of a method for initiating an action through a browser extension according to an embodiment. In an embodiment, the action includes the generation and execution of computer instructions, such as implemented as software, firmware, middleware, microcode, hardware description language, dynamic language, and combinations thereof.

[0118] At S601, a cloud entity identifier is detected. According to an embodiment, the cloud entity identifier is detected in the web page by an extension, a plug-in, etc., and the extension, the plug-in, etc. is configured to detect the cloud entity identifier. The detection of the cloud entity identifier will be discussed in detail below.

[0119] In an embodiment, the cloud entity identifier is used to query the security database to detect a representation of the cloud entity having the cloud entity identifier. In some embodiments, the query is used to detect additional entities, representations, etc. connected to the representation of the cloud entity in the security database. For example, in an embodiment, the query is directed to the security database to detect another entity connected to the representation of the cloud entity, detect a network security object representation connected to the representation of the cloud entity, detect a network security threat, detect a network security risk, detect a combination thereof, etc.

[0120] In some embodiments, an extension, plugin, or the like is configured to detect a cloud entity identifier and send the detected identifier to a detection environment configured to generate a query to a secure database, wherein the secure database includes a representation of a computing environment in which the cloud entity is deployed.

[0121] In some embodiments, an extension, plugin, etc. is configured to detect a cloud entity identifier and generate a query provided to a secure database for execution. In an embodiment, the query is generated based on the cloud entity identifier and a predefined query template, a set of predefined query templates, combinations thereof, and the like.

[0122] According to an embodiment, the query is configured to return results indicating network security issues associated with the cloud entity of the cloud entity identifier. For example, in an embodiment, the network security issues are threats, risks, vulnerabilities, exposures, configuration errors, combinations thereof, and the like.

[0123] At S602, an action is determined for a cloud entity. In an embodiment, the action is determined based on a return result received in response to executing a query on a secure database, wherein the query includes a cloud entity identifier.

[0124] In some embodiments, the action includes initiating the action, generating instructions to initiate the action, and combinations thereof. In an embodiment, the action includes determining a remediation action based on the network security issue, determining multiple remediation actions based on the network security issue, generating a visual representation of remediation action suggestions, and combinations thereof.

[0125] In some embodiments, the action includes receiving a selection of a remedial action.In an embodiment, the extension, plugin, etc. is further configured to generate a textual input (eg, a text box) that receives text input.

[0126] In an embodiment, a textual input is received, such as a structured query language input, a natural language input, a cloud entity identifier, and a combination thereof. In some embodiments, the textual input is used as a prompt for a large language model (LLM). In some embodiments, the prompt also includes a database schema of a secure database.

[0127] In some embodiments, prompts are generated based on textual input, cloud identifiers, predetermined prompt templates, combinations thereof, and the like. For example, according to an embodiment, the textual input is received via a browser extension. The browser extension is configured to send the textual input to a detection environment, where the textual input is provided to the LLM, for example, as part of the prompt. In an embodiment, the LLM is configured to generate outputs based on the prompts, such as generating a suggested remedial action, generating a query to a security database, and combinations thereof.

[0128] At S603, an action is performed. In an embodiment, an action, a plurality of actions, etc. are performed. In some embodiments, the action is determined and performed continuously. For example, in an embodiment, the action is determined and performed continuously during a single browsing session.

[0129] In some embodiments, performing the action includes initiating the action in a cloud environment, in a detection environment, combinations thereof, etc. In certain embodiments, performing the action includes generating instructions that, when executed, configure a workload (such as a virtual machine, a serverless function, a software application, etc.) to perform the action.

[0130] Figure 7 708 is an example graphical interface of a web page including a web security toolbar extension implemented according to an embodiment. According to an embodiment, a web browser is configured to display a web page, for example, based on a uniform resource locator (URL) 708. In an embodiment, the web page includes a plurality of data field identifiers, such as a resource tag 705, an account attribute tag 706, and the like.

[0131] In an embodiment, a data field value is extracted from each tag, each data field, etc. For example, resource tag 705 includes a data field indicating a resource such as a running instance, a load balancer, a volume, etc. In an embodiment, each such value is used to query a secure database. Such a data field value (e.g., "volume") is used to filter the query results.

[0132] In some embodiments, the data field value provides a unique identifier of the cloud entity. For example, in an embodiment, the account attribute tag 706 includes a data field "Default VPC" (e.g., a VPC cloud entity) having a first value 707 (e.g., vpc-6a00c317). In an embodiment, the first value 707 is used to query a security database to detect a representation of a resource (e.g., based on the resource tag 705) of the cloud entity (e.g., VPC).

[0133] In some embodiments, an extension, plugin, etc. is configured to generate a security toolbar 701. In an embodiment, the security toolbar 701 is generated as an iframe, an overlay, a window, a combination thereof, etc. In some embodiments, the security toolbar 701 includes a visual representation such as an icon and a value associated with the visual representation.

[0134] For example, in an embodiment, the first visualization 702 indicates the number of resources in the VPC that are classified as high-severity vulnerabilities, the second visualization 703 indicates the number of resources in the VPC that are classified as medium-severity vulnerabilities, and the third visualization 704 indicates the number of resources in the VPC that are classified as low-severity vulnerabilities.

[0135] Figure 8 8 is an example schematic diagram of a system 800 according to an embodiment. The system 800 includes a processing circuit 810 coupled to a memory 820, a storage device 830, and a network interface 840. In an embodiment, the components of the system 800 may be communicatively connected via a bus 850.

[0136] The processing circuit 810 may be implemented as one or more hardware logic components and circuits. For example, but not limited to, example types of hardware logic components that may be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), graphics processing units (GPUs), tensor processing units (TPUs), general purpose microprocessors, microcontrollers, digital signal processors (DSPs), etc., or any other hardware logic components capable of performing computations or other information processing.

[0137] The memory 820 may be volatile (e.g., random access memory, etc.), non-volatile (e.g., read-only memory, flash memory, etc.), or a combination thereof. In an embodiment, the memory 820 is an on-chip memory, an off-chip memory, a combination thereof, etc. In some embodiments, the memory 820 is a temporary memory of the processing circuit 810.

[0138] In a configuration scheme, software for implementing one or more embodiments disclosed herein may be stored in storage device 830, in memory 820, and in a combination thereof. Software should be broadly understood as any type of instruction, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. Instructions may include code (e.g., in source code format, binary code format, executable code format, or any other suitable code format). When executed by processing circuit 610, the instructions cause processing circuit 810 to perform the various processes described herein.

[0139] The storage device 830 is a magnetic storage device, an optical storage device, a solid-state storage device, a combination thereof, etc., and according to an embodiment, the storage device 830 is implemented as a flash memory such as a hard drive, or other memory technology, or any other medium that can be used to store the required information.

[0140] The network interface 840 is configured to provide connectivity with, for example, the computing environment 100 , the detection environment 101 , the various workloads deployed therein, and the like.

[0141] It should be understood that the above architecture may be used to implement various workloads, such as virtual machines 102, serverless functions 103, software containers 104, detectors 105, detection controllers 106, secure databases 107, client devices 108, combinations thereof, and the like.

[0142] It should be understood that the embodiments described herein are not limited to Figure 8 While specific architectures are shown, other architectures may be equally used without departing from the scope of the disclosed embodiments.

[0143] Various embodiments disclosed herein can be implemented as hardware, firmware, software or any combination thereof. In addition, the software is preferably implemented as an application program, which is tangibly embodied in a program storage unit or a computer-readable medium, which is composed of several components, or a combination of certain devices and / or devices. The application program can be uploaded to a machine including any suitable architecture and executed by the machine. Preferably, the machine is implemented on a computer platform, which has hardware such as one or more central processing units ("CPU"), memory and input / output interfaces. The computer platform may also include an operating system and microinstruction codes. The various processes and functions described herein may be part of a microinstruction code, or part of an application program, or any combination thereof, and these codes or programs may be executed by a CPU, whether or not such a computer or processor is explicitly shown. In addition, various other peripheral units may be connected to the computer platform, such as an additional data storage unit and a printing unit. In addition, a non-transient computer-readable medium is any computer-readable medium other than a transient propagation signal.

[0144] All examples and conditional language described herein are intended for teaching purposes to help the reader understand the principles of the disclosed embodiments and the concepts contributed by the inventors to promote the development of the art, and should be understood to be not limited to these specific narrated examples and conditions. In addition, all statements describing the principles, aspects, and embodiments of the disclosed embodiments herein, as well as their specific examples, are intended to cover their structural and functional equivalents. In addition, it is intended that such equivalents include currently known equivalents as well as equivalents developed in the future, i.e., any element developed to perform the same function, regardless of its structure.

[0145] It should be understood that any reference to an element using names such as "first", "second" etc. herein will not generally limit the quantity or order of these elements. On the contrary, these names are generally used as a convenient method to distinguish two or more elements or element instances in this article. Therefore, the reference to the first and second elements does not mean that only two elements can be adopted, nor does it mean that the first element must precede the second element in some way. In addition, unless otherwise stated, a group of elements includes one or more elements.

[0146] As used herein, the phrase "at least one of" following a list of items means that any one of the listed items may be used alone or in any combination of two or more of the listed items may be used. For example, if a system is described as including "at least one of A, B, and C," the system may include only A; only B; only C; 2A; 2B; 2C; 3A; a combination of A and B; a combination of B and C; a combination of A and C; a combination of A, B, and C; a combination of 2A and C; a combination of A, 3B, and 2C; and so on.

Claims

1. A method for presenting a network security background based on a detection web page, comprising: detecting a plurality of identifiers in a web page, each identifier corresponding to a cloud entity deployed in a cloud computing environment; initiating a query to a secure database based on one of the plurality of identifiers, wherein the secure database includes a representation of the cloud computing environment; executing the query on the secure database to return a response, wherein the response includes a cybersecurity risk; as well as Presenting a representation of the network security risk on a display associated with the webpage based on the response.

2. The method according to claim 1, further comprising: A representation of the network security risk is presented on a security toolbar.

3. The method according to claim 1, further comprising: The representation of the cybersecurity risk is presented as a web page overlay.

4. The method according to claim 1, further comprising: A remedial action is determined based on the cybersecurity risk.

5. The method according to claim 4, further comprising: The remedial action is initiated in the cloud computing environment.

6. The method according to claim 1, further comprising: A data field value associated with one of the plurality of identifiers is extracted.

7. The method according to claim 6, further comprising: Generate a query based on the extracted data field values.

8. The method according to claim 1, further comprising: A client device displaying the webpage is configured to install an extension, wherein the extension is configured to detect the plurality of identifiers in the webpage.

9. The method according to claim 1, further comprising: The query is generated based on a first identifier of the plurality of identifiers, wherein the query includes filtering based on a second identifier of the plurality of identifiers.

10. A non-transitory computer readable medium storing a set of instructions for presenting a network security context based on a detected web page, the set of instructions comprising: One or more instructions that, when executed by one or more processors of a device, cause the device to: detecting a plurality of identifiers in a web page, each identifier corresponding to a cloud entity deployed in a cloud computing environment; initiating a query to a secure database based on one of the plurality of identifiers, wherein the secure database includes a representation of the cloud computing environment; executing the query on the secure database to return a response, wherein the response includes a cybersecurity risk; as well as Presenting a representation of the network security risk on a display associated with the webpage based on the response.

11. A system for presenting a network security background based on a detected web page, comprising: Processing circuit; a memory, the memory comprising instructions that, when executed by the processing circuit, configure the system to: detecting a plurality of identifiers in a web page, each identifier corresponding to a cloud entity deployed in a cloud computing environment; initiating a query to a secure database based on one of the plurality of identifiers, wherein the secure database includes a representation of the cloud computing environment; executing the query on the secure database to return a response, wherein the response includes a cybersecurity risk; as well as Presenting a representation of the network security risk on a display associated with the webpage based on the response.

12. The system according to claim 11, wherein: The memory includes further instructions that, when executed by the processing circuit, further configure the system to: A representation of the network security risk is presented on a security toolbar.

13. The system according to claim 11, wherein: The memory includes further instructions that, when executed by the processing circuit, further configure the system to: The representation of the cybersecurity risk is presented as a web page overlay.

14. The system according to claim 11, wherein: The memory includes further instructions that, when executed by the processing circuit, further configure the system to: A remedial action is determined based on the cybersecurity risk.

15. The system of claim 14, wherein: The memory includes further instructions that, when executed by the processing circuit, further configure the system to: The remedial action is initiated in the cloud computing environment.

16. The system according to claim 11, wherein: The memory includes further instructions that, when executed by the processing circuit, further configure the system to: A data field value associated with one of the plurality of identifiers is extracted.

17. The system of claim 16, wherein: The memory includes further instructions that, when executed by the processing circuit, further configure the system to: Generate a query based on the extracted data field values.

18. The system of claim 11, wherein: The memory includes further instructions that, when executed by the processing circuit, further configure the system to: A client device displaying the webpage is configured to install an extension, wherein the extension is configured to detect the plurality of identifiers in the webpage.

19. The system of claim 11, wherein: The memory includes further instructions that, when executed by the processing circuit, further configure the system to: The query is generated based on a first identifier of the plurality of identifiers, wherein the query includes filtering based on a second identifier of the plurality of identifiers.

Citation Information

Patent Citations

  • Customer relation management system based on cloud platform and cloud computing

    CN104735102A

  • Method and device for identifying secure download link, terminal and storage medium

    CN110213211A

  • Automatic inspection method and inspection platform for state grid information management system

    CN112632362A

  • Information security detection method and device, electronic equipment and storage medium

    CN116910751A

  • Security Component for Use With an Internet Browser Application and Method and Apparatus Associated Therewith

    US20080172382A1