System and method for generating network security remediation in computing environment
By configuring virtual instances and generating remediation infrastructure in the cloud computing environment, the problems of high access rights and expensive maintenance in the cloud computing environment are solved, and fast response and efficient network security remediation are achieved.
Patent Information
- Application Number
- CN202411731382.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-14
- Filing Date
- 2024-11-29
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-11-29
AI Technical Summary
When performing network security remediation in cloud computing environments, the existing technology faces the problems of high access rights and expensive maintenance costs, which leads to inefficient remediation solutions.
By configuring a virtual instance to communicate with the inspection environment, multiple remediation scripts are received, and a remediation infrastructure including multiple remediation actions is generated, network security issues in the computing environment are detected, and corresponding remediation actions are initiated based on the detection results.
It realizes rapid response and execution of network security remediation actions in a cloud computing environment, reduces the need for high-permission access, reduces maintenance costs, and improves remediation efficiency.
Smart Images

Figure CN120165894A_ABST
Abstract
Description
Technical Field
[0001] This disclosure generally relates to network security remediation, and more particularly to providing remediation infrastructure for cloud computing environments. Background Art
[0002] Network security threats can occur in a computing environment in various ways. For example, in a cloud computing environment, some threats include vulnerabilities, misconfigurations, exposures, and exploitations, etc.
[0003] There are various solutions for monitoring network security threats in a computing environment, including threat detection and digital forensics solutions, etc. Although monitoring typically requires read-level access to the computing environment, remediation and mitigation require actions to be executed and initiated in the computing environment, and these actions usually require a higher level of permission and access than simple read-level access.
[0004] For reasons such as these, the remediation solutions adopted are slow because organizations are reluctant to allow third parties to have this access continuously. Alternatively, the remediation solution can be maintained and provided by the organization itself in the computing environment, but this requires maintaining expensive specialization.
[0005] Therefore, it would be advantageous to provide a solution that can overcome the above challenges. Summary of the Invention
[0006] The following is an overview of several example embodiments of this disclosure. This overview is provided to facilitate a basic understanding of these embodiments by the reader and does not fully define the breadth of this disclosure. This overview is not an extensive review of all expected embodiments and is neither intended to identify the key or important elements of all embodiments nor to depict the scope of any or all aspects. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to the more detailed description presented later. For convenience, the term "some embodiments" or "certain embodiments" may be used herein to refer to a single embodiment or multiple embodiments of this disclosure.
[0007] A system of one or more computers can be configured to perform specific operations or actions by installing software, firmware, hardware, or a combination thereof on the system, and the software, firmware, hardware, or a combination thereof causes the system to perform these actions during operation. One or more computer programs can be configured to perform specific operations or actions by including instructions that, when executed by a data processing device, cause the device to perform these actions.
[0008] In one general aspect, a method may include configuring a virtual instance in a computing environment to communicate with an inspection environment. The method may further include configuring the virtual instance to receive, in the computing environment, a plurality of remediation scripts from the inspection environment. The method may further include generating a remediation infrastructure including a plurality of remediation actions, each remediation action corresponding to at least one of the plurality of remediation scripts. The method may further include detecting a cybersecurity issue in the computing environment. The method may further include, based on detecting the cybersecurity issue, configuring the virtual instance to initiate a remediation action among the plurality of remediation actions. The method may further include receiving, in the inspection environment, feedback from the virtual instance in response to initiating the remediation action. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.
[0009] The implementation may include one or more of the following features. The method may include: inspecting a cybersecurity object in a computing environment, where the cybersecurity object indicates a cybersecurity issue. The method may include: associating a first set of remediation actions of a plurality of remediation actions with a first set of user accounts; and associating a second set of remediation actions of the plurality of remediation actions with a second set of user accounts, where each set of user accounts is authorized to initiate only the remediation actions associated with the corresponding user group. The method may include: disabling a first remediation action of the plurality of remediation actions. The method may include: detecting a condition in the computing environment; and disabling the first remediation action based on the detected condition. The method may include: enabling a second remediation based on the detected condition. The method may include: disabling the first remediation action of the plurality of remediation actions only for the first set of user accounts. The method may include: associating the first remediation action with a first user group, where the first user group is authorized to initiate the first remediation action only for a first pre-authorized resource in the computing environment. The method may include: associating the first remediation action with a second user group, where the second user group is authorized to initiate the first remediation action for any resource in the computing environment. The method may include: associating the first remediation action with a second user group, where the second user group is authorized to initiate the first remediation action only for a second pre-authorized resource different from the first pre-authorized resource. The method may include: generating an indicator value for each remediation action, the indicator value indicating the degree of disruption of the determined remediation action. The method may include: providing a first entity with permission to initiate the first remediation action in response to determining that the degree of disruption of the determined first remediation action is at or above a threshold. The method may include: providing the first entity with permission only in response to detecting a condition in the computing environment. The method may include: configuring a virtual instance to receive a customized remediation script. The method may include: initiating a second remediation action in response to feedback indicating that a remediation action was unsuccessful. The method may include: generating a notification in response to feedback indicating that a remediation action was successful. The method may include: configuring a virtual instance to send a status report corresponding to the remediation infrastructure. The implementation of the described technology may include hardware, a method or process, or a computer tangible medium.
[0010] In one general aspect, a non-transitory computer-readable medium may include one or more instructions that, when executed by one or more processors of a device, cause the device to: configure a virtual instance in a computing environment to communicate with an inspection environment. The medium may also configure the virtual instance to receive, in the computing environment, a plurality of remediation scripts from the inspection environment. The medium may also generate a remediation infrastructure including a plurality of remediation actions, each remediation action corresponding to at least one of the plurality of remediation scripts. The medium may also detect a cybersecurity issue in the computing environment. The medium may also, based on detecting the cybersecurity issue, configure the virtual instance to initiate a remediation action among the plurality of remediation actions. The medium may also, in response to initiating the remediation action, receive feedback from the virtual instance in the inspection environment. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.
[0011] In one general aspect, a system may include processing circuitry. The system may also include a memory that contains instructions that, when executed by the processing circuitry, configure the system to: configure a virtual instance in a computing environment to communicate with an inspection environment. The system may also configure the virtual instance to receive, in the computing environment, a plurality of remediation scripts from the inspection environment. The system may also generate a remediation infrastructure including a plurality of remediation actions, each remediation action corresponding to at least one of the plurality of remediation scripts. The system may also detect a cybersecurity issue in the computing environment. The system may also, based on detecting the cybersecurity issue, configure the virtual instance to initiate a remediation action among the plurality of remediation actions. The system may also, in response to initiating the remediation action, receive feedback from the virtual instance in the inspection environment. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.
[0012] The implementation may include one or more of the following features. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: check for network security objects in the computing environment, where the network security objects indicate network security issues. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: associate a first set of remediation actions from among a plurality of remediation actions with a first set of user accounts; and associate a second set of remediation actions from among the plurality of remediation actions with a second set of user accounts, where each set of user accounts is authorized to initiate only the remediation actions associated with the corresponding user group. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: disable a first remediation action from among the plurality of remediation actions. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: detect conditions in the computing environment; and disable the first remediation action based on the detected conditions. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: enable a second remediation based on the detected conditions. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: disable the first remediation action from among the plurality of remediation actions for only the first set of user accounts. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: associate the first remediation action with a first user group, where the first user group is authorized to initiate the first remediation action only for a first pre-authorized resource in the computing environment. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: associate the first remediation action with a second user group, where the second user group is authorized to initiate the first remediation action for any resource in the computing environment. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: associate the first remediation action with a second user group, where the second user group is authorized to initiate the first remediation action only for a second pre-authorized resource that is different from the first pre-authorized resource. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: generate an indicator value for each remediation action, the indicator value indicating the degree of disruption of the determined remediation action; and provide permission to a first entity to initiate the first remediation action in response to determining that the degree of disruption of the determined first remediation action is at or above a threshold. In the system, the memory contains further instructions that, when executed by the processing circuit, further configure the system to: initiate a second remediation action in response to feedback indicating that a remediation action was unsuccessful. Implementations of the described techniques may include hardware, a method or process, or a computer tangible medium. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The subject matter disclosed herein is particularly pointed out and distinctly claimed in the claims of the specification. The foregoing and other objects, features, and advantages of the disclosed embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings.
[0014] Figure 1 is an example schematic diagram of an inspection environment and a computing environment with a generative remediator implemented according to an embodiment.
[0015] Figure 2 is an example diagram of a security graph implemented according to an embodiment.
[0016] Figure 3 is an example schematic diagram of a generative remediator data flow implemented according to an embodiment.
[0017] Figure 4 is an example flowchart of a method for generating a remediation action implemented according to an embodiment.
[0018] Figure 5 is an example flowchart of a method for initiating a remediation action according to an embodiment.
[0019] Figure 6 is an example schematic diagram of a data flow of a remediation infrastructure deployed in a computing environment implemented according to an embodiment.
[0020] Figure 7 is an example flowchart of a method for deploying and utilizing a remediation infrastructure in a computing environment implemented according to an embodiment.
[0021] Figure 8 is an example flowchart of a method for providing remediation feedback from a computing environment to an inspection environment implemented according to an embodiment.
[0022] Figure 9 is an example schematic diagram of a generative remediator according to an embodiment. Detailed Description
[0023] It is important to note that the embodiments disclosed herein are merely examples of many useful applications of the innovative teachings herein. In general, the statements made in the specification of this application do not necessarily limit any of the various claimed embodiments. Additionally, some statements may apply to some inventive features but not to others. In general, unless otherwise stated, without loss of generality, a single element may be plural and vice versa. In the drawings, the same numerals refer to the same parts in several views.
[0024] Figure 1An example schematic diagram of an inspection environment and a computing environment with a generative remediator implemented according to an embodiment.
[0025] In an embodiment, the computing environment 110 includes multiple entities, such as resources, principals, etc. For example, in an embodiment, the entity is a cloud entity.
[0026] In some embodiments, the computing environment 110 is a cloud computing environment, an on-prem environment, a hybrid environment, and combinations thereof, etc. In certain embodiments, the cloud computing environment includes a virtual private cloud (VPC) and a virtual network (VNet), etc.
[0027] In certain embodiments, the cloud computing environment is deployed on a cloud computing infrastructure. In an embodiment, the cloud computing infrastructure is Amazon Web Services ( Web Services, AWS), Google Cloud Platform ( CloudPlatform, GCP), and Microsoft Azure ( Azure), etc.
[0028] In certain embodiments, the computing environment 110 includes multiple resources, such as virtual machines 112, software containers 114, serverless functions 116, and various combinations thereof, etc. According to some embodiments, the virtual machine 112 is, for example The software container 114 utilizes a platform, and the serverless function 116 is Lambda.
[0029] In some embodiments, the computing environment 110 includes multiple principals, such as user accounts, service accounts, local accounts, user groups, roles, and various combinations thereof, etc.
[0030] In an embodiment, the computing environment 110 is monitored by a network security inspection environment 120 (also referred to as the inspection environment 120). In certain embodiments, the inspection environment 120 is implemented as a cloud computing environment, a hybrid environment, an on-prem environment, and combinations thereof, etc.
[0031] In an embodiment, the inspection environment 120 includes multiple inspector workloads, such as inspector 122, etc. In some embodiments, the inspector 122 is configured to detect network security objects. For example, in an embodiment, the inspector 122 is configured to detect network security objects on a disk associated with the virtual machine 112. In an embodiment, for example, clones, replicas, and snapshots generated based on the disk of the virtual machine 112 are used to generate an inspectable disk.
[0032] In some embodiments, the checker 122 checks the checkable disk. This allows, for example, static analysis to be performed on the disk without disturbing the virtual machine 112 or utilizing its resources. In an embodiment, the cybersecurity object is a file, secret, password, sensitive data, code object, hash, key, certificate, registry file, library, package, binary, application, operating system, malware, nested workload, and combinations thereof, etc.
[0033] In certain embodiments, the cybersecurity objects are used to detect cybersecurity risks. For example, in an embodiment, secrets and passwords, etc. are stored as easily accessible plaintext and clear text, etc. In such an embodiment, for example, by storing secrets in this way, the secrets are more easily exposed and thus present a higher cybersecurity risk. In some embodiments, the secret provides access to another resource, thereby creating a cybersecurity risk for the lateral movement path.
[0034] In some embodiments, the inspection controller 124 is configured to initiate the generation of the checkable disk using a service account in the computing environment 110. In certain embodiments, the inspection controller 124 is configured to generate an inspector workload (such as the checker 122, etc.) in response to a demand for the inspector workload. For example, in an embodiment, the inspection controller 124 is configured to have permission to instantiate a virtual instance that executes an application configured to check the checkable disk for cybersecurity objects.
[0035] According to some embodiments, the checker 122 is configured to store data, information, etc. about the cybersecurity objects, inspections, etc. in the security database 126. In some embodiments, the security database 126 includes constraints and predefined data schemas, etc., which are used to represent the computing environment 110.
[0036] In some embodiments, the data schema of the security database 126 is used to represent the computing environment 110 using multiple data templates, each template describing a different entity. For example, in an embodiment, a first data template is used to describe resources, and a second data template is used to describe subjects. In an embodiment, the first data template is used to describe any resource in the computing environment 110, that is, the first data template is used to represent the virtual machine 112, the serverless function 116, and the software container 114.
[0037] In certain embodiments, the security database 126 is implemented as a tabular database, a columnar database, an SQL database, a non - SQL database, a graph database, and various combinations thereof, etc. For example, in an embodiment, the security database 126 is a graph database, such as etc., where the subject, resource, remediation action, cybersecurity risk, cybersecurity object, enrichment, and endpoint, etc. are stored as nodes on a graph stored in the security database 126. The following discusses an example representation of the computing environment in more detail with reference to Figure 2 An example representation of the computing environment is discussed in more detail.
[0038] According to an embodiment, the inspection environment 120 further includes a generative remediator 128. In an embodiment, the generative remediator includes a generative artificial intelligence model, such as a large language model (LLM), etc. In some embodiments, the LLM is, for example etc.
[0039] In certain embodiments, the generative remediator 128 is configured to generate remediation actions. In some embodiments, the generative remediator 128 is configured to generate remediation actions in response to detecting cybersecurity threats and cybersecurity risks, etc., for example, based on detecting a cybersecurity object. In an embodiment, cybersecurity threats include misconfigurations, vulnerabilities, exposures, and various combinations thereof, etc.
[0040] In some embodiments, a cybersecurity threat is detected in response to detecting multiple cybersecurity objects, a cybersecurity object and an attack path (e.g., exposure), a cybersecurity object and a vulnerability, and various combinations thereof, etc. In an implementation, such a combination is also referred to as a toxic combination.
[0041] In an embodiment, the generative remediator 128 is configured to generate prompts for the LLM. In some embodiments, the prompts are generated based on the representation mode of the security database 126, discoveries (e.g., the results of cybersecurity inspections, such as the detection of cybersecurity objects), predefined actions, and combinations thereof, etc.
[0042] According to an embodiment, the generative remediator 128 is configured to generate prompts based on a predefined template. In an embodiment, generating a prompt based on a predefined template includes parsing the input received by the generative remediator 128, detecting the values of data fields therein, and adjusting the predefined template based on the detected data values.
[0043] In certain embodiments, it is advantageous to provide the LLM with a prompt that includes a data pattern (i.e., a representation mode) for representation, as this reduces the need to fine-tune the LLM.
[0044] In some embodiments, the generative remediator 128 is further configured to initiate a remediation action. In certain embodiments, the remediation actions include: initiation of a resource, initiation of a subject, and combinations thereof, etc.
[0045] For example, according to an embodiment, the remediation actions include: revoking access to a resource, revoking access from a resource, revoking access from a principal, revoking access to a principal, updating the permissions of a principal, changing the user group of a principal, changing the role of a principal, revoking an access token, sandboxing a resource, configuring a firewall to filter traffic to a resource, configuring a firewall to filter traffic from a resource, generating an alert, installing a patch, removing a software application from a resource, updating a software package, removing a software package, and combinations thereof, etc.
[0046] In some embodiments, the inspection environment 120, the generative remediator 128, etc. are configured to deploy the remediator 118 in the computing environment 110. For example, according to an embodiment, the remediator 118 is implemented as a serverless function, a software container, a virtual machine, and combinations thereof, etc.
[0047] In an embodiment, the remediator 118 is a workload that is configured to deploy, manage, and expose, etc. the remediation infrastructure in the computing environment 110. This will be discussed in more detail below with reference to Figure 6 discussed in more detail.
[0048] In some embodiments, the remediator is configured to deploy multiple remediation actions, each remediation action including a remediation script. According to an embodiment, the remediation script includes scripts, code, and instructions, etc., which, when executed in the computing environment 110, remediate and attempt to remediate, etc. the cybersecurity issues detected in the computing environment 110.
[0049] In some embodiments, the first set of remediation actions is generated by the generative remediator 128, and the second set of remediation actions is predefined remediation actions.
[0050] Figure 2 is an example diagram of a security graph implemented according to an embodiment. In an embodiment, for example, the network security objects of a virtual machine are inspected by an inspector discussed in more detail throughout the text.
[0051] According to an embodiment, the inspector and the inspection controller, etc. are configured to generate a representation of the virtual machine, such as a virtual machine (VM) node 230. In an embodiment, the inspector is configured to detect application endpoints represented as endpoint nodes 220. The application endpoints allow the virtual machine to connect to a public network, such as the Internet, etc. In an embodiment, the endpoint node 220 is connected to the public network node 210, which indicates that the application (APP) endpoints can access the public network.
[0052] In some embodiments, the checker is also configured to detect hosting technologies. For example, according to an embodiment, a hosting technology (such as a database, etc.) is represented by a hosting technology node. In some embodiments, a database is represented by a database (DB) node 232, and the DB node 232 is connected to the VM node 230 to indicate that the DB is hosted on the VM.
[0053] According to an embodiment, the checker is configured to detect secrets on the VM. In some embodiments, a single checker is configured to detect multiple network security objects. In other embodiments, each checker is configured to detect a single network security object.
[0054] In an embodiment, a detected secret is represented by a secret node 234 connected to the VM node 230. In some embodiments, the detected secret is associated with a user account represented by a user node 240. In an embodiment, the user account is configured to assume an administrator account, represented by an administrative node 250. In an embodiment, the administrator account is configured to access resources (such as a bucket, etc.) that expose the data therein. In some embodiments, the resource is represented by a resource node 260.
[0055] In certain embodiments, the checker is configured to detect a network security object that indicates the VM includes vulnerabilities, exposures, misconfigurations, etc. (e.g., represented by a CVE (common vulnerabilities and exposures) node 235). For example, in an embodiment, the CVE node 235 represents the Log4Shell vulnerability in Log4j. According to an embodiment, the CVE node 235 is connected to the VM node 230 to indicate that a vulnerability has been detected on the VM.
[0056] In some embodiments, a security discovery is represented by a security discovery node 231. For example, according to an embodiment, access logs (such as network logs, cloud logs, and event logs, etc.). In some embodiments, the logs are parsed to detect an identifier of the VM.
[0057] In an embodiment, an event is detected in the log, and the event corresponds to an identifier corresponding to the security discovery. For example, in an embodiment, multiple unsuccessful access events indicate an attempt to brute-force attack the VM. In some embodiments, the security discovery node 231 is connected to the VM node 230 to indicate that a security discovery has been detected regarding the VM.
[0058] In some embodiments, the security database is configured to detect potential lateral movement paths from a virtual machine (VM node 230) to a resource (resource node 260) by obtaining access to the VM (e.g., by brute force), obtaining access to the secrets stored thereon, and leveraging the user to obtain administrative access to the resource from there. In embodiments, lateral movement (LM) paths and potential lateral movement paths, etc. are represented by an LM discovery node 233 connected to the VM node 230 to indicate, for example, that there is a lateral movement path between the VM node 230 and another resource.
[0059] In some embodiments, a toxic combination is defined by policies, conditions, rules, and combinations thereof, etc. For example, in the above embodiments, a vulnerability in combination with a secret poses a higher cybersecurity risk compared to the presence of any one of these findings alone.
[0060] Detecting such toxic combinations is advantageous because they allow remediation actions to be initiated at multiple points (e.g., each element of the toxic combination) to address cybersecurity threats.
[0061] In certain embodiments, nodes representing findings, cybersecurity risks, and cybersecurity objects, etc. are connected to a remediation node, where the remediation node represents a remediation action. In some embodiments, for example, a generative remediator is configured to detect a remediation action based on the remediation node and adapt a remediation action template to a specific finding.
[0062] Figure 3 is an example schematic diagram of a generative remediator data flow implemented according to an embodiment. In an embodiment, the generative remediator 310 is configured to receive multiple inputs. In some embodiments, the received inputs are predefined actions 320, findings 330, representation patterns 340, and combinations thereof, etc.
[0063] In an embodiment, the predefined action 320 is a remediation action, a remediation script, an instruction, and combinations thereof, etc. In some embodiments, the predefined action 320 includes a template, predefined values, and combinations thereof, etc.
[0064] In certain embodiments, the finding 330 is generated by a security graph, an inspector, and an inspection controller, etc., for example, based on cybersecurity objects detected in a computing environment.
[0065] In some embodiments, the finding 330 is a security finding, a lateral movement finding, a CVE finding, a privilege escalation finding, and various combinations thereof, etc.
[0066] In some embodiments, a security finding indicates a cybersecurity problem and a toxic combination of cybersecurity problems, etc. For example, in an embodiment, the cybersecurity problem is a vulnerability, a misconfiguration, an exposure, an attack path, and combinations thereof, etc.
[0067] In an embodiment, for example, security findings are generated based on events in a detection log. For example, a security finding is the detection of a brute force attack (e.g., multiple failed login attempts). According to an embodiment, lateral movement findings include detecting a lateral movement path between a first resource and a second resource, such as by traversing a security graph in a security database to detect potential lateral movement paths. In an embodiment, lateral movement findings include secrets, keys, and principals that connect a first resource to a second resource.
[0068] According to an embodiment, representation schemas include database schemas and constraints, etc., which are used to represent a computing environment, its findings, its enrichments, remediation actions, cybersecurity risks, cybersecurity threats, and cybersecurity objects, etc. in a security database.
[0069] In an embodiment, the generative remediator 310 is configured to receive user input as further input. For example, in an embodiment, the user input indicates platform preferences for remediating a cybersecurity issue.
[0070] In some embodiments, the computing environment includes multiple platforms, such as a CLI (command line interface), a cloud computing console, an infrastructure as code (IaC) platform, and various combinations thereof, etc. Additionally, in some embodiments, various remediation actions can be deployed in a production environment, such as by instructing an admission controller and sensors, etc. to initiate the remediation actions.
[0071] Thus, according to an embodiment, a cybersecurity issue can be remediated from multiple points in the environment. For example, a cybersecurity issue can be the detection of an exposure due to a misconfiguration (e.g., a database with sensitive data not protected by a password, hosted on a virtual machine on which a sensor is deployed).
[0072] In an embodiment, remediating the above cybersecurity issue includes any of the following: configuring a sensor to set a password for the database, updating code objects in an IaC file (e.g., file), deploying a VM with a hosted database from the file to include password protection, etc. In some embodiments, user preferences are determined corresponding to the platform for remediating the cybersecurity issue. In some embodiments, multiple preferred platforms are selected.
[0073] According to an embodiment, the generative remediator 310 is configured to generate a remediation action 350. In some embodiments, the remediation action 350 includes a remediation script, such as multiple lines of code that remediate a cybersecurity issue when executed in a computing environment.
[0074] In some embodiments, the generative remediator 310 is configured to generate a plurality of remediation actions. In some embodiments, the generative remediator 310 is configured to generate a priority value for each of the plurality of remediation actions. For example, in an embodiment, the priority value is generated based on past success indicators. This is advantageous because remediation actions that have been found to be effective in remediating cybersecurity issues in the past may be effective for current cybersecurity threats.
[0075] Figure 4 is an example flowchart of a method for generating remediation actions implemented according to an embodiment.
[0076] At S410, the computing environment is checked for cybersecurity objects. In an embodiment, checking the computing environment for cybersecurity objects includes: detecting a plurality of resources deployed in the computing environment.
[0077] In certain embodiments, detecting the plurality of resources includes, for example, entity discovery. In an embodiment, entity discovery includes querying the application programming interface (API) of the computing environment (such as a cloud computing environment) to determine which resources and workloads are deployed therein.
[0078] For example, according to an embodiment, the cloud API is accessed to determine which virtual machines, software containers, serverless functions, microservices, buckets, storage, and software repositories are deployed in the computing environment.
[0079] In an embodiment, the resources are checked to detect nested resources therein. For example, in an embodiment, a virtual machine is configured to host a software container platform (such as Kubernetes), and each virtual machine and the software containers deployed thereon are separately checked for cybersecurity objects.
[0080] In some embodiments, checking the computing environment includes generating an inspectable disk based on the raw disks deployed in the computing environment. In certain embodiments, generating an inspectable disk includes generating a clone, copy, snapshot, and combinations thereof of the raw disk.
[0081] According to an embodiment, in response to a request to initiate a raw disk check, an inspectable disk is generated on demand, and in response to determining that the check is complete, the resources allocated to the inspectable disk are released.
[0082] In some embodiments, a plurality of inspectors are assigned to check the cybersecurity objects of the inspectable disk, and each inspector is configured to check a different cybersecurity object. For example, in an embodiment, the first inspector is configured to check nested workloads, while the second inspector is configured to check secrets.
[0083] In an embodiment, network security objects are files, secrets, passwords, sensitive data, code objects, hashes, keys, certificates, registry files, libraries, packages, binaries, applications, operating systems, malware, nested workloads, and combinations thereof, etc.
[0084] In S420, network security issues are detected. In an embodiment, network security issues are detected based on the detection of network security objects. In some embodiments, network security issues are detected based on a combination of the detection of network security objects and findings. For example, in an embodiment, findings include security findings, lateral movement findings, privilege escalation findings, vulnerabilities, exposures, misconfigurations, malware, attack paths, and various combinations thereof, etc.
[0085] As an example, a combination (also referred to as a toxic combination) includes detecting vulnerabilities, such as running an application with a known vulnerability and hosting technology of an endpoint (e.g., indicating public network access), where the hosting technology is configured to employ a service account with high permissions.
[0086] In certain embodiments, detecting a toxic combination includes imposing policies, rules, conditions, etc. on a representation of a computing environment. In some embodiments, a security database is queried based on, for example, a pre - existing query that is configured to detect a toxic combination. For example, in some embodiments, a security graph is traversed to detect nodes corresponding to a query directed to the security graph, such as the graph discussed in more detail above regarding Figure 2 the graph, etc.
[0087] In certain embodiments, multiple network security issues are detected. In some embodiments, each network security issue includes a priority score, a severity score, and combinations thereof, etc. For example, in an embodiment, the scores are qualitative scores (e.g., low, medium, high), quantitative scores (e.g., from 1 to 10), and combinations thereof, etc.
[0088] In S430, a remediation action is generated. In an embodiment, the remediation action is generated by a generative remediator configured to generate the remediation action. In some embodiments, the remediation action is generated based on the network security issue.
[0089] In an embodiment, the generative remediator is configured to receive a network security issue, including, for example, an identifier of a resource (e.g., a name in a namespace and an IP address, etc.) and data about the network security object, etc., and generate a remediation action based on the received input.
[0090] In some embodiments, the remediation action is generated based on a template, such as including a code template. In an embodiment, the code template includes machine - readable instructions that, when executed in a computing environment (such as a cloud computing environment, etc.), cause the remediation action to be initiated.
[0091] In some embodiments, the generative remediator is configured to generate prompts for a large language model (LLM), which is configured to generate remediation actions. In an embodiment, the prompts are generated based on a template (e.g., based on a code template).
[0092] In some embodiments, a first LLM is used to generate prompts and a second LLM is used to generate remediation actions. In an embodiment, the first LLM and the second LLM are the same model.
[0093] In an embodiment, when provided to the LLM model, the prompt configures the LLM model to generate an output that includes a remediation action. In an embodiment, the remediation action includes a remediation script and multiple remediation scripts, etc. In an embodiment, the remediation script includes code, such as high-level code, etc. In some embodiments, the high-level code script, for example, is a script.
[0094] Figure 5 is an example flowchart of a method for initiating a remediation action according to an embodiment. In an embodiment, the initiated remediation action is generated by the generative remediator, as discussed in more detail above with respect to Figure 4 more detailed discussion.
[0095] In S510, an input is received. In an embodiment, the received input is provided to the generative remediator. In some embodiments, the received input includes a cybersecurity issue, a cybersecurity alert, a predefined action, a discovery, a representation pattern, and combinations thereof, etc.
[0096] In an embodiment, the predefined action is a remediation action, a remediation script, an instruction, and combinations thereof, etc. In some embodiments, the predefined action includes a template, a predefined value, and combinations thereof, etc.
[0097] In certain embodiments, for example, based on cybersecurity objects detected in a computing environment, discoveries are generated by a security graph, an inspector, and an inspection controller, etc.
[0098] In some embodiments, the discoveries are security discoveries, lateral movement discoveries, CVE discoveries, privilege escalation discoveries, and various combinations thereof, etc. In some embodiments, the security discovery indicates a cybersecurity issue and a toxic combination of cybersecurity issues, etc. For example, in an embodiment, the cybersecurity issue is a vulnerability, a misconfiguration, an exposure, an attack path, and combinations thereof, etc.
[0099] In an embodiment, for example, security findings are generated based on events in a detection log. For example, a security finding is the detection of a brute-force attack (e.g., multiple failed login attempts). According to an embodiment, lateral movement discovery includes detecting a lateral movement path between a first resource and a second resource, such as by traversing a security graph in a security database to detect potential lateral movement paths. In an embodiment, lateral movement discovery includes secrets, keys, and principals that connect the first resource to the second resource, etc.
[0100] According to an embodiment, a representation schema includes database schemas, constraints, etc., for representing a computing environment, its findings, its enrichment, remediation actions, cybersecurity risks, cybersecurity threats, cybersecurity objects, etc. in a security database.
[0101] In an embodiment, a generative remediator is configured to receive user input as further input. For example, in an embodiment, the user input indicates a platform preference for remediating a cybersecurity issue.
[0102] In S520, a prompt is generated. In an embodiment, the prompt is generated by a first LLM and provided as input to a second LLM. In some embodiments, the first LLM is the second LLM.
[0103] In some embodiments, a generative remediator is configured to generate a prompt for a large language model (LLM), which is configured to generate a remediation action. In an embodiment, the prompt is generated based on a template (e.g., based on a code template).
[0104] In an embodiment, when provided to the LLM model, the prompt configures the LLM model to generate an output that includes a remediation action. In an embodiment, the remediation action includes a remediation script and multiple remediation scripts, etc. In an embodiment, the remediation script includes code, such as high-level code, etc. In some embodiments, the high-level code script, for example, is a script.
[0105] In S530, a remediation action is initiated. In an embodiment, the remediation action is generated based on the output of the LLM. For example, according to an embodiment, the prompt generated in S520 is provided to the LLM, and the LLM is configured to generate an output that includes a remediation action.
[0106] In an embodiment, initiating a remediation action includes executing one instruction and multiple instructions in a computing environment, etc. In certain embodiments, the initiated remediation action is initiated with respect to a computing platform among multiple computing platforms deployed in the computing environment. For example, according to an embodiment, the computing environment is a command line interface (CLI), an infrastructure as code (IaC) platform, a console, a sensor, an admission controller, and combinations thereof, etc.
[0107] Figure 6 FIG. is an exemplary schematic diagram of the data flow of a remediation infrastructure deployed in a computing environment implemented according to an embodiment. In some embodiments, the inspection environment 610 is configured to deploy a remediation infrastructure in the computing environment 620.
[0108] For example, in an embodiment, the inspection environment 610 is configured to generate workloads, such as remediators 626 deployed in the computing environment 620. In certain embodiments, this is advantageous because it does not require the inspection environment to be granted permission to access the entire computing environment 620, but rather the organization of the computing environment 620 can deploy the remediator workload 626 according to the organization's standards and best practices.
[0109] In some embodiments, the remediator 626 is configured to communicate with a queue service 624. In an embodiment, the queue service 624 is configured to communicate with a notification service 622. In certain embodiments, the queue service 624 and the notification service 622 are implemented as a single queue service and are shown as separate entities herein only for convenience. In an embodiment, the notification service 622 is, for example, Amazon Simple Notification Service (SNS). In some embodiments, the queue service 624 is Amazon Simple Queue Service (SQS).
[0110] In certain embodiments, each component of the remediation infrastructure is configured to receive data from a single source and send the data to a single destination. For example, the queue service 624 is configured to send, store, and receive messages, etc., between software components in the computing environment (e.g., between the notification service 622 and the remediator 626).
[0111] In some embodiments, the notification service 622 is configured to send, store, and receive messages, etc., between software components of the computing environment 620 and software components of the inspection environment 610. According to an embodiment, the remediator 626 is configured to deploy multiple remediation actions. In some embodiments, each remediation action corresponds to a script, multiple scripts, etc., such as multiple remediation scripts 628-1 to 628-N, where "N" is a natural number with a value of "2" or greater.
[0112] In certain embodiments, the remediator 626 is configured to initiate a remediation action, for example, by executing the script 628-2. In some embodiments, the remediator 626 is configured to determine the result of executing the script 628-2. For example, in an embodiment, the remediator 626 is configured to detect the result of a remediation action in a log (such as an active log, a cloud log, a network log, an identity and access management log, and combinations thereof).
[0113] In some embodiments, the remediation action includes a determined effect. For example, according to an embodiment, the determined effect (also referred to as a result, feedback, etc.) of changing the permissions associated with a user account includes a record in a log that indicates that a user account with a first set of permissions has been modified to include a second set of permissions. In such an embodiment, the remediator 626 is also configured to detect the determined effect, such as by parsing the log, detecting log records, and detecting artifacts in the computing environment, etc.
[0114] In some embodiments, the remediator 626 is configured to determine whether the remediation action is successful or unsuccessful. For example, in an embodiment, the remediator 626 is configured to determine the success of the execution of the remediation action based on the result of the determined execution of the remediation action.
[0115] In an embodiment, the result of the execution of the remediation action is provided to the inspection environment 610. In certain embodiments, the inspection environment 610 is configured to update the security database based on the result of the remediation action. For example, in the case where the remediation action for a network security issue is successful, the network security issue is removed from the representation of the computing environment stored in the security database.
[0116] Figure 7 is an example flowchart of a method for deploying and utilizing a remediation infrastructure in a computing environment implemented according to an embodiment.
[0117] At S710, a remediation infrastructure is deployed in the computing environment. In some embodiments, the remediation infrastructure includes: multiple remediation actions, multiple remediation scripts, workloads, queuing services, notification services, and combinations thereof, etc.
[0118] In some embodiments, a selection is received to select a set of multiple remediation scripts. For example, this is useful in cases where the multiple remediation scripts include scripts that are not applicable to the computing environment of a particular deployment and the deployment's computing platform, etc.
[0119] In an embodiment, the workload is configured to initiate a remediation action in the computing environment and communicate with the inspection environment (e.g., via queuing and notification services).
[0120] According to some embodiments, the workload is configured to send identifiers for each remediation script, each remediation action, each active remediation script, each active remediation action, each inactive remediation script, each inactive remediation action, and various combinations thereof, etc. For example, in some embodiments, the workload is configured to periodically send identifiers in response to requests from the inspection environment and combinations thereof, etc.
[0121] In optional S720, the remediation infrastructure is customized. In some embodiments, the remediation infrastructure is customized by selecting workloads that can be deployed in a computing environment. For example, in an embodiment, the remediation infrastructure includes serverless functions, software containers, and virtual machines, each of which is configured to perform the function of a remediator.
[0122] In an embodiment, the workload type is determined based on the computing environment, the resource allocation of the computing environment, etc. In some embodiments, the remediation actions are customized. In an embodiment, customizing the remediation actions includes providing customized remediation actions. In some embodiments, customizing the remediation actions includes selecting a set of remediation actions from a plurality of remediation actions such that the set of remediation actions can be executed in the computing environment.
[0123] In S730, a plurality of remediation scripts are deployed in the computing environment. In an embodiment, deploying a plurality of remediation scripts includes sending the remediation scripts from an inspection environment to a remediator via the remediation infrastructure. In some embodiments, the remediation scripts are deployed continuously, periodically, on demand, and in combinations thereof, etc.
[0124] In certain embodiments, the deployed remediation scripts include unique identifiers, such as globally unique identifiers and locally unique identifiers, etc. In an embodiment, the globally unique identifier is unique across multiple computing environments, while the locally unique identifier is unique within a single computing environment.
[0125] In S740, a representation of the remediation script is generated. In an embodiment, the representation includes a visual representation, such as a graphical user interface (GUI) for controlling the remediation infrastructure. For example, according to an embodiment, the GUI includes an indicator for determining whether the remediation script is active (i.e., the script is deployed in the computing environment and can be started) or inactive (i.e., the script is deployed in the computing environment and cannot be started).
[0126] In some embodiments, the GUI includes an interruption indicator to indicate the degree of interruption to the computing environment, its resources, and its subjects, etc., caused by starting a remediation action. In certain embodiments, the interruption indicator includes a value. In an embodiment, the value is a binary value (e.g., true / false). In some embodiments, the value is qualitative (e.g., low, high, etc.), quantitative (e.g., from 1 to 10), and combinations thereof, etc.
[0127] According to an embodiment, the GUI also includes indicators of which user accounts, user groups, user roles, etc. are configured with permissions to start remediation actions and remediation scripts, etc. in the computing environment. In some embodiments, the input received through the GUI configures the inspection environment to deploy changes in the remediation infrastructure.
[0128] At S750, user input is received. In an embodiment, the user input is received via a GUI. In some embodiments, the user input received via the GUI configures the inspection environment to deploy changes in the remediation infrastructure.
[0129] According to an embodiment, the changes to the remediation infrastructure include updating remediation actions, updating remediation scripts, changing the permissions associated with the remediation actions, changing the permissions associated with the remediation scripts, deploying new remediation actions, deploying new remediation scripts, deleting remediation actions, deleting remediation scripts, starting remediation actions, starting remediation scripts, providing remediation actions, providing remediation scripts, and combinations thereof, etc.
[0130] Figure 8 is an example flowchart of a method implemented according to an embodiment for providing remediation feedback from a computing environment to an inspection environment.
[0131] At S810, a remediation action is selected. In an embodiment, the remediation action is selected from a list of predetermined remediation actions. In some embodiments, the remediation action includes one or more remediation scripts. In an embodiment, the remediation action is generated by a generative remediator, as discussed in more detail herein.
[0132] According to an embodiment, in response to detecting a cybersecurity issue, a remediation action is selected. In some embodiments, the remediation action is selected from a plurality of remediation actions. In certain embodiments, the cybersecurity issue includes a plurality of applicable remediation actions, each remediation action applicable to a unique computing platform of the computing environment.
[0133] In an embodiment, an inspection is performed to determine whether a previous remediation action has been selected from the cybersecurity issue. In some embodiments, the remediation action fails to remediate the cybersecurity issue, so it is beneficial to initiate a second different remediation action to remediate the cybersecurity issue.
[0134] At S820, the remediation script is started. In an embodiment, starting the remediation script includes executing scripts and code in the computing environment, etc.
[0135] In some embodiments, the remediation script configures the computing environment to revoke access to a resource, revoke access from a resource, revoke access from a principal, revoke access to a principal, update the permissions of a principal, change the user group of a principal, change the role of a principal, revoke an access token, sandbox a resource, configure a firewall to filter traffic to a resource, configure a firewall to filter traffic from a resource, generate an alert, install a patch, remove a software application from a resource, update a software package, remove a software package, and combinations thereof, etc.
[0136] In some embodiments, remediation actions, remediation scripts, etc. are initiated by entities in a computing environment. For example, in some embodiments, a first group of entities (e.g., a first user group) includes permissions and permission sets, etc., which authorize the first group of entities to initiate a first group of remediation actions. In some embodiments, the permissions and permission sets, etc. authorize the first group of entities to initiate only the first group of remediation actions.
[0137] According to some embodiments, a disruption level is determined for each remediation action, each remediation script, and combinations thereof, etc. In some embodiments, permissions to initiate remediation actions are further determined based on the disruption level. For example, according to an embodiment, permissions to initiate remediation actions with a "high" disruption level are provided only to users associated with a first role.
[0138] In some embodiments, conditions of the computing environment are detected. In an embodiment, the conditions are network bandwidth utilization (e.g., as an indicator of activity), the number of logged-in user accounts, the number of utilized resources, the number of available resources, the type of computing environment (e.g., cloud, on-prem, hybrid, and VPC, etc.), the type of computing infrastructure (e.g., bare metal, AWS, and GCP, etc.), and various combinations thereof, etc. In an embodiment, permissions are further determined based on the conditions of the computing environment. For example, according to an embodiment, based on the determined conditions, remediation actions are fully enabled for a first user group, fully disabled for a first user group, etc.
[0139] In some embodiments, permissions to initiate remediation actions are determined based on a combination of the disruption level and conditions of the computing environment. In an embodiment, the permissions are determined continuously, periodically, ad-hoc, and combinations thereof, etc.
[0140] In S830, feedback is received from the computing environment. In an embodiment, the feedback includes instructions corresponding to the success of the remediation action. In some embodiments, the feedback is generated by a remediator deployed in the computing environment as part of the deployed remediation infrastructure.
[0141] In some embodiments, feedback, results, and determined effects, etc. are determined in the computing environment by detecting events in event logs and detecting artifacts, etc.
[0142] For example, according to an embodiment, the determined effect (also referred to as the result, feedback, etc.) of changing the permissions associated with a user account includes a record in the log that indicates that a user account with a first permission set has been modified to include a second permission set. In such an embodiment, the remediator 626 is also configured to detect the determined effect, e.g., by parsing the log, detecting log records, and detecting artifacts in the computing environment, etc.
[0143] At S840, a check is performed to determine whether the cybersecurity issue has been remedied. In an embodiment, the check is performed based on the received feedback. In an embodiment, when the cybersecurity issue has been remedied, the execution ends. In some embodiments, when the cybersecurity issue has not been remedied (e.g., the remediation action is executed unsuccessfully), S850 is continued to be executed.
[0144] At S850, a notification is generated. In an embodiment, the notification includes an email, an alert, a ticket, etc., to indicate that the remediation action is unsuccessful. In some embodiments, the notification indicates that the remediation action fails to remedy the cybersecurity threat.
[0145] At S860, a check is performed to determine whether another remediation action should be initiated. This is beneficial when the previous remediation action fails or is unsuccessful. In an embodiment, if "yes", the execution is continued at S810 by selecting a different remediation action. In some embodiments, when "no", the execution ends.
[0146] Figure 9 It is an exemplary schematic diagram of the generative remediator 128 according to an embodiment. The generative remediator 128 includes a processing circuit 910, which is coupled to a memory 920, a storage device 930, and a network interface 940. In an embodiment, the components of the generative remediator 128 can be communicatively connected via a bus 950.
[0147] The processing circuit 910 can be understood as one or more hardware logic components and circuits. For example but not limited to, illustrative types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip systems (SOCs), graphics processing units (GPUs), tensor processing units (TPUs), general microprocessors, microcontrollers, and digital signal processors (DSPs), etc., or any other hardware logic components that can perform calculations or other information operations.
[0148] The memory 920 can be volatile (e.g., random access memory, etc.), non-volatile (e.g., read-only memory and flash memory, etc.), or a combination thereof. In an embodiment, the memory 920 is on-chip memory, off-chip memory, and combinations thereof, etc. In some embodiments, the memory 920 is a scratchpad memory for the processing circuitry 910.
[0149] In one configuration, the software for implementing one or more embodiments disclosed herein can be stored in the storage device 930, the memory 920, and combinations thereof, etc. The software should be construed broadly as any type of instruction, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. The instructions can include code (e.g., source code format, binary code format, executable code format, or any other suitable code format). When executed by the processing circuitry 910, the instructions cause the processing circuitry 910 to perform the various processes described herein.
[0150] The storage device 930 is a magnetic storage device, an optical storage device, a solid-state storage device, and combinations thereof, etc. According to an embodiment, the storage device 930 is implemented as flash memory, a hard disk drive, or other memory technology, or any other medium that can be used to store the required information.
[0151] The network interface 940 is configured to provide communication to the generative remediator 128, such as the checker 122, the check controller 124, the security database 126, and the remediator 118, etc.
[0152] It should be understood that the embodiments described herein are not limited to Figure 9 the specific architecture shown. Other architectures can be used equally without departing from the scope of the disclosed embodiments.
[0153] Furthermore, in some embodiments, the checker 122, the check controller 124, the security database 126, and the remediator 118 can be implemented using Figure 9 the architecture shown. In other embodiments, other architectures can be used equally without departing from the scope of the disclosed embodiments.
[0154] The various embodiments disclosed herein may be implemented as hardware, firmware, software, or any combination thereof. Additionally, the software is preferably implemented as an application tangibly embodied on a program storage unit or a computer-readable medium, which consists of a part or certain devices and / or combinations of devices. The application can be uploaded to a machine including any suitable architecture and executed by the machine. Preferably, the machine is implemented on a computer platform having hardware such as one or more central processing units ("CPUs"), a memory, and an input / output interface. The computer platform may also include an operating system and microinstruction code. The various processes and functions described herein may be part of the microinstruction code, part of the application, or any combination thereof, and may be executed by the CPU, whether or not such a computer or processor is explicitly shown. Additionally, various other peripheral units may be connected to the computer platform, such as additional data storage units and printing units, etc. Moreover, a non-transitory computer-readable medium is any computer-readable medium other than a transitory propagated signal.
[0155] All of the examples and conditional language recited herein are intended for pedagogical purposes to aid the reader in understanding the principles of the disclosed embodiments and the concepts contributed by the inventor to further the art, and are to be construed as not being limited to these specifically recited examples and conditions. Additionally, all statements herein reciting principles, aspects, and embodiments of the disclosed embodiments, as well as specific examples thereof, are intended to cover both structural and functional equivalents thereof. Moreover, it is intended that such equivalents include both currently known equivalents and equivalents developed in the future, i.e., any elements developed that perform the same function regardless of structure.
[0156] It should be understood that any reference herein to elements by names such as "first," "second," etc. generally does not limit the number or order of those elements. Instead, these names are generally used herein as a convenient method of distinguishing between two or more elements or instances of elements. Thus, a reference to first and second elements does not mean that only two elements may be used there, or that the first element must somehow precede the second element. Additionally, unless otherwise stated, a group of elements includes one or more elements.
[0157] As used herein, the phrase "at least one" followed by a list of items means that any of the listed items can be used alone, or any combination of two or more of the listed items can be used. For example, if a system is described as including "at least one of A, B, and C," the system can include only A; only B; only C; 2 A's; 2 B's; 2 C's; 3 A's; a combination of A and B; a combination of B and C; a combination of A and C; a combination of A, B, and C; a combination of 2 A's and C; a combination of A, 3 B's, and 2 C's, and so on.
Claims
1. A method for initiating remediation actions in response to a network security issue in a computing environment, comprising: configuring a virtual instance in a computing environment to communicate with an inspection environment; configuring the virtual instance to receive, in the computing environment, a plurality of remediation scripts from the inspection environment; generating a remediation infrastructure comprising a plurality of remediation actions, each remediation action corresponding to at least one remediation script of the plurality of remediation scripts; detecting network security issues in the computing environment; Based on detecting the network security issue, configuring the virtual instance to initiate a remediation action from the plurality of remediation actions; as well as In response to initiating the remedial action, feedback is received from the virtual instance in the inspection environment.
2. The method according to claim 1, further comprising: A network security object in the computing environment is inspected, wherein the network security object indicates the network security issue.
3. The method according to claim 1, further comprising: associating a first set of remedial actions in the plurality of remedial actions with a first set of user accounts; as well as A second set of remedial actions of the plurality of remedial actions is associated with a second set of user accounts, wherein each set of user accounts is authorized to initiate only remedial actions associated with the corresponding user group.
4. The method according to claim 3, further comprising: A first remedial action in the plurality of remedial actions is disabled.
5. The method according to claim 4, further comprising: detecting a condition in the computing environment; as well as The first remedial action is disabled based on the detected condition.
6. The method according to claim 5, further comprising: A second remedy is enabled based on the detected condition.
7. The method according to claim 3, further comprising: A first remedial action of the plurality of remedial actions is disabled only for the first set of user accounts.
8. The method according to claim 3, further comprising: A first remedial action is associated with a first user group, wherein the first user group is authorized to initiate the first remedial action only on a first pre-authorized resource in the computing environment.
9. The method according to claim 8, further comprising: The first remedial action is associated with a second user group, wherein the second user group is authorized to initiate the first remedial action on any resource in the computing environment.
10. The method according to claim 8, further comprising: The first remedial action is associated with the second user group, wherein the second user group is authorized to initiate the first remedial action only on a second pre-authorized resource, the second pre-authorized resource being different from the first pre-authorized resource.
11. The method according to claim 1, further comprising: An indicator value is generated for each remedial action, the indicator value indicating a determined degree of interruption of the remedial action.
12. The method according to claim 11, further comprising: In response to determining that the determined level of interruption of the first remedial action is at or above a threshold, permission is provided to the first subject to initiate the first remedial action.
13. The method according to claim 12, further comprising: The permission is provided to the first principal only in response to detecting a condition in the computing environment.
14. The method according to claim 1, further comprising: The virtual instance is configured to receive a custom remediation script.
15. The method according to claim 1, further comprising: In response to feedback indicating that the remedial action was unsuccessful, a second remedial action is initiated.
16. The method according to claim 1, further comprising: In response to feedback indicating that the remedial action was successful, a notification is generated.
17. The method of claim 1, further comprising: The virtual instance is configured to send a status report corresponding to the remediation infrastructure.
18. A non-transitory computer-readable medium storing a set of instructions for initiating remedial actions in response to a network security issue in a computing environment, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a device, cause the device to: configuring a virtual instance in a computing environment to communicate with an inspection environment; configuring the virtual instance to receive, in the computing environment, a plurality of remediation scripts from the inspection environment; generating a remediation infrastructure comprising a plurality of remediation actions, each remediation action corresponding to at least one remediation script of the plurality of remediation scripts; detecting network security issues in the computing environment; Based on detecting the network security issue, configuring the virtual instance to initiate a remediation action from the plurality of remediation actions; as well as In response to initiating the remedial action, feedback is received from the virtual instance in the inspection environment.
19. A system for initiating remedial action in response to a network security issue in a computing environment, comprising: Processing circuit; a memory containing instructions that, when executed by the processing circuit, configure the system to: configuring a virtual instance in a computing environment to communicate with an inspection environment; configuring the virtual instance to receive, in the computing environment, a plurality of remediation scripts from the inspection environment; generating a remediation infrastructure comprising a plurality of remediation actions, each remediation action corresponding to at least one remediation script of the plurality of remediation scripts; detecting network security issues in the computing environment; Based on detecting the network security issue, configuring the virtual instance to initiate a remediation action from the plurality of remediation actions; as well as In response to initiating the remedial action, feedback is received from the virtual instance in the inspection environment.
20. The system of claim 19, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: A network security object in the computing environment is inspected, wherein the network security object indicates the network security issue.
21. The system of claim 19, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: associating a first set of remedial actions in the plurality of remedial actions with a first set of user accounts; as well as A second set of remedial actions of the plurality of remedial actions is associated with a second set of user accounts, wherein each set of user accounts is authorized to initiate only remedial actions associated with the corresponding user group.
22. The system of claim 21, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: A first remedial action in the plurality of remedial actions is disabled.
23. The system of claim 22, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: detecting a condition in the computing environment; and The first remedial action is disabled based on the detected condition.
24. The system of claim 23, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: A second remedy is enabled based on the detected condition.
25. The system of claim 21, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: A first remedial action of the plurality of remedial actions is disabled only for the first set of user accounts.
26. The system of claim 21, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: A first remedial action is associated with a first user group, wherein the first user group is authorized to initiate the first remedial action only on a first pre-authorized resource in the computing environment.
27. The system of claim 26, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: The first remedial action is associated with a second user group, wherein the second user group is authorized to initiate the first remedial action on any resource in the computing environment.
28. The system of claim 26, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: The first remedial action is associated with the second user group, wherein the second user group is authorized to initiate the first remedial action only on a second pre-authorized resource, the second pre-authorized resource being different from the first pre-authorized resource.
29. The system of claim 19, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: generating an indicator value for each remedial action, the indicator value indicating a degree of disruption of the determined remedial action; and In response to determining that the determined level of interruption of the first remedial action is at or above a threshold, permission is provided to the first subject to initiate the first remedial action.
30. The system of claim 19, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: In response to feedback indicating that the remedial action was unsuccessful, a second remedial action is initiated.
Citation Information
Patent Citations
Customizable courses of action for responding to incidents in information technology environments
US11182163B1
Enterprise level cybersecurity automatic remediation
US20180159887A1
Method and system to remediate a security issue
US20220109682A1
Vulnerability dashboard and automated remediation
US20220222350A1
Detecting vulnerabilities in configuration code of a cloud environment utilizing infrastructure as code
US20230164164A1