Systems, methods, and computer-readable media for generating network security remediations in a computing environment

By configuring virtual instances to receive remediation scripts and generate remediation infrastructure, the problem of high-level access permissions required for cybersecurity threat remediation solutions in existing technologies is solved, enabling rapid and low-cost cybersecurity threat response.

CN120165894BActive Publication Date: 2026-04-21WIZ INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
WIZ INC
Filing Date
2024-11-29
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In existing technologies, remediation solutions for cybersecurity threats require high-level access permissions, which makes organizations reluctant to allow third parties to continue accessing them, or requires organizations to maintain them themselves, which is costly.

Method used

By configuring virtual instances to receive remediation scripts, generating remediation infrastructure, detecting cybersecurity issues, and initiating corresponding remediation actions based on the detection results, generative remediation tools are used to generate and deploy remediation actions, including access revocation and license renewal, reducing the need for high-level access to the computing environment.

Benefits of technology

It enables rapid response to cybersecurity threats without requiring high-level access privileges, reducing the cost and complexity of remediation solutions and improving security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165894B_ABST
    Figure CN120165894B_ABST
Patent Text Reader

Abstract

A system and method of initiating remediation actions in response to a network security issue in a computing environment is disclosed. The method includes configuring a virtual instance in the computing environment to communicate with an inspection environment; configuring the virtual instance to receive a plurality of remediation scripts from the inspection environment in the computing environment; generating a remediation infrastructure comprising a plurality of remediation actions, each remediation action corresponding to at least one remediation script of the plurality of remediation scripts; detecting a network security issue in the computing environment; based on detecting the network security issue, configuring the virtual instance to initiate a remediation action of the plurality of remediation actions; and in response to initiating the remediation action, receiving feedback from the virtual instance in the inspection environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to cybersecurity remediation, and in particular to providing remediation infrastructure for cloud computing environments. Background Technology

[0002] Cybersecurity threats can appear in computing environments in various ways. For example, in cloud computing environments, some threats include vulnerabilities, misconfigurations, exposures, and exploitation.

[0003] Solutions exist for various cybersecurity threats to monitoring computing environments, including threat detection and digital forensics solutions. While monitoring typically requires read-level access to the computing environment, remediation and mitigation require actions to be performed and initiated within the computing environment, which usually require higher levels of permissions and access than simple read-level access.

[0004] For reasons such as these, remediation solutions are slow to be adopted because organizations are unwilling to allow third parties to maintain such access. Alternatively, remediation solutions could be maintained and provided by the organization itself within its computing environment, but this requires costly specialization to maintain.

[0005] Therefore, it would be beneficial to provide a solution that can overcome the above challenges. Summary of the Invention

[0006] The following is an overview of several exemplary embodiments of this disclosure. This overview is provided to facilitate the reader in gaining a basic understanding of these embodiments and is not intended to limit the breadth of this disclosure. This overview is not an extensive summary of all contemplated embodiments and is neither intended to identify key or essential elements of all embodiments nor to depict the scope of any or all aspects. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to the more detailed description that follows. For convenience, the terms "some embodiments" or "certain embodiments" may be used herein to refer to a single embodiment or multiple embodiments of this disclosure.

[0007] A system of one or more computers can be configured to perform specific operations or actions by installing software, firmware, hardware, or combinations thereof on the system, which in operation cause the system to perform these actions. A computer program can be configured to perform specific operations or actions by including instructions that, when executed by a data processing device, cause the device to perform these actions.

[0008] In one general aspect, the method may include configuring a virtual instance in a computing environment to communicate with an inspection environment. The method may also include configuring the virtual instance in the computing environment to receive multiple remediation scripts from the inspection environment. The method may further include generating a remediation infrastructure comprising multiple remediation actions, each remediation action corresponding to at least one of the multiple remediation scripts. The method may further include detecting cybersecurity issues in the computing environment. The method may further include configuring the virtual instance to initiate a remediation action among multiple remediation actions based on the detected cybersecurity issues. The method may further include receiving feedback from the virtual instance in the inspection environment in response to initiating a remediation action. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0009] Implementation may include one or more of the following features. Methods may include: examining network security objects in a computing environment, wherein the network security objects indicate network security issues. Methods may include: associating a first set of remedial actions of a plurality of remedial actions with a first group of user accounts; and associating a second set of remedial actions of a plurality of remedial actions with a second group of user accounts, wherein each group of user accounts is authorized to initiate only the remedial action associated with the corresponding user group. Methods may include: disabling the first remedial action of a plurality of remedial actions. Methods may include: detecting conditions in the computing environment; and disabling the first remedial action based on the detected conditions. Methods may include: enabling a second remediation based on the detected conditions. Methods may include: disabling the first remedial action of a plurality of remedial actions only for the first group of user accounts. Methods may include: associating the first remedial action with a first user group, wherein the first user group is authorized to initiate the first remedial action only for a first pre-authorized resource in the computing environment. Methods may include: associating the first remedial action with a second user group, wherein the second user group is authorized to initiate the first remedial action for any resource in the computing environment. The method may include: associating a first remedial action with a second user group, wherein the second user group is authorized to initiate the first remedial action only for a second pre-authorized resource, which is different from the first pre-authorized resource. The method may include: generating an indicator value for each remedial action, the indicator value indicating the degree of interruption of the determined remedial action. The method may include: granting permission to a first subject to initiate the first remedial action in response to determining that the degree of interruption of the determined first remedial action is at or above a threshold. The method may include: granting permission to the first subject only in response to detecting conditions in the computing environment. The method may include: configuring a virtual instance to receive a customized remedial script. The method may include: initiating a second remedial action in response to feedback indicating that the remedial action was unsuccessful. The method may include: generating a notification in response to feedback indicating that the remedial action was successful. The method may include: configuring a virtual instance to send a status report corresponding to the remedial infrastructure. Implementations of the described techniques may include hardware, methods or processes, or tangible computer media.

[0010] In one general aspect, a non-transitory computer-readable medium may include one or more instructions, which, when executed by one or more processors of a device, cause the device to: configure a virtual instance in a computing environment to communicate with an inspection environment. The medium may also configure the virtual instance to receive multiple remediation scripts from the inspection environment in the computing environment. The medium may also generate a remediation infrastructure including multiple remediation actions, each remediation action corresponding to at least one of the multiple remediation scripts. The medium may also detect cybersecurity issues in the computing environment. Based on the detected cybersecurity issues, the medium may also configure the virtual instance to initiate a remediation action among the multiple remediation actions. The medium may also receive feedback from the virtual instance in the inspection environment in response to initiating a remediation action. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0011] In one general aspect, the system may include processing circuitry. The system may also include memory containing instructions that, when executed by the processing circuitry, configure the system to: configure a virtual instance in a computing environment to communicate with an inspection environment. The system may also configure the virtual instance to receive multiple remediation scripts from the inspection environment in the computing environment. The system may also generate a remediation infrastructure including multiple remediation actions, each remediation action corresponding to at least one of the multiple remediation scripts. The system may also detect cybersecurity issues in the computing environment. Based on the detected cybersecurity issues, the system may also configure the virtual instance to initiate one of the multiple remediation actions. The system may also receive feedback from the virtual instance in the inspection environment in response to initiating a remediation action. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0012] The implementation may include one or more of the following features. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: examine network security objects in the computing environment, wherein the network security objects indicate network security issues. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: associate a first set of remedial actions out of a plurality of remedial actions with a first group of user accounts; and associate a second set of remedial actions out of a plurality of remedial actions with a second group of user accounts, wherein each group of user accounts is authorized to initiate only the remedial actions associated with the corresponding user group. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: disable the first remedial action out of a plurality of remedial actions. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: detect conditions in the computing environment; and disable the first remedial action based on the detected conditions. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: enable a second remediation based on the detected conditions. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to disable the first remedial action among multiple remedial actions only for a first group of user accounts. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to associate the first remedial action with a first user group, wherein the first user group is authorized to initiate the first remedial action only for a first pre-authorized resource in the computing environment. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to associate the first remedial action with a second user group, wherein the second user group is authorized to initiate the first remedial action for any resource in the computing environment. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to associate the first remedial action with a second user group, wherein the second user group is authorized to initiate the first remedial action only for a second pre-authorized resource, which is different from the first pre-authorized resource. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: generate an indicator value for each remedial action, the indicator value indicating the degree of interruption of the determined remedial action; and, in response to determining that the degree of interruption of the determined first remedial action is at or above a threshold, grant permission to a first subject to initiate a first remedial action. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: initiate a second remedial action in response to feedback indicating that a remedial action was unsuccessful. Implementations of the described techniques may include hardware, methods or processes, or a tangible computer medium. Attached Figure Description

[0013] The subject matter disclosed herein is specifically pointed out and clearly claimed in the claims of the specification. The foregoing and other objects, features, and advantages of the disclosed embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings.

[0014] Figure 1 This is an example schematic diagram of an inspection environment and a computational environment with a generative remedy implemented according to an embodiment.

[0015] Figure 2 This is an example diagram of a security diagram implemented according to an embodiment.

[0016] Figure 3 This is an example schematic diagram of a generative remedy data stream implemented according to an embodiment.

[0017] Figure 4 This is an example flowchart of a method for generating remedial actions implemented according to an embodiment.

[0018] Figure 5 This is an example flowchart of a method for initiating a remedial action according to an embodiment.

[0019] Figure 6 This is an example schematic diagram of data flow in a remediation infrastructure deployed in a computing environment, implemented according to an embodiment.

[0020] Figure 7 This is an example flowchart of a method for deploying and utilizing remediation infrastructure in a computing environment, implemented according to an embodiment.

[0021] Figure 8 This is an example flowchart of a method for providing remedial feedback from a computing environment to an inspection environment, implemented according to an embodiment.

[0022] Figure 9 This is an example schematic diagram of a generative remedy according to an embodiment. Detailed Implementation

[0023] It is important to note that the embodiments disclosed herein are merely examples of the many advantageous uses of the inventive teachings herein. Generally, the statements made in this specification do not necessarily limit any of the various claimed embodiments. Furthermore, some statements may apply to some inventive features but not to others. Generally, unless otherwise stated, singular elements may be plural, and vice versa, without loss of generality. In the drawings, the same numerals refer to the same parts in several views.

[0024] Figure 1This is an example schematic diagram of an inspection environment and a computing environment with a generative remediator, implemented according to an embodiment.

[0025] In this embodiment, the computing environment 110 includes multiple entities, such as resources, entities, etc. For example, in this embodiment, the entity is a cloud entity.

[0026] In some embodiments, the computing environment 110 is a cloud computing environment, an on-prem environment, a hybrid environment, or a combination thereof. In some embodiments, the cloud computing environment includes virtual private cloud (VPC) and virtual network (VNet), etc.

[0027] In some embodiments, the cloud computing environment is deployed on cloud computing infrastructure. In one embodiment, the cloud computing infrastructure is Amazon Web Services (AWS). Web Services, AWS, Google Cloud Platform Cloud Platform (GCP) and Microsoft Azure ( Azure, etc.

[0028] In some embodiments, the computing environment 110 includes multiple resources, such as virtual machine 112, software container 114, serverless functionality 116, and various combinations thereof. According to some embodiments, virtual machine 112 is, for example... Software container 114 exploit The platform, without server functionality, is 116. Lambda.

[0029] In some embodiments, the computing environment 110 includes multiple entities, such as user accounts, service accounts, local accounts, user groups, roles, and various combinations thereof.

[0030] In this embodiment, the computing environment 110 is monitored by a network security inspection environment 120 (also referred to as inspection environment 120). In some embodiments, the inspection environment 120 is implemented as a cloud computing environment, a hybrid environment, an on-premises environment, or a combination thereof.

[0031] In some embodiments, the inspection environment 120 includes multiple inspector workloads, such as inspector 122. In some embodiments, inspector 122 is configured to detect network security objects. For example, in some embodiments, inspector 122 is configured to detect network security objects on a disk associated with virtual machine 112. In some embodiments, inspectable disks are generated, for example, using clones, copies, and snapshots generated based on the disk of virtual machine 112.

[0032] In some embodiments, inspector 122 inspects inspectable disks. This allows, for example, static analysis to be performed on the disk without interfering with or utilizing the virtual machine 112 or its resources. In embodiments, network security objects are files, secrets, passwords, sensitive data, code objects, hashes, keys, certificates, registry files, libraries, software packages, binaries, applications, operating systems, malware, nested workloads, and combinations thereof.

[0033] In some embodiments, network security objects are used to detect network security risks. For example, in some embodiments, secrets and passwords are stored as easily accessible plaintext and simple text. In such embodiments, for example, by storing secrets in this way, secrets are more easily exposed, thus presenting a higher network security risk. In some embodiments, secrets provide access to another resource, thereby creating a network security risk of lateral movement paths.

[0034] In some embodiments, the inspection controller 124 is configured to initiate the generation of an inspectable disk using a service account in the computing environment 110. In some embodiments, the inspection controller 124 is configured to generate an inspector workload (such as inspector 122, etc.) in response to a demand for inspector workloads. For example, in one embodiment, the inspection controller 124 is configured to have permission to instantiate a virtual instance that executes an application configured to inspect inspectable disks for network security objects.

[0035] According to some embodiments, inspector 122 is configured to store data, information, etc., about network security objects, inspections, etc., in security database 126. In some embodiments, security database 126 includes constraints and predefined data schemas, etc., for representing computing environment 110.

[0036] In some embodiments, the data schema of the security database 126 is used to represent the computing environment 110 using multiple data templates, each template describing a different entity. For example, in one embodiment, a first data template is used to describe resources, and a second data template is used to describe entities. In another embodiment, the first data template is used to describe any resource in the computing environment 110, that is, the first data template is used to represent the virtual machine 112, the serverless function 116, and the software container 114.

[0037] In some embodiments, the security database 126 is implemented as a tabular database, a columnar database, an SQL database, a non-SQL database, a graph database, and various combinations thereof. For example, in one embodiment, the security database 126 is a graph database, such as... The entities, resources, remedial actions, cybersecurity risks, cybersecurity objects, enrichments, and endpoints are stored as nodes on a graph stored in the security database 126. (See the following reference.) Figure 2 An example representation of the computing environment is discussed in more detail.

[0038] According to an embodiment, the inspection environment 120 also includes a generative remediator 128. In an embodiment, the generative remediator includes a generated artificial intelligence model, such as a large language model (LLM). In some embodiments, the LLM is, for example... wait.

[0039] In some embodiments, the generative remediation unit 128 is configured to generate remediation actions. In some embodiments, the generative remediation unit 128 is configured to generate remediation actions in response to the detection of cybersecurity threats and risks, such as based on the detection of cybersecurity objects. In embodiments, cybersecurity threats include misconfigurations, vulnerabilities, exposures, and various combinations thereof.

[0040] In some embodiments, a cybersecurity threat is detected in response to the detection of multiple cybersecurity objects, cybersecurity objects and attack paths (e.g., exposures), cybersecurity objects and vulnerabilities, and various combinations thereof. In the embodiments, such combinations are also referred to as toxic combinations.

[0041] In one embodiment, the generative remediator 128 is configured to generate tips for LLM. In some embodiments, tips are generated based on representation patterns of the security database 126, discoveries (e.g., results of cybersecurity checks, such as detection of cybersecurity objects), predefined actions, and combinations thereof.

[0042] According to an embodiment, the generative remedy 128 is configured to generate prompts based on a predefined template. In this embodiment, generating prompts based on a predefined template includes parsing the input received by the generative remedy 128, detecting the values ​​of data fields therein, and adjusting the predefined template based on the detected data values.

[0043] In some embodiments, it is advantageous to provide the LLM with hints that include a data pattern for representation (i.e., a representation pattern) because this reduces the need for fine-tuning the LLM.

[0044] In some embodiments, the generative remedy 128 is further configured to initiate a remedy action. In some embodiments, the remedy action is: initiation of a resource, initiation of a subject, or a combination thereof.

[0045] For example, according to embodiments, remedial actions include: revoking access to a resource, revoking access from a resource, revoking access from a subject, revoking access to a subject, updating a subject's license, changing a subject's user group, changing a subject's role, revoking an access token, sandboxing a resource, configuring a firewall to filter traffic to a resource, configuring a firewall to filter traffic from a resource, generating an alert, installing a patch, removing a software application from a resource, updating a software package, removing a software package, and combinations thereof.

[0046] In some embodiments, the inspection environment 120 and the generative remedy 128 are configured to deploy the remedy 118 in the computing environment 110. For example, according to embodiments, the remedy 118 is implemented as a serverless function, a software container, a virtual machine, or a combination thereof.

[0047] In this embodiment, the remediator 118 is a workload configured to deploy, manage, and expose remediation infrastructure within the computing environment 110. This will be referenced below. Figure 6 Let's discuss this in more detail.

[0048] In some embodiments, the remediator is configured to deploy multiple remediation actions, each including a remediation script. According to embodiments, the remediation script includes scripts, code, and instructions, etc., which, when executed in computing environment 110, remediate and attempt to remediate cybersecurity issues detected in computing environment 110.

[0049] In some embodiments, the first set of remedial actions is generated by the generative remediator 128, and the second set of remedial actions is a predefined remedial action.

[0050] Figure 2 This is an example diagram of a security graph implemented according to an embodiment. In the embodiment, for example, network security objects of the virtual machine are inspected by an inspector, which is discussed in more detail throughout the text.

[0051] According to an embodiment, inspectors and inspection controllers are configured to generate representations of virtual machines, such as virtual machine (VM) node 230. In an embodiment, the inspector is configured to detect application endpoints represented as endpoint node 220. Application endpoints allow virtual machines to connect to public networks, such as the Internet. In an embodiment, endpoint node 220 is connected to public network node 210, indicating that the application (APP) endpoint can access the public network.

[0052] In some embodiments, the inspector is also configured to detect managed technologies. For example, according to an embodiment, a managed technology (such as a database) is represented by a managed technology node. In some embodiments, a database is represented by a database (DB) node 232, and the DB node 232 is connected to the VM node 230 to indicate that the DB is hosted on a VM.

[0053] According to embodiments, the inspector is configured to detect secrets on the VM. In some embodiments, a single inspector is configured to detect multiple network security objects. In other embodiments, each inspector is configured to detect a single network security object.

[0054] In one embodiment, the detected secret is represented by a secret node 234 connected to VM node 230. In some embodiments, the detected secret is associated with a user account represented by user node 240. In one embodiment, the user account is configured to assume an administrator account, represented by management node 250. In one embodiment, the administrator account is configured to access resources (such as buckets) that expose data therein. In some embodiments, the resource is represented by resource node 260.

[0055] In some embodiments, the inspector is configured to detect network security objects that indicate vulnerabilities, exposures, misconfigurations, etc., within the VM (e.g., represented by CVE (common vulnerabilities and exposures) node 235). For example, in one embodiment, CVE node 235 represents the Log4Shell vulnerability in Log4j. According to an embodiment, CVE node 235 is connected to VM node 230 to indicate that a vulnerability has been detected on the VM.

[0056] In some embodiments, security discovery is represented by security discovery node 231. For example, according to an embodiment, this includes access logs (such as network logs, cloud logs, and event logs). In some embodiments, logs are parsed to detect the VM's identifier.

[0057] In an embodiment, events are detected in the log, each corresponding to an identifier associated with a security discovery. For example, in an embodiment, multiple unsuccessful access events indicate an attempt to brute-force the VM. In some embodiments, the security discovery node 231 connects to the VM node 230 to indicate that a security discovery has been detected regarding the VM.

[0058] In some embodiments, the security database is configured to detect potential lateral movement paths from a VM (VM node 230) to a resource (resource node 260) by gaining access to the VM (e.g., through brute force), gaining access to secrets stored thereon, and from there using the user to gain administrative access to the resource. In embodiments, lateral movement (LM) paths and potential lateral movement paths are represented by an LM discovery node 233 connected to VM node 230 to indicate, for example, the existence of a lateral movement path between VM node 230 and another resource.

[0059] In some embodiments, the toxic combination is defined by policies, conditions, rules, and combinations thereof. For example, in the embodiments described above, vulnerabilities combined with secrets pose a higher cybersecurity risk than any one of these findings alone.

[0060] Detecting such toxic combinations is advantageous because it allows for remedial action to be initiated at multiple points (e.g., each element of the toxic combination) to address cybersecurity threats.

[0061] In some embodiments, nodes representing discoveries, cybersecurity risks, and cybersecurity objects are connected to remediation nodes, where remediation nodes represent remediation actions. In some embodiments, for example, a generative remediator is configured to detect remediation actions based on remediation nodes and adapt remediation action templates to specific discoveries.

[0062] Figure 3 This is an example schematic diagram of a generative remedy data flow implemented according to an embodiment. In this embodiment, the generative remedy 310 is configured to receive multiple inputs. In some embodiments, the received inputs are predefined actions 320, discovery 330, representation patterns 340, and combinations thereof.

[0063] In some embodiments, the predefined action 320 is a remedial action, a remedial script, an instruction, or a combination thereof. In some embodiments, the predefined action 320 includes templates, predefined values, or combinations thereof.

[0064] In some embodiments, discovery 330 is generated from security graphs, inspectors, and inspection controllers, for example, based on cybersecurity objects detected in a computing environment.

[0065] In some embodiments, discovery 330 is security discovery, lateral movement discovery, CVE discovery, privilege escalation discovery, and various combinations thereof.

[0066] In some embodiments, security findings indicate cybersecurity issues and toxic combinations of cybersecurity issues. For example, in embodiments, cybersecurity issues include vulnerabilities, misconfigurations, exposures, attack paths, and combinations thereof.

[0067] In embodiments, for example, security discoveries are generated based on events in detection logs. For example, security discoveries may be for detecting brute-force attacks (e.g., multiple failed login attempts). According to embodiments, lateral movement discovery includes detecting lateral movement paths between a first resource and a second resource, for example, by traversing a security graph in a security database to detect potential lateral movement paths. In embodiments, lateral movement discovery includes secrets, keys, and principals that connect the first resource to the second resource.

[0068] According to an embodiment, the representation schema includes database schemas and constraints, which are used to represent computing environments, their discoveries, their enrichments, remedial actions, cybersecurity risks, cybersecurity threats, and cybersecurity objects in a secure database.

[0069] In one embodiment, the generative remedy 310 is configured to receive user input as further input. For example, in one embodiment, the user input indicates a platform preference for resolving cybersecurity issues.

[0070] In some embodiments, the computing environment includes multiple platforms, such as CLI (command line interface), cloud computing consoles, infrastructure as code (IaC) platforms, and various combinations thereof. Additionally, in some embodiments, various remedial actions can be deployed in a production environment, for example, by instructing admission controllers and sensors to initiate remedial actions.

[0071] Therefore, according to embodiments, cybersecurity issues can be remedied from multiple points in the environment. For example, a cybersecurity issue could be the detection of exposure due to misconfiguration (e.g., a database containing sensitive data that is not password protected, hosted on a virtual machine on which sensors are deployed).

[0072] In embodiments, remedies for the aforementioned cybersecurity issues include any of the following: configuring sensors to set a password for the database, updating IaC files (e.g., The code object in the file is used to deploy a VM with a managed database, including password protection, etc. In some embodiments, user preferences are determined corresponding to the platform used to remedy cybersecurity issues. In some embodiments, multiple preferred platforms are selected.

[0073] According to an embodiment, the generative remediator 310 is configured to generate remediation actions 350. In some embodiments, remediation actions 350 include remediation scripts, such as multi-line code that remediates cybersecurity issues when executed in a computing environment.

[0074] In some embodiments, the generative remediation unit 310 is configured to generate a plurality of remediation actions. In some embodiments, the generative remediation unit 310 is configured to generate a priority value for each of the plurality of remediation actions. For example, in one embodiment, the priority value is generated based on past success indicators. This is advantageous because remediation actions that were effective in remediating cybersecurity issues in the past may be effective against current cybersecurity threats.

[0075] Figure 4 This is an example flowchart of a method for generating remedial actions implemented according to an embodiment.

[0076] In S410, the computing environment is checked for network security objects. In an embodiment, checking the computing environment for network security objects includes detecting multiple resources deployed in the computing environment.

[0077] In some embodiments, detecting multiple resources includes, for example, entity discovery. In embodiments, entity discovery includes querying the application programming interface (API) of a computing environment (such as a cloud computing environment) to determine which resources and workloads are deployed therein.

[0078] For example, according to an embodiment, a cloud API is accessed to determine which virtual machines, software containers, serverless functions, microservices, buckets, storage, and software repositories are deployed in the computing environment.

[0079] In this embodiment, resources are inspected to detect nested resources. For example, in this embodiment, virtual machines are configured to host a software container platform (e.g., Kubernetes), and each virtual machine and the software container deployed on it are individually inspected as network security objects.

[0080] In some embodiments, inspecting a computing environment includes generating an inspectable disk based on the original disks deployed in the computing environment. In some embodiments, generating an inspectable disk includes generating clones, copies, snapshots, and combinations thereof of the original disks.

[0081] According to an embodiment, in response to a request to initiate a raw disk check, an inspectable disk is generated on demand, and in response to determining that the check is complete, resources allocated to the inspectable disk are released.

[0082] In some embodiments, multiple inspectors are assigned to inspect network security objects on inspectable disks, each inspector being configured to inspect a different network security object. For example, in one embodiment, a first inspector is configured to inspect nested workloads, while a second inspector is configured to inspect secrets.

[0083] In this embodiment, network security objects include files, secrets, passwords, sensitive data, code objects, hashes, keys, certificates, registry files, libraries, software packages, binaries, applications, operating systems, malware, nested workloads, and combinations thereof.

[0084] In S420, network security issues are detected. In some embodiments, network security issues are detected based on the detection of network security objects. In some embodiments, network security issues are detected based on a combination of detecting network security objects and discoveries. For example, in some embodiments, discoveries include security discoveries, lateral movement discoveries, privilege escalation discoveries, vulnerabilities, exposures, misconfigurations, malware, attack paths, and various combinations thereof.

[0085] As an example, a combination (also known as a toxic combination) includes vulnerability detection, such as running applications with known vulnerabilities, and hosting technologies for endpoints (e.g., indicating access to public networks), where the hosting technology is configured to use service accounts with high permissions.

[0086] In some embodiments, detecting toxic combinations includes applying policies, rules, and conditions to a representation of the computing environment. In some embodiments, a security database is queried based on, for example, a pre-existing query configured to detect toxic combinations. For example, in some embodiments, a security graph is traversed to detect nodes corresponding to queries pointing to the security graph, such as those described above. Figure 2 More detailed diagrams, etc.

[0087] In some embodiments, multiple cybersecurity issues are detected. In some embodiments, each cybersecurity issue includes a priority score, a severity score, and combinations thereof. For example, in embodiments, the scores are qualitative scores (e.g., low, medium, high), quantitative scores (e.g., from 1 to 10), and combinations thereof.

[0088] In S430, a remedial action is generated. In some embodiments, the remedial action is generated by a generative remediator configured to generate remedial actions. In some embodiments, the remedial action is generated based on a cybersecurity issue.

[0089] In an embodiment, the generative remedy is configured to receive network security issues, including, for example, identifiers of resources (e.g., names and IP addresses in namespaces) and data about network security objects, and generate remedy actions based on the received input.

[0090] In some embodiments, remedial actions are generated based on templates, such as code templates. In embodiments, the code templates include machine-readable instructions that, when executed in a computing environment (such as a cloud computing environment), cause remedial actions to be initiated.

[0091] In some embodiments, the generative remediator is configured to generate hints for a large language model (LLM), which are configured to generate remedial actions. In embodiments, the hints are generated based on templates (e.g., code templates).

[0092] In some embodiments, a first LLM is used to generate prompts, and a second LLM is used to generate remedial actions. In embodiments, the first LLM and the second LLM are the same model.

[0093] In an embodiment, when provided to an LLM model, the prompt configures the LLM model to generate output including remedial actions. In an embodiment, the remedial actions include remedial scripts and multiple remedial scripts, etc. In an embodiment, the remedial scripts include code, such as high-level code, etc. In some embodiments, the high-level code script, for example, is... script.

[0094] Figure 5 This is an example flowchart of a method for initiating a remedial action according to an embodiment. In this embodiment, the initiated remedial action is generated by a generative remediator, as described above regarding... Figure 4 To be discussed in more detail.

[0095] In S510, input is received. In some embodiments, the received input is provided to the generative remediation unit. In some embodiments, the received input includes network security issues, network security alerts, predefined actions, discoveries, representation patterns, and combinations thereof.

[0096] In some embodiments, predefined actions include remedial actions, remedial scripts, instructions, and combinations thereof. In some embodiments, predefined actions include templates, predefined values, and combinations thereof.

[0097] In some embodiments, discoveries are generated, for example, based on cybersecurity objects detected in a computing environment, by security graphs, inspectors, and inspection controllers.

[0098] In some embodiments, discovery includes security discovery, lateral movement discovery, CVE discovery, privilege escalation discovery, and various combinations thereof. In some embodiments, security discovery indicates cybersecurity issues and toxic combinations of cybersecurity issues. For example, in embodiments, cybersecurity issues include vulnerabilities, misconfigurations, exposures, attack paths, and combinations thereof.

[0099] In embodiments, for example, security discoveries are generated based on events in detection logs. For example, a security discovery might be the detection of brute-force attacks (e.g., multiple failed login attempts). According to embodiments, lateral movement discovery includes detecting lateral movement paths between a first resource and a second resource, for example, by traversing a security graph in a security database to detect potential lateral movement paths. In embodiments, lateral movement discovery includes secrets, keys, and principals that connect the first resource to the second resource.

[0100] According to the embodiments, the representation schema includes database schema, constraints, etc., used to represent computing environments, their discovery, their enrichment, remedial actions, cybersecurity risks, cybersecurity threats, cybersecurity objects, etc. in a security database.

[0101] In one embodiment, the generative remediator is configured to receive user input as further input. For example, in one embodiment, the user input indicates a platform preference for remediating cybersecurity issues.

[0102] In S520, a prompt is generated. In an embodiment, the prompt is generated by a first LLM and provided as input to a second LLM. In some embodiments, the first LLM is the second LLM.

[0103] In some embodiments, the generative remediator is configured to generate hints for a large language model (LLM), which are configured to generate remedial actions. In embodiments, the hints are generated based on templates (e.g., code templates).

[0104] In an embodiment, when provided to an LLM model, the prompt configures the LLM model to generate output including remedial actions. In an embodiment, the remedial actions include remedial scripts and multiple remedial scripts, etc. In an embodiment, the remedial scripts include code, such as high-level code, etc. In some embodiments, the high-level code script, for example, is... script.

[0105] In S530, a remedial action is initiated. In this embodiment, the remedial action is generated based on the LLM's output. For example, according to this embodiment, the prompt generated in S520 is provided to the LLM, configuring the LLM to generate output including the remedial action.

[0106] In embodiments, initiating a remedial action includes executing one or more instructions in a computing environment. In some embodiments, the remedial action is initiated with respect to a computing platform among multiple computing platforms deployed in the computing environment. For example, according to one embodiment, the computing environment is a command line interface (CLI), an Infrastructure as Code (IaC) platform, a console, sensors, an admission controller, or a combination thereof.

[0107] Figure 6 This is an example schematic diagram of a remediation infrastructure deployed in a computing environment according to an embodiment. In some embodiments, inspection environment 610 is configured to deploy the remediation infrastructure in computing environment 620.

[0108] For example, in one embodiment, the inspection environment 610 is configured to generate workloads, such as a remedy 626 deployed in the computing environment 620. In some embodiments, this is advantageous because it does not require the inspection environment to be granted permission to access the entire computing environment 620; instead, the organization of the computing environment 620 can deploy the remedy workload 626 according to the organization's standards and best practices.

[0109] In some embodiments, the remedy 626 is configured to communicate with a queue service 624. In embodiments, the queue service 624 is configured to communicate with a notification service 622. In some embodiments, the queue service 624 and the notification service 622 are implemented as a single queue service; for convenience only, they are shown as separate entities herein. In an embodiment, the notification service 622 is, for example, Amazon. Short notification service (SNS). In some embodiments, queue service 624 is Amazon Short Queue Service (SQS).

[0110] In some embodiments, each component of the remediation infrastructure is configured to receive data from a single source and send data to a single destination. For example, queue service 624 is configured to send, store, and receive messages between software components in the computing environment (e.g., between notification service 622 and remediator 626).

[0111] In some embodiments, notification service 622 is configured to send, store, and receive messages between software components of computing environment 620 and software components of inspection environment 610. According to embodiments, remedy 626 is configured to deploy multiple remedy actions. In some embodiments, each remedy action corresponds to a script, multiple scripts, etc., such as multiple remedy scripts 628-1 to 628-N, where "N" is a natural number with a value of "2" or greater.

[0112] In some embodiments, remedy 626 is configured to initiate a remedy action, for example, by executing script 628-2. In some embodiments, remedy 626 is configured to determine the result of executing script 628-2. For example, in one embodiment, remedy 626 is configured to detect the result of the remedy action in logs such as activity logs, cloud logs, network logs, identity and access management logs, and combinations thereof.

[0113] In some embodiments, the remedial action includes a defined effect. For example, according to an embodiment, a defined effect (also referred to as a result, feedback, etc.) of changing permissions associated with a user account includes a record in a log indicating that a user account having a first set of permissions has been modified to include a second set of permissions. In such an embodiment, the remediator 626 is also configured to detect the defined effect, for example by parsing logs, detecting log entries, and detecting artifacts in the computing environment.

[0114] In some embodiments, the remedy 626 is configured to determine whether a remedy action is successful or unsuccessful. For example, in one embodiment, the remedy 626 is configured to determine the success of the remedy action based on the determined result of performing the remedy action.

[0115] In some embodiments, the results of the remedial actions are provided to the inspection environment 610. In certain embodiments, the inspection environment 610 is configured to update the security database based on the results of the remedial actions. For example, if a remedial action for a cybersecurity issue is successful, the cybersecurity issue is removed from the representation of the computing environment stored in the security database.

[0116] Figure 7 This is an example flowchart of a method for deploying and utilizing remediation infrastructure in a computing environment, implemented according to an embodiment.

[0117] In S710, remediation infrastructure is deployed in the computing environment. In some embodiments, the remediation infrastructure includes: multiple remediation actions, multiple remediation scripts, workloads, queuing services, notification services, and combinations thereof.

[0118] In some embodiments, receiving a selection allows choosing a set of multiple remediation scripts. This is useful, for example, when the multiple remediation scripts include scripts that are not applicable to a particular deployment's computing environment and the deployed computing platform, etc.

[0119] In one embodiment, the workload is configured to initiate remedial actions in the computing environment and communicate with the inspection environment (e.g., via queuing and notification services).

[0120] According to some embodiments, the workload is configured to send identifiers for each remediation script, each remediation action, each active remediation script, each active remediation action, each inactive remediation script, each inactive remediation action, and various combinations thereof. For example, in some embodiments, the workload is configured to periodically send identifiers in response to requests from the inspection environment and combinations thereof.

[0121] In optional S720, the remediation infrastructure is customized. In some embodiments, the remediation infrastructure is customized by selecting workloads that can be deployed in a computing environment. For example, in embodiments, the remediation infrastructure includes serverless functions, software containers, and virtual machines, each of which is configured to perform the functions of a remediator.

[0122] In some embodiments, the workload type is determined based on the computing environment, resource allocation within the computing environment, etc. In some embodiments, remedial actions are customized. Customizing remedial actions in some embodiments includes providing customized remedial actions. In some embodiments, customizing remedial actions includes selecting a set of remedial actions from a plurality of remedial actions, such that the set of remedial actions can be executed in the computing environment.

[0123] In S730, multiple remediation scripts are deployed in the computing environment. In an embodiment, deploying multiple remediation scripts includes sending the remediation scripts from the inspection environment to the remediator via a remediation infrastructure. In some embodiments, the remediation scripts are deployed continuously, periodically, on demand, and in combination thereof.

[0124] In some embodiments, the deployed remediation script includes unique identifiers, such as globally unique identifiers and locally unique identifiers. In some embodiments, the globally unique identifier is unique across multiple computing environments, while the locally unique identifier is unique within a single computing environment.

[0125] In S740, a representation of the remediation script is generated. In embodiments, this representation includes a visual representation, such as a graphical user interface (GUI) for controlling the remediation infrastructure. For example, according to an embodiment, the GUI includes indicators for determining whether the remediation script is active (i.e., the script is deployed in the computing environment and can be started) or inactive (i.e., the script is deployed in the computing environment and cannot be started).

[0126] In some embodiments, the GUI includes an interrupt indicator to indicate the degree of interruption to the computing environment, its resources, and its main body caused by initiating a remedial action. In some embodiments, the interrupt indicator includes a value. In embodiments, the value is a binary value (e.g., true / false). In some embodiments, the value is qualitative (e.g., low, high, etc.), quantitative (e.g., from 1 to 10), and combinations thereof, etc.

[0127] According to embodiments, the GUI also includes indicators indicating which user accounts, user groups, and user roles are configured with permission to initiate remediation actions and remediation scripts in the computing environment. In some embodiments, input received through the GUI configures the environment to deploy changes within the remediation infrastructure.

[0128] In S750, user input is received. In some embodiments, user input is received via a GUI. In some embodiments, the user input received via the GUI configures the inspection environment to deploy changes in the remediation infrastructure.

[0129] According to embodiments, changes to the remediation infrastructure include updating remediation actions, updating remediation scripts, changing permissions associated with remediation actions, changing permissions associated with remediation scripts, deploying new remediation actions, deploying new remediation scripts, deleting remediation actions, deleting remediation scripts, initiating remediation actions, initiating remediation scripts, providing remediation actions, providing remediation scripts, and combinations thereof.

[0130] Figure 8 This is an example flowchart of a method for providing remedial feedback from a computing environment to an inspection environment, implemented according to an embodiment.

[0131] In S810, a remedial action is selected. In an embodiment, a remedial action is selected from a list of predetermined remedial actions. In some embodiments, a remedial action includes one or more remedial scripts. In an embodiment, the remedial action is generated by a generative remediator, such as those discussed in more detail herein.

[0132] According to embodiments, in response to detecting a cybersecurity issue, a remedial action is selected. In some embodiments, a remedial action is selected from a plurality of remedial actions. In some embodiments, the cybersecurity issue includes a plurality of applicable remedial actions, each of which is applicable to a unique computing platform within the computing environment.

[0133] In some embodiments, a check is performed to determine whether a previous remedial action was selected from the cybersecurity issue. In some embodiments, the remedial action failed to remedy the cybersecurity issue, so it is advantageous to initiate a second, different remedial action to remedy the cybersecurity issue.

[0134] In S820, the remediation script is initiated. In an embodiment, initiating the remediation script includes executing scripts and code in a computing environment.

[0135] In some embodiments, remedial scripts configure the computing environment to revoke access to a resource, revoke access from a resource, revoke access from a subject, revoke access to a subject, update a subject's license, change a subject's user group, change a subject's role, revoke an access token, sandbox a resource, configure a firewall to filter traffic to a resource, configure a firewall to filter traffic from a resource, generate alerts, install patches, remove software applications from a resource, update software packages, remove software packages, and combinations thereof.

[0136] In some embodiments, remedial actions and remedial scripts are initiated by subjects in the computing environment. For example, in some embodiments, a first group of subjects (e.g., a first user group) includes licenses and license sets that authorize the first group of subjects to initiate a first set of remedial actions. In some embodiments, licenses and license sets authorize the first group of subjects to initiate only the first set of remedial actions.

[0137] According to some embodiments, a level of disruption is determined for each remedial action, each remedial script, and combinations thereof. In some embodiments, permission to initiate a remedial action is further determined based on the level of disruption. For example, according to an embodiment, permission to initiate a remedial action with a “high” level of disruption is granted only to users associated with a first role.

[0138] In some embodiments, conditions of the computing environment are detected. In these embodiments, conditions include network bandwidth utilization (e.g., as an indicator of activity), the number of logged-in user accounts, the amount of resources used, the amount of available resources, the type of computing environment (e.g., cloud, on-prem, hybrid, and VPC), the type of computing infrastructure (e.g., bare metal, AWS, and GCP), and various combinations thereof. In these embodiments, permissions are further determined based on the conditions of the computing environment. For example, according to an embodiment, based on the determined conditions, remedial actions are fully enabled for a first user group, or remedial actions are fully disabled for the first user group, etc.

[0139] In some embodiments, permission to initiate remedial actions is determined based on a combination of the degree of interruption to the computing environment and conditions. In embodiments, permission is determined continuously, periodically, ad-hoc, and combinations thereof.

[0140] In S830, feedback is received from the computing environment. In some embodiments, the feedback includes instructions corresponding to a successful remediation action. In some embodiments, the feedback is generated by a remediator deployed in the computing environment as part of the deployed remediation infrastructure.

[0141] In some embodiments, feedback, results, and effects are determined in a computing environment by detecting events in event logs and detecting artifacts, etc.

[0142] For example, according to an embodiment, a determined effect (also referred to as a result, feedback, etc.) of changing the permissions associated with a user account includes a record in a log indicating that a user account having a first set of permissions has been modified to include a second set of permissions. In such an embodiment, the remedy 626 is also configured to detect the determined effect, for example by parsing the log, detecting log entries, and detecting artifacts in the computing environment.

[0143] In S840, a check is performed to determine whether the network security issue has been remedied. In an embodiment, the check is performed based on received feedback. In an embodiment, if the network security issue has been remedied, the execution ends. In some embodiments, if the network security issue has not been remedied (e.g., the remediation action was unsuccessful), execution continues to S850.

[0144] In S850, a notification is generated. In embodiments, the notification includes emails, alerts, and tickets, indicating that remedial actions were unsuccessful. In some embodiments, the notification indicates that remedial actions failed to mitigate the cybersecurity threat.

[0145] In S860, a check is performed to determine whether another remedial action should be initiated. This is advantageous if the previous remedial action failed or was unsuccessful. In an embodiment, if "yes," execution continues in S810 by selecting a different remedial action. In some embodiments, execution terminates when "no."

[0146] Figure 9 This is an example schematic diagram of a generative remedy 128 according to an embodiment. The generative remedy 128 includes processing circuitry 910 coupled to a memory 920, a storage device 930, and a network interface 940. In this embodiment, the components of the generative remedy 128 can be communicatively connected via a bus 950.

[0147] The processing circuitry 910 can be understood as one or more hardware logic components and circuits. For example, but not limited to, illustrative types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip systems (SOCs), graphics processing units (GPUs), tensor processing units (TPUs), general-purpose microprocessors, microcontrollers, and digital signal processors (DSPs), or any other hardware logic component capable of performing computations or other information operations.

[0148] The memory 920 may be volatile (e.g., random access memory, etc.), non-volatile (e.g., read-only memory and flash memory, etc.), or a combination thereof. In embodiments, the memory 920 is on-chip memory, off-chip memory, and combinations thereof. In some embodiments, the memory 920 is a temporary storage memory for processing circuitry 910.

[0149] In one configuration, software for implementing one or more embodiments disclosed herein may be stored in storage device 930, memory 920, and combinations thereof. Software should be interpreted broadly as any type of instruction, whether referred to as software, firmware, middleware, microcode, hardware description language, or others. Instructions may include code (e.g., source code format, binary code format, executable code format, or any other suitable code format). When executed by processing circuitry 910, the instructions cause processing circuitry 910 to perform the various processes described herein.

[0150] Storage device 930 is a magnetic storage device, an optical storage device, a solid-state storage device, or a combination thereof. According to an embodiment, storage device 930 is implemented as flash memory, hard disk drive or other memory technology, or any other medium that can be used to store desired information.

[0151] Network interface 940 is configured to provide communication to generative remedies 128, such as inspector 122, inspection controller 124, security database 126, and remedy 118.

[0152] It should be understood that the embodiments described herein are not limited to those described herein. Figure 9 The specific architecture shown can be used equivalently with other architectures without departing from the scope of the disclosed embodiments.

[0153] Furthermore, in some embodiments, the inspector 122, the inspection controller 124, the security database 126, and the remedy 118 may be employed. Figure 9 The architecture shown is an implementation of the present invention. In other embodiments, other architectures may be used equivalently without departing from the scope of the disclosed embodiments.

[0154] The various embodiments disclosed herein can be implemented as hardware, firmware, software, or any combination thereof. Furthermore, the software is preferably implemented as an application tangibly embodied in a program storage unit or computer-readable medium, which comprises some or some devices and / or combinations of devices. The application can be uploaded to and executed by a machine including any suitable architecture. Preferably, the machine is implemented on a computer platform having hardware such as one or more central processing units (“CPUs”), memory, and input / output interfaces. The computer platform may also include an operating system and microinstruction code. The various processes and functions described herein may be part of the microinstruction code or an application program, or any combination thereof, which can be executed by the CPU, whether or not such a computer or processor is explicitly shown. Furthermore, various other peripheral units may be connected to the computer platform, such as additional data storage units and printing units. Additionally, a non-transitory computer-readable medium is any computer-readable medium other than transient propagation signals.

[0155] All examples and conditional language listed herein are intended for pedagogical purposes to aid the reader in understanding the principles of the disclosed embodiments and the concepts contributed by the inventors to advance the art, and should be understood as not being limited to these specifically listed examples and conditions. Furthermore, all statements regarding the principles, aspects, and embodiments of the disclosed embodiments, as well as specific examples thereof, are intended to cover their structural and functional equivalents. Additionally, it is intended that such equivalents include both currently known equivalents and those developed in the future; that is, any element developed that performs the same function, regardless of its structure.

[0156] It should be understood that any reference to elements in this document using names such as "first," "second," etc., generally does not limit the number or order of these elements. Rather, these names are generally used herein as a convenient way to distinguish two or more elements or instances of elements. Therefore, references to first and second elements do not imply that only two elements can be used there, or that the first element must somehow precede the second element. Furthermore, unless otherwise stated, a group of elements includes one or more elements.

[0157] As used herein, the phrase “at least one” followed by a list of items means that any of the listed items may be used alone, or any combination of two or more of the listed items may be used. For example, if a system is described as including “at least one of A, B, and C”, then the system may include only A; only B; only C; 2 A; 2 B; 2 C; 3 A; a combination of A and B; a combination of B and C; a combination of A and C; a combination of A, B, and C; a combination of 2 A and C; a combination of A, 3 B, and 2 C, and so on.

Claims

1. A method for initiating remediation actions in response to a cybersecurity issue in a computing environment, comprising: Configure virtual instances in the computing environment to communicate with the inspection environment; Configure the virtual instance to receive multiple remediation scripts from the inspection environment in the computing environment; Generate a remediation infrastructure that includes multiple remediation actions, each remediation action corresponding to at least one of the multiple remediation scripts; Detect network security issues in the computing environment; Based on the detection of the network security issue, the virtual instance is configured to initiate a remedial action among the multiple remedial actions; as well as In response to initiating the remedial action, feedback is received in the inspection environment from the computing environment in which the virtual instance is deployed.

2. The method according to claim 1, further comprising: Examine network security objects in the computing environment, wherein the network security objects indicate the network security issue.

3. The method according to claim 1, further comprising: Associate the first set of remedial actions among the plurality of remedial actions with the first set of user accounts; as well as The second group of remedial actions is associated with a second group of user accounts, wherein each group of user accounts is authorized to initiate only the remedial action associated with the user account in the corresponding group.

4. The method of claim 3, further comprising: Disable the first of the multiple remedial actions.

5. The method of claim 4, further comprising: Detect the conditions in the computing environment; as well as The first remedial action is disabled based on the detected conditions.

6. The method of claim 5, further comprising: A second remedy is activated based on the detected conditions.

7. The method of claim 3, further comprising: The first of the multiple remedial actions is disabled only for the first group of user accounts.

8. The method of claim 3, further comprising: The first remedial action is associated with the first group of user accounts, wherein the first group of user accounts is authorized to initiate the first remedial action only for a first pre-authorized resource in the computing environment.

9. The method of claim 8, further comprising: The first remedial action is associated with the second group of user accounts, wherein the second group of user accounts is authorized to initiate the first remedial action on any resource in the computing environment.

10. The method of claim 8, further comprising: The first remedial action is associated with the second group of user accounts, wherein the second group of user accounts is authorized to initiate the first remedial action only for a second pre-authorized resource, which is different from the first pre-authorized resource.

11. The method of claim 1, further comprising: An indicator value is generated for each remedial action, which indicates the degree of interruption of the determined remedial action.

12. The method of claim 11, further comprising: In response to determining that the degree of interruption of the determined first remedial action is at or above a threshold, permission is granted to the first subject to initiate the first remedial action.

13. The method of claim 12, further comprising: Permissions are granted to the first subject only in response to the detection of conditions in the computing environment.

14. The method of claim 1, further comprising: Configure the virtual instance to receive custom remediation scripts.

15. The method of claim 1, further comprising: In response to feedback indicating that the remedial action was unsuccessful, a second remedial action is initiated.

16. The method of claim 1, further comprising: A notification is generated in response to feedback indicating that the remedial action was successful.

17. The method of claim 1, further comprising: Configure the virtual instance to send status reports corresponding to the remediation infrastructure.

18. A non-transitory computer-readable medium storing a set of instructions for initiating remedial actions in response to a cybersecurity issue in a computing environment, the set of instructions comprising: One or more instructions, when executed by one or more processors of the device, cause the device to: Configure virtual instances in the computing environment to communicate with the inspection environment; Configure the virtual instance to receive multiple remediation scripts from the inspection environment in the computing environment; Generate a remediation infrastructure that includes multiple remediation actions, each remediation action corresponding to at least one of the multiple remediation scripts; Detect network security issues in the computing environment; Based on the detection of the network security issue, the virtual instance is configured to initiate a remedial action among the multiple remedial actions; as well as In response to initiating the remedial action, feedback is received in the inspection environment from the computing environment in which the virtual instance is deployed.

19. A system for initiating remediation actions in response to cybersecurity issues in a computing environment, comprising: Processing circuitry; A memory containing instructions that, when executed by the processing circuitry, configure the system to: Configure virtual instances in the computing environment to communicate with the inspection environment; Configure the virtual instance to receive multiple remediation scripts from the inspection environment in the computing environment; Generate a remediation infrastructure that includes multiple remediation actions, each remediation action corresponding to at least one of the multiple remediation scripts; Detect network security issues in the computing environment; Based on the detection of the network security issue, the virtual instance is configured to initiate a remedial action among the multiple remedial actions; as well as In response to initiating the remedial action, feedback is received in the inspection environment from the computing environment in which the virtual instance is deployed.

20. The system of claim 19, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: Examine network security objects in the computing environment, wherein the network security objects indicate the network security issue.

21. The system of claim 19, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: Associate the first set of remedial actions among the plurality of remedial actions with the first set of user accounts; as well as The second group of remedial actions is associated with a second group of user accounts, wherein each group of user accounts is authorized to initiate only the remedial action associated with the user account in the corresponding group.

22. The system of claim 21, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: Disable the first of the multiple remedial actions.

23. The system of claim 22, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: Detect the conditions in the computing environment; and The first remedial action is disabled based on the detected conditions.

24. The system of claim 23, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: A second remedy is activated based on the detected conditions.

25. The system of claim 21, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: The first of the multiple remedial actions is disabled only for the first group of user accounts.

26. The system of claim 21, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: The first remedial action is associated with the first group of user accounts, wherein the first group of user accounts is authorized to initiate the first remedial action only for a first pre-authorized resource in the computing environment.

27. The system of claim 26, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: The first remedial action is associated with the second group of user accounts, wherein the second group of user accounts is authorized to initiate the first remedial action on any resource in the computing environment.

28. The system of claim 26, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: The first remedial action is associated with the second group of user accounts, wherein the second group of user accounts is authorized to initiate the first remedial action only for a second pre-authorized resource, which is different from the first pre-authorized resource.

29. The system of claim 19, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: Generate an indicator value for each remedial action, the indicator value indicating the degree of interruption of the determined remedial action; and In response to determining that the degree of interruption of the determined first remedial action is at or above a threshold, permission is granted to the first subject to initiate the first remedial action.

30. The system of claim 19, wherein, The memory contains further instructions that, when executed by the processing circuitry, further configure the system to: In response to feedback indicating that the remedial action was unsuccessful, a second remedial action is initiated.

Citation Information

Patent Citations

  • Customizable courses of action for responding to incidents in information technology environments

    US11182163B1

  • Enterprise level cybersecurity automatic remediation

    US20180159887A1