Application endpoint network security techniques

By generating application endpoints and resource representations in a secure database, determining network paths and proactively checking, the problem of application endpoints being susceptible to threats is solved, network security and detection and repair efficiency are improved, and computing resource consumption is reduced.

CN120389873APending Publication Date: 2025-07-29WIZ INC
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202411787925.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-29
Filing Date
2024-12-06
Publication Date
2025-07-29

Smart Images

  • Figure CN120389873A_ABST
    Figure CN120389873A_ABST
Patent Text Reader

Abstract

A system and method for application endpoint verification and protection are presented. The method comprises the following steps: detecting an application endpoint deployed on a resource in a computing environment; generating in a secure data an application endpoint representation and a resource representation, where the secure database includes a computing environment representation; determining a network path between the resource and an external network, the network path including an application endpoint and a reachability parameter; initiating an active check of application endpoints on the network path; and initiating a mitigation action in the computing environment in response to determining that the application endpoint is exposed to the external network by the active check.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to network security, and more particularly to application endpoint security. Background Art

[0002] An application endpoint is a specific Uniform Resource Locator (URL) or Uniform Resource Identifier (URI) in a software application that serves as an entry point for interacting with the application's functionality. These endpoints define various operations or actions that can be performed, typically following the principles of Representational State Transfer (REST) or other web service architectures.

[0003] Each endpoint corresponds to a specific resource or functionality within the application. For example, in a web-based application, endpoints may include actions such as retrieving user information, submitting a form, or accessing a specific data resource. Endpoints are crucial for enabling communication between different components of the application or between the application itself.

[0004] Endpoints are typically associated with HyperText Transfer Protocol (HTTP) methods, such as GET for retrieving data, POST for creating a new resource, PUT or PATCH for updating an existing resource, and DELETE for removing a resource. Developers use these endpoints to build the functionality of the application and expose them to clients such as web browsers or mobile applications through an Application Programming Interface (API).

[0005] Due to potential vulnerabilities that can be exploited by attackers, application endpoints pose network security risks. Poorly secured or misconfigured endpoints may be vulnerable to various threats, such as injection attacks, unauthorized access, or denial of service. Inadequate input validation and authentication mechanisms can lead to data breaches or unauthorized actions.

[0006] Furthermore, if the endpoint exposes sensitive information without proper encryption, it increases the risk of eavesdropping and data interception. Regular security assessments and the robust implementation of authentication, authorization, and encryption mechanisms are essential for mitigating these risks and ensuring the overall network security of the application, yet these utilize a significant amount of computing resources.

[0007] Therefore, it would be advantageous to provide a solution that can overcome the above challenges. Summary of the Invention

[0008] The following is an overview of several example embodiments of the present disclosure. For the convenience of the reader, this overview is provided to give a basic understanding of these embodiments and does not fully define the scope of the present disclosure. This overview is not an extensive review of all contemplated embodiments and is neither intended to identify key or important elements of all embodiments nor to describe the scope of any or all aspects. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to the more detailed description that follows. For convenience, the term "some embodiments" or "certain embodiments" may be used herein to refer to a single embodiment or multiple embodiments of the present disclosure.

[0009] A system of one or more computers can be configured to perform particular operations or actions by installing software, firmware, hardware, or a combination thereof on the system, which, in operation, cause the system to perform these actions. One or more computer programs can be configured to perform particular operations or actions by including instructions that, when executed by a data processing apparatus, cause the apparatus to perform these actions.

[0010] In one general aspect, a method can include detecting an application endpoint on a resource deployed in a computing environment. The method can also include generating in a security database: an application endpoint representation and a resource representation, wherein the security database includes a computing environment representation. The method can also include determining a network path between the resource and an external network, the network path including the application endpoint and a reachability parameter. The method can also include initiating an active check of the application endpoint on the network path. The method can also include initiating a mitigation action in the computing environment in response to determining, via the active check, that the application endpoint is exposed to the external network. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each storage device being configured to perform the actions of the method.

[0011] Implementations can include one or more of the following features. A method can include: applying a policy to a computational environment representation, where the policy includes rules applied to application endpoint representations. A method can include: generating a value in an application endpoint representation based on results of applying the rules to the application endpoint representation. A method can include: further initiating a mitigation action in response to determining that the application endpoint representation violates a rule. A method can include: applying a policy to a portion of the computational environment representation. A method can include: applying a policy to a portion of a representation, where each representation in the portion of the representation includes a label having a predetermined value. A method can include: selecting a policy from a plurality of policies, each policy corresponding to a different severity level. A method can include: checking resources of a network security object in response to determining that an application endpoint representation violates a rule. A method can include: determining that the resources include a network security risk based on detecting the network security object. Implementations of the described techniques can include hardware, methods or processes, or computer tangible media.

[0012] In one general aspect, a non-transitory computer-readable medium can include one or more instructions that, when executed by one or more processors of a device, cause the device to: detect an application endpoint on a resource deployed in a computational environment; generate in a security database: an application endpoint representation and a resource representation, where the security database includes a computational environment representation; determine a network path between the resource and an external network, the network path including the application endpoint and reachability parameters; initiate an active inspection of the application endpoint on the network path; and initiate a mitigation action in the computational environment in response to determining, via the active inspection, that the application endpoint is exposed to the external network. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each storage device being configured to perform the actions of the method.

[0013] In one general aspect, a system can include processing circuitry. The system can also include a memory that contains instructions that, when executed by the processing circuitry, configure the system to: detect an application endpoint on a resource deployed in a computational environment. The system can also include generating in a security database: an application endpoint representation and a resource representation, where the security database includes a computational environment representation. The system can also determine a network path between the resource and an external network, the network path including the application endpoint and reachability parameters. The system can also initiate an active inspection of the application endpoint via the network path. The system can also initiate a mitigation action in the computational environment in response to determining, via the active inspection, that the application endpoint is exposed to the external network. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each storage device being configured to perform the actions of the method.

[0014] Implementations can include one or more of the following features. A system, where the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: apply a policy to a computational environment representation, where the policy includes rules applied to an application endpoint representation. A system, where the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: generate a value in the application endpoint representation based on the result of applying the rules to the application endpoint representation. A system, where the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: initiate a mitigation action in response to determining that the application endpoint representation violates a rule. A system, where the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: apply a policy to a portion of the computational environment representation. A system, where the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: apply a policy to a portion of the representation, where each representation in the portion of the representation includes a tag with a predetermined value. A system, where the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: select a policy from a plurality of policies, each policy corresponding to a different severity level. A system, where the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: check resources of a network security object in response to determining that the application endpoint representation violates a rule. A system, where the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: determine that the resources include a network security risk based on detecting the network security object. Implementations of the described techniques can include hardware, a method or process, or a computer tangible medium. Brief Description of the Drawings

[0016] The subject matter disclosed herein is particularly pointed out and distinctly claimed in the claims of the specification. The foregoing and other objects, features, and advantages of the disclosed embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings.

[0017] Figure 1 is an example diagram of a cloud computing environment monitored by an active checker implemented according to an embodiment.

[0018] Figure 2A is an example of a security graph of a network path to an application endpoint implemented according to an embodiment.

[0019] Figure 2B is an example diagram of a graphical user interface (GUI) for describing an application endpoint representation of an embodiment.

[0020] Figure 3 FIG. 0 is an exemplary flowchart of a method for performing proactive checks in a cloud computing environment implemented according to an embodiment.

[0021] Figure 4A FIG. 1 is an exemplary flowchart of a method for determining reachability attributes of security objects according to the description of an embodiment.

[0022] Figure 4B FIG. 2 is an exemplary flowchart showing the analysis of a network path to determine the reachability performance of objects included in the path according to an embodiment.

[0023] Figure 5 Such as FIG. 3 is a screenshot of a user interface implemented according to an embodiment.

[0024] Figure 6 FIG. 4 is an exemplary flowchart of a method for detecting an application path according to an embodiment.

[0025] Figure 7 FIG. 5 is an exemplary flowchart of a method for network security checks of application endpoints in a computing environment implemented according to an embodiment.

[0026] Figure 8 FIG. 6 is an exemplary schematic diagram of a proactive checker implemented according to an embodiment. DETAILED DESCRIPTION

[0027] It is important to note that the embodiments disclosed herein are merely examples of many useful applications of the innovative teachings herein. In general, the statements made in the specification of this application do not necessarily limit any of the various claimed embodiments. Additionally, some statements may apply to some inventive features but not to others. In general, unless otherwise stated, without loss of generality, a singular element may be plural and vice versa. In the drawings, the same numerals refer to the same parts in several views.

[0028] Figure 1 FIG. 100 is an exemplary diagram of a cloud computing environment monitored by a proactive checker implemented according to an embodiment. According to an embodiment, the first cloud computing environment 110 includes multiple entities and resources. In an embodiment, the resources are public cloud entities (such as functions such as processing power, memory, storage devices, and communication). In an embodiment, the resources are configured to expose multiple functions.

[0029] According to an embodiment, the resources are virtual machines (VMs) (such as VM 113), software container platforms (such as container engine 115), serverless functions (such as serverless function 117), etc. VirtualBox can be used to implement VM 113. Container engine 115 can use or or be implemented. The serverless function 117 can use to implement.

[0030] In an embodiment, the principal is a cloud entity that acts on resources, which means that it can request or otherwise initiate actions, operations, etc. that cause resources to perform functions in the computing environment 110.

[0031] In some embodiments, the principal is, for example, a user account (such as user account 112), a service account (such as service account 114), a role, a user group, a local account, and a network account, etc. In an embodiment, the user account 112 is implemented as a data structure including information about identity, such as a username, a password hash, associated roles, associated user groups, and combinations thereof, etc.

[0032] In certain embodiments, the first cloud computing environment 110 is implemented using cloud computing infrastructure, such as Amazon Web Services (AWS, Web Services), Microsoft Azure ( Azure), and Google Cloud Platform ( Cloud Platform, GCP), etc. In an embodiment, the first cloud computing environment 110 includes a virtual private cloud (VPC), a virtual network (VNet), a virtual private network (VPN), and combinations thereof, etc.

[0033] In an embodiment, the first cloud computing environment 110 is, for example, an organization's production environment. The production environment is, for example, a computing environment that provides services to client devices inside and outside the production environment. The organization may also have a staging environment, which is a computing environment that is substantially the same as the production environment in the deployment of at least some resources (such as workloads and virtual instances, etc.), and this computing environment is used to test new policies, new permissions, new applications, new devices, and new resources, etc. that do not exist in the production environment.

[0034] For an organization, it is usually most important to keep the production environment in a fully operable state. Therefore, using an active scanner to test the accessibility of the first cloud computing environment 110 may not be conducive to achieving this goal, because a large amount of resources need to be invested at least in terms of network bandwidth to perform such a test.

[0035] In an embodiment, the inspection environment 120 is communicatively connected to the first cloud environment 110 and the public network 130. According to an embodiment, the public network 130 is also communicatively connected to the first cloud computing environment 110. In an embodiment, the public network 130 includes a wireless, cellular, or wired network, a local area network (LAN), a wide area network (WAN), a metro area network (MAN), the Internet, the worldwide web (WWW), similar networks, and any combination thereof.

[0036] According to an embodiment, the inspection environment 120 is implemented as a VPC in a cloud computing infrastructure. In an embodiment, the cloud computing infrastructure of the inspection environment 120 is the same cloud computing infrastructure as the first cloud computing environment 110.

[0037] In some embodiments, the inspection environment 120 is implemented as multiple cloud environments, each using a different cloud infrastructure. In an embodiment, the inspection environment 120 includes a security database (DB) 122 for storing a representation of the computing environment 110, an active checker 125, and an inspection controller 127.

[0038] In an embodiment, the representation stored in the security DB 122 includes a representation of the first cloud computing environment 110 using a predefined data schema. In some embodiments, the security DB 122 is implemented as a graph database, such as

[0039] For example, according to an embodiment, each resource and each subject of the first cloud environment 110 are represented as corresponding resource nodes or subject nodes in a security graph. In an embodiment, the various nodes in the security graph are connected, for example, based on policies, roles, permissions, etc. detected in the first cloud computing environment 110.

[0040] In some embodiments, the predefined data schema includes a data structure into which values are input to represent a specific cloud entity. For example, according to an embodiment, a resource is represented by a template data structure including data attributes, and the values of the data attributes uniquely identify the resource, such as address, name, type, and operating system version (OS version), etc.

[0041] In an embodiment, the inspection controller 127 is configured to select resources, etc. from the first cloud computing environment 110 and initiate an inspection of the selected resources. According to an embodiment, initiating the inspection includes providing an inspector (not shown) to inspect resources, copies of resources, clones of resources, snapshots of resources, etc. of network security objects.

[0042] In some embodiments, a network security object, a plurality of network security objects (e.g., a toxic combination), etc. indicate network security threats, network security risks, misconfigurations, exposures, vulnerabilities, and combinations thereof, etc.

[0043] In an embodiment, a network security object is a password, a certificate, a key, a software library, a binary software, a software application, an operating system, a file, a folder, a code object, a hash value, a malware object, and combinations thereof, etc.

[0044] In certain embodiments, the inspection controller 127 is further configured to perform network discovery of the first cloud computing environment 110, such as discovering new resources deployed therein, detecting network paths, detecting network objects, and combinations thereof, etc.

[0045] In an embodiment, the proactive checker 125 is configured to receive a network path to access a resource in the first cloud computing environment 110. In an embodiment, the network path is stored as a data string including one or more reachability parameters. These parameters include a host name, a protocol, an IP address, a port, a user name, and a password, etc. In certain embodiments, the proactive checker 125 is further configured to receive a list of network paths. According to an embodiment, the network path is received periodically.

[0046] In certain embodiments, the proactive checker 125 is further configured to generate an instruction including a query to the security DB 122, and such an instruction (or instructions) when executed by the security database 122 causes an output including one or more network paths to be generated. For example, according to some embodiments, the network paths are generated once every 24 hours, and the proactive inspection occurs once a day, once a week, once a month, etc.

[0047] In some embodiments, for example, as described in more detail below, the proactive checker 125 is configured to access a first resource in the cloud environment, determine or otherwise receive a second network path to at least one second resource, and proactively inspect the second network path to determine whether each at least one second resource can be accessed from the first resource. This is advantageous for determining, for example, the reachability of the second resource, such as a web server (second resource) accessed through a load balancer (first resource). Thus, an attacker may potentially gain access to the first resource through the first network path (i.e., from an external network), and then gain access to the second resource through the second network path (i.e., the internal network path between the first resource and the second resource). Figure 7 As described in more detail below, the proactive checker 125 is configured to access a first resource in the cloud environment, determine or otherwise receive a second network path to at least one second resource, and proactively inspect the second network path to determine whether each at least one second resource can be accessed from the first resource. This is advantageous for determining, for example, the reachability of the second resource, such as a web server (second resource) accessed through a load balancer (first resource). Thus, an attacker may potentially gain access to the first resource through the first network path (i.e., from an external network), and then gain access to the second resource through the second network path (i.e., the internal network path between the first resource and the second resource).

[0048] For example, the first network path may indicate a host name, such as example.com, while the second network path indicates an application path. For example, the first network path may be "example.com:220" and the second network path may be "\webserver\".

[0049] In some embodiments, the second network path may be determined based on an application detected in the security graph. For example, the security graph may be traversed to determine what application nodes (i.e., nodes representing applications) are connected to a resource node (e.g., a node representing a virtual machine). Based on the type of the application node, a second network path corresponding to the application represented by the application node may be generated. For example, it may be predetermined that the MySQL engine listens for commands at "\mysql\input". Thus, if an application node representing the MySQL application is detected by traversing the graph, a first network path may be generated based on the machine hosting the application, and a second network path may be generated based on a predetermined path (e.g., \mysql\input\).

[0050] In an embodiment, the active checker 125 is configured to generate an instruction based on the network path to access a resource associated with the network path. For example, according to an embodiment, the instruction may be to send a data packet to the Internet Protocol (IP) address of the resource and receive an acknowledgement (ACK) response.

[0051] In certain embodiments, the active checker 125 is configured to generate a log that includes, for example, the network path, the instruction sent by the active checker 125, and any response received from the resource. For example, in an embodiment where the active checker 125 is configured to send an HTTP (HyperText Transfer Protocol) request, the response may be a 404 error, a 403 error, a 500 error, a 502 error, etc.

[0052] In an embodiment, the active checker 125 initiates an active check of the network path to determine whether the resource is accessible via the network path from a network external to the first cloud environment 110, such as the public network 130.

[0053] In some embodiments, the inspection controller 127 is configured to detect an application endpoint on the resource. For example, according to an embodiment, the application endpoint is an interface through which the resource can be accessed from a network external to the first cloud computing environment 110.

[0054] In an embodiment, detecting endpoints is performed using static analysis techniques. In some embodiments, the application endpoints are detected by examining resources hosting the technology (e.g., installed software applications), detecting software libraries, binaries, and application paths associated with the hosted technology, and determining that the hosted technology is configured to communicate typically via a predetermined port (e.g., port 80).

[0055] In some embodiments, the resource includes a network address, the representation of the application endpoint is stored in the security database 122, and is further connected to the resource representation on which the application endpoint is detected. In certain embodiments, it is advantageous to use the active checker 125 to perform an active check to determine whether the application endpoint is a verified application endpoint that can be used to access the resource from a network external to the first computing environment 110.

[0056] Figure 2A FIG. 200 is an example of a security graph showing a network path to an application endpoint implemented according to an embodiment. The security graph 200 includes a plurality of nodes, each node being connected to at least one other node by an edge. In certain embodiments, a pair of nodes may be connected by multiple edges. In some embodiments, each edge may indicate the type of connection between the nodes. For example, an edge may indicate "can access" to indicate that a cloud entity represented by the first node can access a cloud entity represented by the second node.

[0057] The first enrichment node 210 (also referred to as the common network node 210) represents a common network (such as the common network 130 described above). Figure 1 An enrichment node (such as the enrichment node 210) is a node generated based on insights determined from data collected from a computing environment (such as the first cloud computing environment 110 described above). For example, an enrichment node may also represent a vulnerability. By connecting a resource node in the graph to an enrichment node representing a vulnerability, the security graph 200 can indicate that the resource contains a vulnerability. This allows for a compact representation because the security graph does not redundantly store multiple data fields for the same vulnerability in each resource node. Figure 1 The common network node 210 is connected to a first resource node 220 (also referred to as the firewall node 220) representing a firewall workload. The firewall represented by the firewall node 220 may be implemented as, for example, a virtual machine in the first cloud computing environment. Connecting the common network node 210 to the firewall node 220 indicates that the firewall is open for transceiver communication between itself and the common network.

[0058]

[0059] ​The firewall node 220 is also connected to a second resource node 230 (also referred to as the API gateway node 230) representing an API (Application Programming Interface) gateway. The API gateway is a workload (such as a serverless function), which can act as a reverse proxy between the client and the resources, accept API calls, direct them to the appropriate services, workloads, and resources, etc., and return the results to the client when appropriate.

[0060] The API gateway node 230 is connected to a first principal node 240 (also referred to as the VM node 240) representing virtual machines hosting applications and databases, and the API gateway node 230 is also connected to a second principal node 250 (also referred to as the container cluster node 250) hosting multiple container nodes.

[0061] In an embodiment, the VM node 240 is connected to an application node 242 and a database node 244. The application node 242 can indicate, for example, a certain application with a version number, binaries, files, and libraries, etc. executed on the VM represented by the VM node 240. In an embodiment, the application node 242 is connected to an application endpoint node 246, indicating that the application includes an application endpoint, which potentially exposes the VM represented by the VM node 240 to the external network.

[0062] In an embodiment, the VM node 240 is connected to multiple application nodes. According to an embodiment, the database node 244 represents a database stored on the VM (represented by the VM node 240) or on a storage device accessible by the VM. The database node 244 can include attributes defining the database, such as type (graph, columnar, and distributed, etc.), version number, query language, and access policy, etc.

[0063] In some embodiments, the container cluster includes multiple container nodes, such as represented by a first container node 252 and a second container node 254. In an embodiment, the second container node 254 includes an application endpoint represented by an application endpoint node 256.

[0064] Figure 2B It is an example diagram of a graphical user interface (GUI) for describing the application endpoint representation of an embodiment. In an embodiment, the application endpoint representation includes multiple performances 260. For example, in some embodiments, the performance 260 is a data field with data values filled through performing static analysis, inspection, proactive inspection, etc.

[0065] In an embodiment, the performances 260 of the application endpoint representation include name, host, port, cloud platform, protocol, and their combinations, etc.

[0066] In some embodiments, the representation includes a severity 270, which indicates the severity level of the network security of an application endpoint to a computing environment. In an embodiment, the severity is stored as a data value, including a quantitative score (e.g., from "1" to "10"), a qualitative score (e.g., "low", "medium", "high", etc.), and combinations thereof, etc.

[0067] In an embodiment, the representation further includes the status of a port, the status of a network protocol message (e.g., HTTP status), an authentication service provider, an authentication method, a status code (e.g., HTTP status code "403"), browser output (e.g., a screenshot), and combinations thereof, etc.

[0068] Figure 3 FIG. 300 is an example flowchart of a method for performing proactive checks of a cloud computing environment implemented according to an embodiment.

[0069] At S310, at least one network path of a first resource in a cloud computing environment is received. A network path, also referred to as object reachability, includes data (e.g., reachability parameters) for accessing the first resource from a public network (such as the Internet), which is not the cloud computing environment of the first resource. In an embodiment, the proactive checker can receive at least one network path from, for example, a security graph. In an embodiment, S320 includes generating an instruction (or instructions) that, when executed by a database system storing the security graph, returns results for one or more resources and the corresponding network paths for each of the one or more resources. In some embodiments, the network paths can be received periodically.

[0070] In some embodiments, the first resource can be one of a plurality of first resources, and each first resource is substantially the same. For example, a set of virtual machines generated based on the same code or image are substantially the same because their initial deployment will be the same except for the unique identifier assigned to each machine. In such an embodiment, in order to reduce the required computing and network resources, it may be beneficial to check at least one network path of a subset of the plurality of first resources. In such an embodiment, this may be acceptable because it is expected that multiple VMs are accessible in similar network paths. In some embodiments, the subset includes one or more first resources.

[0071] In an embodiment, each received network path includes a set of reachability parameters to reach a specific cloud object in the cloud environment. The reachability parameters as well as the network paths are generated by statically analyzing the cloud environment. An example method of such static analysis is described below with reference to Figure 4A and Figure 4B describe an example method of such static analysis.

[0072] At S320, an access instruction for accessing a first resource is generated based on a network path. In an embodiment, the access instruction is generated by an active checker deployed outside the cloud environment where the first resource is located. In some embodiments, the instruction includes one or more access parameters. These parameters may include, but are not limited to, a host name, an IP address, a communication protocol, a port, a user name, and a password, etc., or a combination thereof. The communication protocol may be, for example, HTTP or User Datagram Protocol (UDP). For example, the instruction may be an Internet Packet Explorer (ping), GET, CONNECT, or TRACE request over HTTP.

[0073] In some embodiments, multiple access instructions may be generated. For example, the multiple generated access instructions may include a first access instruction having a first request, and a second access instruction having a second request different from the first request. For example, the first access instruction may include a CONNECT request, and the second access instruction may include a GET request. In some embodiments, multiple first access instructions may be generated. In such an embodiment, each first access instruction may include the same type of request (e.g., CONNECT) having different values (e.g., different web addresses, different ports, etc.). For example, a resource may be accessed at IP address 10.0.0.127 and ports 800 to 805. The IP address and the port may be reachability parameters based on which the active checker may generate multiple first access instructions based on an HTTP GET request, such as:

[0074] GET / bin HTTP / 1.1

[0075] Host: 10.0.0.127:800

[0076] And further generate another HTTP GET request:

[0077] GET / bin HTTP / 1.1

[0078] Host: 10.0.0.127:801

[0079] And so on. These programs, when executed, will attempt to access the / bin folder in the resource with the IP address 10.0.0.127. In some embodiments, the active checker (e.g., Figure 1The active checker 125) can be connected to a proxy server (not shown) via the public network 130, send a first access instruction to a resource in the cloud environment 110 via a first proxy server, and send a second access instruction (which may be the same as or different from the first access instruction) via a second proxy server. In such an embodiment, each proxy server may appear to originate from a different country of origin, so the source will receive access requests from seemingly different sources. This is useful for determining, for example, whether a resource is configured to block certain network traffic based on geographical location.

[0080] In S330, cause the generated access instruction to be executed. When the access instruction is executed, cause an attempt to actually access the resource. In an embodiment, this attempt may result in the generation of network traffic, including requests sent to the resource and responses received (i.e., data packets). While static analysis provides possible paths to access the resource, executing the access instruction provides the real results of attempting to utilize the possible paths to determine which paths are truly viable and which are not. For example, based on static analysis, a path may be viable, but not feasible, for example, an application deployed on the resource prevents such access from occurring. In an embodiment, if the access instruction does not return an error message when executed, the network path is determined to be viable (or accessible). The error message may be, for example, a timeout (e.g., in response to a "ping" request), 403 Forbidden (e.g., in response to an HTTP GET request), etc. In some embodiments, the access instruction may be executed by the active checker 125.

[0081] In S340, based on the execution of the generated access instruction, perform a determination to determine whether the network path is accessible. Performing an active check of the cloud environment allows determination of which reachability paths (i.e., network paths) are truly vulnerable, meaning paths that can be used to obtain access to the cloud environment, and which reachability paths (network paths) are not vulnerabilities due to the active checker being unable to obtain access to the resource, so the reachability paths are practically impossible. Reachability paths confirmed by both static analysis (i.e., analysis using the security graph) and active checking are paths that should be considered more vulnerable. In an embodiment, if the network path results in successful access to the resource, the network path is determined to be accessible (or viable). If the resource cannot be reached via the network path, the network path is determined to be inaccessible (or infeasible).

[0082] At S350, update the security graph based on network path determination. In some embodiments, the active checker may update the security graph that includes a representation of the cloud environment in which the first resource is deployed to indicate whether the reachability path is confirmed by the active check (i.e., viable), where the confirmed path is the path through which the active checker successfully accesses the resource. Further, the security graph may be updated with an alert generated based on determining that the resource has a reachability path through the public network.

[0083] At S360, generate a report based on the execution of the generated instructions. In an embodiment, the report may be generated by the active checker that executes the method. In some embodiments, generating the report may include updating a log with the network traffic between the active checker and the resource. For example, the active checker may record (e.g., write to the log) the generated instructions, the resource identifier, and the response received from the resource. The response may include, for example, a response code. The response code may indicate success, redirection, client error, server error, etc., where the client is the active checker and the server is the resource. In some embodiments, the security graph stored in the security DB 122 may be updated based on the viability of the determined network path. For example, if the resource is successfully accessed, or successfully unaccessed (i.e., an attempt is made to access the resource, but the attempt to access the resource is unsuccessful), then the result may be stored as an attribute of the resource node represented in the security graph. For example, the VM node 240 in FIG. 2 may have an attribute indicating the reachability state, and the attribute may have values corresponding to the following: successfully reached (i.e., the active checker successfully accesses the resource), successfully not reached (i.e., the active checker does not successfully access the resource), and undetermined (the active checker has not yet attempted to access the resource through the network path). In some embodiments, certain network paths (i.e., viable or non-viable) may be determined, while other network paths may be undetermined. A node may be associated with multiple network paths, each network path having its own active check indicator.

[0084] In some embodiments, the active checker may communicate with a virtual private network (VPN) or a proxy to mask the IP address that the active checker attempts to access. This may be useful for testing whether a firewall (such as shown by the firewall node 220 in FIG. 2) will let the communication through based on blocking or allowing certain IP addresses. In such an embodiment, multiple similar instructions may be generated, each instruction originating from a different IP address of the active checker.

[0085] In some embodiments, the network path may include multiple resources. The above method may be executed for each of the multiple resources to determine the reachability of each resource.

[0086] It is advantageous to utilize an active checker that uses network paths generated from a security graph because attempting to access resources in this way to determine the viability (i.e., reachability) of a network path requires fewer resources compared to, for example, randomly guessing a network path to attempt to access resources.

[0087] In some embodiments, the active checker can generate a screenshot of a user interface for accessing a resource via a network path. The following Figure 5 is one such example of a screenshot of a user interface implemented according to an embodiment.

[0088] Furthermore, utilizing the active checker to verify network paths and update the security graph with the results allows detection of workloads that contain both vulnerabilities and verified network paths. This allows alerts to be generated for users of the cloud environment in order to address such issues by accurately describing network security threats. This in turn allows for more efficient utilization of resources as the most vulnerable leaks in the cloud environment will be addressed first.

[0089] Figure 4A FIG. 400 is an example flow chart depicting a method for determining the reachability performance of a security object according to an embodiment. Reachability performance defines whether and how an object on a generated security graph can be reached from an external or internal network and / or an external or internal object. External refers to outside the organization's cloud environment. An object can be any computing or network object specified in the generated security graph as described above.

[0090] At S405, the security graph is accessed or obtained from a graph database. In the security graph, various objects or entities that can be included in an organization's network or cloud environment can be represented as "nodes" or "vertices" that can be interconnected by one or more "links" or "edges" that represent relationships between the various objects included in the network or environment. Each object in the graph can be associated with known performance of that object. Examples of such performance can include the name of the object, IP address, various predefined security rules or access rules, etc.

[0091] At S410, possible network paths within the obtained security graph are identified. A network path is a connection of two or more security objects that can be accessed from an external or internal network and / or an external or internal object. That is, a network path can include an ordered representation of a possible data / control flow between two or more objects in the graph. In an embodiment, where two objects in the graph are represented as vertices and the vertices are connected by an edge, a path can be constructed between the two vertices. The path can be a vertex-only path that describes a sequence of vertex-to-vertex "jumps", an edge-only path that describes only the edges included in the sequence without describing the associated vertices, or an edge-and-vertex path that describes both the edges and vertices included in the sequence.

[0092] According to the disclosed embodiments, a path shows a connection between secure objects and / or computing objects communicating through a network. The objects can be virtual, physical, or logical entities.

[0093] In an embodiment, a path can be identified by traversing a security graph. The traversal can start or end at an object connected to an external network (the Internet). The traversal of the security graph can be performed using solutions disclosed in related art, such as breadth - first search (BFS), tree traversal, etc., and any combination thereof.

[0094] In another embodiment, a path can be identified by querying a graph database storing the security graph. Examples of applicable queries include, but are not limited to, queries configured to identify all paths between a first graph object (node) and a second graph object, queries configured to identify all paths between all graph vertices of a first object type and all graph vertices of a second object type, other similar queries, and any combination thereof.

[0095] As performed in S410 to S430, a list of paths is iteratively identified to determine the reachability performance of the paths. Specifically, in S415, the list of paths is populated to include all identified paths. The list of paths can be a table, a list, or other types of data structures. The list of paths can be unordered or ordered, including sorting according to one or more path performances.

[0096] In S420, a path is selected from the list of paths. At the first run of the method, the first path in the list is selected.

[0097] In S425, the path elements are analyzed to determine the reachability performance. As in S425, the path element analysis is an iterative analysis of each element included in the path selected in S420. Refer to Figure 4B The operations of S425 are discussed in detail.

[0098] In S430, it is determined whether the last path in the list of paths has been analyzed. If so, the execution terminates; otherwise, the execution returns to S420.

[0099] Figure 4B FIG. S425 is an example flowchart according to an embodiment, which shows the analysis of a network path to determine the reachability performance of the objects included in the path.

[0100] At S455, identify the elements within the selected network path. The elements are network and / or computing objects and the relationships (or connections) between these objects. The identification of the elements within the selected path can include, but is not limited to, identification based on the performance and other similar data included in the elements, element identification based on the element identification provided during the execution of S410 above Figure 4A etc., and any combination thereof. In addition, the identification of the elements within the path can include the identification of the element performance or attributes, including but not limited to name, network address, rule set, port configuration, etc., and any combination thereof.

[0101] Then, at S460 to S480, iteratively process the list of paths to determine the reachability performance of the elements. Specifically, at S460, select the next element. The next element is the subsequent element of the set of elements within the selected path identified at S455. In the case where the execution of S460 follows the execution of S480, the next element can be the element that immediately follows the element associated with the previous execution of S470 and S475 in the selected network path. In the case where the execution of the method described Figure 4B includes the first execution of S460, the first execution of S460 can include selecting the first element of the selected path.

[0102] For exemplary purposes, the network path can be a path from a virtual machine (VM), connected to a network interface card (NIC), connected to a load balancer, connected to a firewall. According to the first example, in the case of the first execution of S460, the first execution of S460 can include selecting the VM as the selected element. In addition, according to the second example, in the case where the execution of S460 follows the execution of S480, the selection of the next element at S460 can include selecting the NIC following the VM, or selecting the load balancer following the NIC, or selecting the firewall following the load balancer.

[0103] At S465, determine whether the selected element has been analyzed. Determining whether the selected element can include determining whether one or more reachability performances are included in the relevant graph elements. Since the execution of S475 provides filling the reachability performance into the security graph, elements in the graph that do not include such reachability performance can be considered unanalyzed.

[0104] Where, at S465, it is determined that the selected element has been analyzed, then continue to execute S460. Where, at S465, it is determined that the selected element has not been analyzed, then continue to execute S470.

[0105] At S470, reachability performance is determined. Reachability performance is an object performance that describes whether and how a given path element can be reached via a selected path, specifically, the object performance that can be reached from an external network, an internal network, both, and combinations thereof. Examples of reachability performance include, but are not limited to, binary performance describing whether an element can be reached, the protocol by which an element can be reached, the network address by which an element can be reached, the port by which an element can be reached, access rules, etc., and any combination thereof.

[0106] In an embodiment, the reachability performance is determined as the minimum set of reachability performances of all other objects in the path. As a simple example, if a path includes two objects, where one object can receive traffic from any source IP address via port 1515, and the other object can only receive traffic from the source IP address of 173.54.189.188, then the reachability performance of the second object can be that the second object can be reached via "source IP address 173.54.189.188 and port 1515".

[0107] At S475, the reachability performance is populated into the security graph. As determined at S470, the reachability performance can be populated into the graph through processes including, but not limited to, labeling or annotating graph vertices (or "nodes"), updating network or graph object performance, generating one or more graph overviews, layer or graph adjacent data features, etc., and any combination thereof.

[0108] In an embodiment, for each object, populating the reachability performance into the security graph can include populating the object network access control list (NACL) as described below into the security graph elements corresponding to various path elements, and populating a specific range of NACL and other similar performances into the graph. The specific range of NACL is the NACL that describes the accessibility performance specific to a given range of objects, paths, or networks, where the given range can be the Internet, various given accounts, various given environments, etc. The specific range of NACL can, for example, describe the object performance regarding the Internet accessibility of an object, where the object can be configured to include different access control performances for Internet access and local intranet access.

[0109] In addition, populating the reachability attributes into the graph may include populating one or more paths into the graph, including by similar or identical population processes as those described for the population of individual objects. Populating paths into the graph may include, but is not limited to, populating one or more paths into the graph, including the currently analyzed path, the population of one or more path performances, etc., and any combination thereof. The path performances that may be populated into the graph are performances that describe various attributes of the paths, including but not limited to NACLs applicable to path elements, path segments, or the complete path, and any combination thereof, and the NACL applicable to the complete path includes the complete path aggregation NACL, etc. In addition, populating path performances into the graph may include populating one or more specific ranges of path performances, where such specific ranges of path performances may be performances related to specific ranges, such as those described herein.

[0110] In cases where the population of reachability performances includes labeling or annotating the graph or its elements, one or more graph vertices or edges, the corresponding objects or relationships, or both may be labeled, annotated, or otherwise associated with one or more data features describing the relevant reachability performances. In addition, in cases where the population of reachability performances of the graph includes updating graph objects, graph vertices, and edges, the corresponding objects and relationships, or both, may be directly updated to explicitly include the calculated performances.

[0111] In addition, in cases where the population of reachability performances includes the generation of one or more layers or overlays, the generated layers or overlays may be independent of but corresponding to the data features of the relevant graph, where the generated overlays or layers may include one or more data features describing the reachability performances of various graph elements.

[0112] In S480, it is determined whether all elements in the selected path have been analyzed. Determining whether all elements in the selected path have been analyzed may include, but is not limited to, determining whether the execution of the immediately preceding S475 is related to the last element in the selected path, determining whether additional elements are remaining in the path, determining whether any additional intra-path elements have been analyzed, etc., and any combination thereof.

[0113] Wherein, if it is determined in S480 that not all elements in the selected path have been analyzed, then S460 is continued to be executed. In S480, if it is determined that all elements in the selected path have been analyzed, then the execution terminates.

[0114] Figure 5 is an example of a screenshot 500 generated by an active checker implemented according to an embodiment. A screenshot is an image showing the content displayed on a computer. In an embodiment, the active checker (such as Figure 1The active checker 125) may include a web browser application for executing access instructions. The web browser application may generate a user interface for display. The screenshot 500 includes a portion of such a user interface, which includes a response header 510 received based on a request to access a resource. In this case, the response header 510 includes an HTTP code 403 (i.e., Forbidden), meaning the request to access the resource is denied. The detailed code 512 includes a message associated with the 403 code (i.e., "Access Denied"), message 514, request identifier 516, and host identifier 518.

[0115] Figure 6 FIG. 600 is an example flowchart of a method for detecting an application path according to an embodiment. An application path is a path that an attacker can use when obtaining access to a cloud computing environment, which includes a first resource through which the attacker obtains access to the cloud computing environment, and a subsequent second resource that the attacker can access in the cloud computing environment after obtaining access to the first resource, where the first resource corresponds to a virtual machine, a container, etc., and the second resource corresponds to an application executed (or deployed) on the first resource. In an embodiment, detecting an application path includes detecting a vulnerability that allows reaching the first resource, obtaining access to it, and obtaining access to the second resource through the first resource, where the second resource can be accessed by the first resource but should not be accessed, such as a user account or service account that accesses the first resource.

[0116] In S610, a reachable first resource is selected. In an embodiment, the reachable first resource may be selected from a list of reachable resources. The list may be stored as a table in a database, for example. The list may include an identifier of each reachable resource and at least one feasible network path. A reachable resource is a resource that can be reached from an external network, as the external network is outside the cloud computing environment in which the resource is deployed. In an embodiment, the reachable resources include network paths, reachability parameters, etc., as discussed in more detail above. A reachable resource is a resource that includes at least a feasible network path and has reachability parameters that allow access to the resource from an external network, and the resource is deployed in a cloud computing environment. In an embodiment, a security graph may be queried to generate a result that includes at least reachable resources. In some embodiments, the generated result includes multiple reachable resources, each with its own at least one feasible network path. In other embodiments, the result includes multiple network paths of a reachable resource (i.e., the resource can be reached from multiple network paths).

[0117] At S620, a first resource is accessed. In an embodiment, accessing the first resource includes providing credentials that permit access to the first resource to the first resource. For example, a private key may permit access to a secure shell protocol (SSH) server. As another example, access to an API gateway (such as Figure 2A the API gateway 230) may be provided by providing credentials. As yet another example, a load balancer (the first resource) may provide access to a server (the second resource) that listens on an application address. For example, an SSH server may be exposed behind a load balancer and listen on a local application address (e.g., 10.0.0.115). By accessing the load balancer that includes an external network path and accessing the application address from there, an attacker may gain access to the SSH server.

[0118] At S630, a second resource is selected. In an embodiment, the second resource is an application exposed via the first resource. In an embodiment, a security graph is queried to determine the second resource. In some embodiments, the cloud computing environment in which the first resource is deployed is represented in the security graph, such as, for example, as detailed above in Figure 2A In some embodiments, querying the security graph includes causing a query to be executed on a database hosting the security graph and receiving, as a result, an identifier representing a second resource node that is connected to a node representing the first resource.

[0119] For example, the security graph may be traversed to detect a node representing an application (application node) that is connected to a node representing the first resource. A second network path from the first resource node to the application node may be determined. For example, the first resource may be accessed by accessing "example.com:80", while the second resource (i.e., the application node) may be accessed using an application address or other listening address. In an embodiment, the application may be preconfigured to listen on an address and port, etc. The second network path may be generated based on the preconfigured listening.

[0120] As another example, the application node may indicate that a web server application (the second resource) is deployed on a virtual machine (the first resource). An access attempt may include generating an access instruction on the first resource (the first network path) using port 80 (the second network path), which is a preconfigured port for Internet web traffic.

[0121] At S640, a second resource is actively determined to be reachable via a first resource. In an embodiment, if the first resource is available for accessing the second resource, then the second resource is reachable from the first resource. In the above example, if a web server is reachable via a virtual machine, then the web server is also reachable. Thus, if the first resource is a reachable resource, which means a viable network path has been found and the second resource can be accessed from the first resource, an attacker who obtains access to the first resource can also obtain access to the second resource. Therefore, although the second resource may not have a directly viable network path, it can still become reachable by accessing the first resource, which means there is a second network path, i.e., the network path between the first resource and the second resource. In an embodiment, a resource is accessible if, for example, an instruction can be sent to the resource and then executed by the resource. For example, if a network path to a virtual machine hosting a SQL (Structured Query Language) database application is determined and the second network path allows access to the SQL database (i.e., the application path), then the SQL database can be determined to be reachable and further instructions for performing a SQL injection can be generated for execution by the SQL database application.

[0122] At optional S650, the security graph is updated based on the determination. In some embodiments, a node can include an indicator indicating whether a resource is reachable. In other embodiments, an edge can be added between a node representing the first resource and a node representing the second resource to indicate that the second resource is reachable from the first resource. Proactively checking the second resource in this way allows detection of certain vulnerabilities in a cloud computing environment, which is of course desirable.

[0123] At S660, a check is performed to determine whether the reachability of another second resource from the first resource should be checked. In an embodiment, if another resource should be checked to determine reachability, the execution continues at S640; otherwise, the execution terminates. For example, if another application is determined to be deployed on the first resource, e.g., by traversing the security graph and detecting another application node connected to the first resource node, then a second application path can be determined and its reachability can be determined by executing the method detailed herein.

[0124] Figure 7 is an example flowchart of a method for network security checking of application endpoints in a computing environment implemented according to an embodiment. In an embodiment, application endpoints of resources deployed in a computing environment, such as a cloud computing environment, are detected. According to some embodiments, it is advantageous to continuously, periodically, etc. verify the accessibility via the application endpoints, e.g., using an active checker configured to perform such a method.

[0125] At S710, the computing environment is inspected. In an embodiment, network security objects of the computing environment are inspected, such objects indicating, for example, network security threats, network security risks, misconfigurations, vulnerabilities, exposures, and combinations thereof.

[0126] In an embodiment, the computing environment is inspected to detect network paths. For example, in some embodiments, an inspector is configured to perform network discovery of the network of the computing environment to detect network objects. In certain embodiments, resources of the computing environment are inspected, for example, using static analysis techniques, to detect software applications, software libraries, binaries, etc.

[0127] In an embodiment, inspecting the computing environment includes configuring resources of the computing environment to install sensors thereon. In an embodiment, the sensors are configured to detect runtime data, runtime process identifiers, software artifacts, and combinations thereof.

[0128] At S720, application endpoints are detected. In an embodiment, application endpoints are detected on resources using inspection techniques discussed in more detail herein. In certain embodiments, inspecting the computing environment includes detecting multiple application endpoints for a single resource. For example, in an embodiment, a resource has multiple application endpoints, including a first application endpoint having a first network address using a first port, and a second application endpoint having the first network address using a second port.

[0129] In an embodiment, application endpoints are detected based on the applications detected on the resources (e.g., by static analysis). For example, in an embodiment, PostgreSQL is detected on a virtual machine having an address of 195.24.12.2 in a cloud computing environment TM software application. In an embodiment, Postgre is configured to use port 5432, and thus an application endpoint is detected at 195.24.12.2:5432.

[0130] At S730, the representation is stored in a security database. In an embodiment, the security database includes a representation of the computing environment. In some embodiments, the security database includes a representation of the resources on which application endpoints are detected.

[0131] In some embodiments, the endpoint representation includes an identifier, hostname, port number, computing environment identifier, computing environment type, external IP address, internal IP address, status indicator, protocol identifier, browser result, browser screenshot, authentication method, severity indicator, and combinations thereof.

[0132] In some embodiments, the representation of an endpoint is connected by a vertex to the resource representation on which the endpoint is detected. In some embodiments, the resource representation is connected to multiple representations, each representing a unique endpoint detected on the resource.

[0133] At S740, an active check is initiated. In an embodiment, the active check is initiated for an application endpoint. In some embodiments, the active check is initiated periodically for the application endpoint, e.g., daily for a number of days, hourly for a number of hours, etc.

[0134] In some embodiments, the active check includes initiating an instruction connected to the application endpoint, e.g., via a port, a suspicious port, etc. According to an embodiment, a Transmission Control Protocol (TCP) three-way handshake is initiated from an external network to a resource using the application endpoint, and the result is recorded, stored, etc.

[0135] In an embodiment, the TCP three-way handshake includes a Synchronize (SYN) message (used by the active checker to initiate the connection), a Synchronize-Acknowledgement (SYN-ACK) message (used by the resource to acknowledge and synchronize the connection), and an ACK message (used by the resource or the active checker to acknowledge the receipt of the SYN message).

[0136] In some embodiments, a status, a status indicator, etc. are established for the application endpoint based on the response received from the resource. For example, in an embodiment, the status is related to a port, such as open (the port on the resource is open), closed (all ports are closed), checker disabled (active check of the resource is not allowed), excluded (the resource is excluded from the check), unsupported port (the checker does not support the port), check failed, and combinations thereof, etc.

[0137] In an embodiment, the active checker is further configured to initiate a network protocol check on an open port. For example, in some embodiments, the network protocol is HTTP, and the active checker is configured to send an HTTP GET request to the resource. In an embodiment, the response to the GET request in the application endpoint representation is stored, recorded, etc. Examples in this regard are discussed in more detail above in Figure 5 There is a more detailed discussion.

[0138] In an embodiment, a protocol is used on a port based on the port number. In some embodiments, the protocol is, for example, HTTP, HTTPS (Hypertext Transfer Protocol Secure), FTP (File Transfer Protocol), SSH, SMTP (Simple Mail Transfer Protocol), SMB (Server Message Block), IPSec (Internet Protocol Security), SFTP (Secure FTP), MSSQL, Grafana, MySQL, RDP (Remote Desktop Protocol), UPnP (Universal Plug and Play), PostgreSQL, Redis (Remote Dictionary Server), Kubernetes API, Cassandra, SSL (Secure Sockets Layer), Elasticsearch, etc.

[0139] In some embodiments, in the case where an application is detected by active inspection, a representation is generated to indicate that the application (e.g., hosting technology) has been verified at runtime.

[0140] At S750, a mitigation action is initiated. In an embodiment, the mitigation action is initiated based on the result of the active inspection. In some embodiments, the result of the active inspection matches policies, rules, and conditional rules, etc. This is advantageous because it provides a mechanism that initiates mitigation actions based on predetermined objective criteria applied in a consistent manner.

[0141] For example, in an embodiment, the policy includes a rule stating that no resource should have an open port. In such an embodiment, in the case where an open port is detected by active inspection (and further verified in some embodiments), the mitigation action further includes generating a remediation action and an alert, etc.

[0142] In some embodiments, multiple policies are implemented on a computing environment by applying the policies to a representation of the computing environment stored in a security database. In an embodiment, the security database is configured with multiple predetermined policies, for example, each policy having a different leniency level, and is also configured to accept an input indicating which policy is to be applied to the computing environment.

[0143] In some embodiments, the policy further includes exceptions, which include resource identifiers, resource types, group types, etc. for which the policy should not be applied.

[0144] In an embodiment, a remediation action is initiated. In some embodiments, the remediation action includes generating an alert, the severity of the generated alert, updating the severity of the alert, generating a ticket in a support ticket system, updating the severity of the generated ticket, sandboxing a resource, revoking access from a resource, revoking access to a resource, configuring a resource to open a port, configuring a resource to close a port, configuring a resource to temporarily close a port, and combinations thereof.

[0145] Figure 8 FIG. 7 is an exemplary schematic diagram of the proactive checker 125 according to an embodiment. According to an embodiment, the proactive checker 125 includes a processing circuit 810, which is coupled to a memory 820, a storage device 830, and a network interface 840. In an embodiment, the components of the proactive checker 125 are communicatively connected via a bus 850.

[0146] In certain embodiments, the processing circuit 810 is implemented as one or more hardware logic components and circuits. For example, according to an embodiment, illustrative types of hardware logic components include field programmable gate array (FPGA), application-specific integrated circuit (ASIC), application-specific standard product (ASSP), system-on-a-chip system (SOCs), graphics processing unit (GPU), tensor processing unit (TPU), artificial intelligence (AI) accelerator, general microprocessor, microcontroller, digital signal processor (DSP), etc., or any other hardware logic component configured to perform arithmetic or other information manipulation.

[0147] In an embodiment, the memory 820 is a volatile memory (e.g., random access memory, etc.), a non-volatile memory (e.g., read-only memory, flash memory, etc.), and combinations thereof. In some embodiments, the memory 820 is an on-chip memory, an off-chip memory, and combinations thereof. In certain embodiments, the memory 820 is a scratchpad memory for the processing circuit 810.

[0148] In one configuration, the software for implementing one or more embodiments disclosed herein is stored in the storage device 830, the memory 820, and combinations thereof. Software should be construed broadly as any type of instruction, whether it is called software, firmware, middleware, microcode, hardware description language, or otherwise. According to an embodiment, the instructions include code (e.g., source code format, binary code format, executable code format, or any other suitable code format). According to an embodiment, when executed by the processing circuit 810, these instructions cause the processing circuit 810 to perform the various processes described herein.

[0149] In some embodiments, the storage device 830 is a magnetic storage device, an optical storage device, a solid-state storage device, and combinations thereof. According to an embodiment, the storage device 830 is implemented as a flash memory, a hard disk drive, another storage technology, various combinations thereof, or any other medium that can be used to store the required information.

[0150] According to an embodiment, the network interface 840 is configured to provide communication with, for example, the computing environment 110, the public network 130, the inspection controller 127, and the security database 122 to the active checker 125.

[0151] It should be understood that the embodiments described herein are not limited to Figure 8 the specific architecture shown. Other architectures can be equally used without departing from the scope of the disclosed embodiments.

[0152] In addition, in certain embodiments, the inspection controller 127, the security database 122, and combinations thereof can be implemented using Figure 8 the architecture shown. In other embodiments, other architectures can be equally used without departing from the scope of the disclosed embodiments.

[0153] The various embodiments disclosed herein may be implemented as hardware, firmware, software, or any combination thereof. Additionally, the software is preferably implemented as an application tangibly embodied on a program storage unit or a computer-readable medium, which consists of a part or certain devices and / or combinations of devices. The application can be uploaded to and executed by a machine including any suitable architecture. Preferably, the machine is implemented on a computer platform having hardware such as one or more processing units ("PU", "processing unit"), a memory, and an input / output interface. The computer platform may also include an operating system and microinstruction code. The various processes and functions described herein may be part of the microinstruction code, part of the application, or any combination thereof, which may be executed by the PU, whether or not such a computer or processor is explicitly shown. Additionally, various other peripheral units may be connected to the computer platform, such as additional data storage units and printing units. Furthermore, a non-transitory computer-readable medium is any computer-readable medium other than a transitory propagated signal.

[0154] All of the examples and conditional language recited herein are intended for pedagogical purposes to aid the reader in understanding the principles of the disclosed embodiments and the concepts contributed by the inventor to further the art, and are to be construed as not being limited to such specifically recited examples and conditions. Additionally, all statements herein reciting principles, aspects, and embodiments of the disclosed embodiments, as well as specific examples thereof, are intended to cover their structural and functional equivalents. Furthermore, such equivalents include both currently known equivalents and equivalents developed in the future, i.e., any elements developed that perform the same function regardless of structure.

[0155] It should be understood that any reference to elements using names such as "first", "second", etc. generally does not limit the number or order of these elements. Instead, these names are generally used herein as a convenient method of distinguishing between two or more elements or instances of elements. Thus, the reference to a first element and a second element does not mean that only two elements may be used there, or that the first element must somehow precede the second element. Additionally, unless otherwise stated, a set of elements includes one or more elements.

[0156] As used herein, the phrase "at least one" followed by a list of items means that any of the listed items can be used alone, or any combination of two or more of the listed items can be used. For example, if a system is described as including "at least one of A, B, and C", the system can include only A; only B; only C; 2 of A; 2 of B; 2 of C; 3 of A; a combination of A and B; a combination of B and C; a combination of A and C; a combination of A, B, and C; a combination of 2 of A and C; a combination of A, 3 of B, and 2 of C; and so on.

Claims

1. A method for application endpoint verification and protection, comprising: Detecting application endpoints on resources deployed in a computing environment; Generating in a security database: an application endpoint representation and a resource representation, wherein the security database includes a computing environment representation; Determining the existence of at least one existing network path between the resource and an external network, the network path including the application endpoint and reachability parameters; Initiating an active check of the application endpoint on the network path; and In response to determining through the active check that the application endpoint is exposed to the external network, initiating a mitigation action in the computing environment.

2. The method according to claim 1, further comprising: Applying a policy to the computing environment representation, wherein the policy includes rules applied to the application endpoint representation.

3. The method according to claim 2, further comprising: Generating values in the application endpoint representation based on the result of applying the rules to the application endpoint representation.

4. The method according to claim 2, further comprising: In response to determining that the application endpoint representation violates the rules, further initiating the mitigation action.

5. The method according to claim 2, further comprising: Applying the policy to a portion of the computing environment representation.

6. The method according to claim 5, further comprising: Applying the policy to a portion of the representation, wherein each representation in the portion of the representation includes a tag with a predetermined value.

7. The method according to claim 2, further comprising: Selecting the policy from a plurality of policies, each policy corresponding to a different severity level.

8. The method according to claim 2, further comprising: In response to determining that the application endpoint representation violates the rules, checking the resource of the network security object.

9. The method according to claim 8, further comprising: Based on detecting the network security object, determining that the resource includes a network security risk.

10. A non-transitory computer-readable medium storing an instruction set for application endpoint verification and protection, the instruction set comprising: One or more instructions that, when executed by one or more processors of a device, cause the device to: Detect application endpoints on resources deployed in a computing environment; Generate in a security database: An application endpoint representation and a resource representation, wherein the security database includes a computing environment representation; Determine the existence of at least one existing network path between the resource and an external network, the network path including the application endpoint and reachability parameters; Initiate an active check of the application endpoint on the network path; and In response to determining through the active check that the application endpoint is exposed to the external network, initiate a mitigation action in the computing environment.

11. A system for application endpoint verification and protection, comprising: Processing circuitry; A memory that contains instructions which, when executed by the processing circuit, configure the system to: Detect application endpoints on resources that have been deployed in a computing environment; Generate in a security database: An application endpoint representation and a resource representation, where the security database includes a computing environment representation; Determine the existence of at least one existing network path between the resource and an external network, the network path including the application endpoint and reachability parameters; Initiate an active check of the application endpoint on the network path; and In response to determining through the active check that the application endpoint is exposed to the external network, initiate a mitigation action in the computing environment.

12. The system according to claim 11, wherein, The memory contains further instructions which, when executed by the processing circuit, further configure the system to: Apply a policy to the computing environment representation, where the policy includes rules applied to the application endpoint representation.

13. The system according to claim 12, wherein The memory contains further instructions which, when executed by the processing circuit, further configure the system to: Generate values in the application endpoint representation based on the result of applying the rules to the application endpoint representation.

14. The system according to claim 12, wherein, The memory contains further instructions which, when executed by the processing circuit, further configure the system to: In response to determining that the application endpoint representation violates the rules, further initiate the mitigation action.

15. The system according to claim 12, wherein The memory contains further instructions which, when executed by the processing circuit, further configure the system to: Apply the policy to a portion of the computing environment representation.

16. The system according to claim 15, wherein, The memory contains further instructions which, when executed by the processing circuit, further configure the system to: Apply the policy to a portion of the representation, where each representation in the portion of the representation includes a tag with a predetermined value.

17. The system according to claim 12, wherein, The memory contains further instructions which, when executed by the processing circuit, further configure the system to: Select the policy from a plurality of policies, each policy corresponding to a different severity level.

18. The system according to claim 12, wherein The memory contains further instructions which, when executed by the processing circuit, further configure the system to: In response to determining that the application endpoint representation violates the rules, check the resource for network security objects.

19. The system according to claim 18, wherein, The memory contains further instructions which, when executed by the processing circuit, further configure the system to: Based on detecting the network security objects, determine that the resource includes a network security risk.

Citation Information

Patent Citations

  • Security early warning method and device based on protocol identification in scheduling data network

    CN110430191A

  • Application vulnerability detection method and device, electronic equipment and storage medium

    CN115828259A

  • Static analysis techniques for determining reachability properties of network and computing objects

    US11374982B1

  • Automated container security

    US20180027009A1

  • Contextual security behavior management and change execution

    US20200021620A1