Method and system for associating events of logs with processes of workloads and medium

By deploying sensors and inspecting network security objects in cloud computing environments, generating rich logs, and correlating runtime processes and events, we can solve the problem of identity abuse in cloud computing environments, improve security and data protection capabilities, and prevent unauthorized access and cybercrime.

CN120729554APending Publication Date: 2025-09-30WIZ INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510626336.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2025-05-15
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

The problem of identity abuse in cloud computing environments includes the risk of unauthorized access to sensitive information or resources, leading to data breaches, financial losses, legal liabilities and breach of trust, facilitating cybercrime and affecting the integrity of online interactions.

Method used

Deploy sensors in cloud computing environments, detect runtime processes on workloads, detect events in logs using identity identifiers, inspect network security objects, generate rich logs, correlate runtime processes with events, and use cloud API calls and infrastructure as code platforms to detect and match identities and processes, which are then stored in a secure database.

Benefits of technology

Effectively identify and respond to identity abuse, reduce the risk of unauthorized access, protect the security of cloud computing environments, prevent data breaches and cybercrime, and maintain the integrity of online interactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729554A_ABST
    Figure CN120729554A_ABST
Patent Text Reader

Abstract

The invention provides a method, a system and a medium for associating events of logs with processes of workloads. The method includes configuring a workload deployed in a cloud computing environment to deploy a sensor on the workload, the sensor configured to detect a runtime process on the workload, the runtime process utilizing an identity; detecting events in a log of the cloud computing environment based on the identifier of the workload, the log comprising a plurality of events; checking a code object of the network security object, the code object being used to deploy a workload in a cloud computing environment; associating the runtime process with the event based on the identifier of the network security object and the workload, where the network security object indicates an identity; and generating a rich log including an identifier of a runtime process associated with the event and the cyber-security object.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates generally to identity management in cloud computing environments, and particularly to protecting computing environments from the misuse of cloud identities. Background Art

[0002] Identity misuse in a computing environment is the unauthorized or inappropriate use of an individual or entity's identity for malicious purposes. This can include various forms of digital identity, including usernames, passwords, biometric data, digital certificates, and other credentials used to authenticate a user or entity within a computer system, network, or online platform. The dangers associated with identity misuse are multifaceted and can have serious consequences for individuals and organizations.

[0003] One of the primary dangers of identity misuse is the risk of unauthorized access to sensitive information or resources. When attackers illegally gain access to an individual or organization's identity credentials, they can leverage this access to penetrate secure systems, databases, or applications. This can lead to data breaches, compromising confidential data such as personal information, financial records, or intellectual property. Unauthorized access to sensitive data not only violates privacy but can also lead to financial losses, legal liability, and reputational damage.

[0004] Furthermore, identity misuse can fuel various forms of cybercrime, including financial fraud, identity theft, and phishing attacks. Attackers can use stolen identities to conduct fraudulent transactions, apply for loans or credit cards, or engage in other illegal activities under false pretenses. This not only poses a direct threat to an individual's financial security but also undermines trust in online transactions and e-commerce.

[0005] Furthermore, identity abuse has broader societal impacts by eroding trust in digital systems and undermining the integrity of online interactions. When personal identities are compromised, this can lead to a loss of confidence in the security measures implemented by organizations and governments to protect personal data. This ultimately hinders the adoption of digital technologies, hindering economic growth and innovation.

[0006] By exploiting vulnerabilities in identity management systems, attackers can gain unauthorized access to sensitive information, commit cybercrime, and undermine the integrity of online interactions. Individuals, organizations, and policymakers must implement robust security measures and adhere to identity protection best practices to mitigate the risks associated with identity misuse.

[0007] Therefore, it would be advantageous to provide a solution that can overcome the above challenges. Summary of the Invention

[0008] The following is an overview of several example embodiments of the present disclosure. This overview is provided to facilitate the reader in providing a basic understanding of these embodiments and does not fully limit the scope of the present disclosure. This overview is not an extensive review of all contemplated embodiments and is neither intended to identify key or important elements of all embodiments nor to delineate the scope of any or all aspects. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to a more detailed description that will be presented later. For convenience, the terms "some embodiments" or "certain embodiments" may be used herein to refer to a single embodiment or multiple embodiments of the present disclosure.

[0009] A system of one or more computers can be configured to perform specific operations or actions by installing software, firmware, hardware, or a combination thereof on the system, which, when executed, causes the system to perform those actions. One or more computer programs can be configured to perform specific operations or actions by including instructions that, when executed by a data processing device, cause the device to perform those actions.

[0010] In one general aspect, a method may include configuring a workload deployed in a cloud computing environment to deploy a sensor on the workload, the sensor configured to detect a runtime process on the workload, the runtime process utilizing an identity. The method may also include detecting an event in a log of the cloud computing environment based on an identifier of the workload, the log comprising a plurality of events. The method may also include inspecting a code object of a network security object, the code object being used to deploy the workload in the cloud computing environment. The method may also include associating a runtime process with the event based on identifiers of the network security object and the workload, wherein the network security object indicates the identity. The method may also include generating an enriched log, the enriched log comprising an identifier of the runtime process associated with the event and the network security object. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0011] Implementations may include one or more of the following features. A method may include configuring a sensor to detect a cloud application programming interface (API) call, the cloud API call including an identifier of an identity. The method may include detecting a disk of a workload; generating an inspectable disk based on the detected disk; inspecting the inspectable disk to detect a cybersecurity object; and, in response to detecting the cybersecurity object on the inspectable disk, storing a representation of the workload, a representation of the identity, and a representation of the event in a secure database. The method may include detecting events of only predetermined event types in a log. The method may include accessing an infrastructure as code (IaC) platform to detect code objects. The cybersecurity object in the method is any of the following: a secret, a certificate, a key, a software application, a software library, a software binary, an operating system, a code object, a hash of an object, a signature, a software artifact, and any combination thereof. The method may include matching static analysis results of data received from the sensor with any of the following: a code object, a disk, and any combination thereof. The method may include matching the data received from the sensor and the static analysis results with events detected in logs of a computing environment. The method may include matching the identity with runtime processes and code objects. Implementations of the described techniques may include hardware, a method or process, or computer-tangible media.

[0012] In one general aspect, a non-transitory computer-readable medium may include one or more instructions that, when executed by one or more processors of a device, cause the device to: configure a workload deployed in a cloud computing environment to deploy a sensor on the workload, the sensor configured to detect a runtime process on the workload, the runtime process utilizing an identity; detect an event in a log of the cloud computing environment based on an identifier of the workload, the log comprising a plurality of events; inspect a code object for a network security object, the code object being used to deploy the workload in the cloud computing environment; associate the runtime process with the event based on identifiers of the network security object and the workload, wherein the network security object indicates the identity; and generate an enriched log comprising the identifier of the runtime process associated with the event and the network security object. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0013] In one general aspect, a system may include processing circuitry. The system may also include memory containing instructions that, when executed by the processing circuitry, configure the system to: configure a workload deployed in a cloud computing environment to deploy a sensor on the workload, the sensor configured to detect a runtime process on the workload, the runtime process utilizing an identity. The system may also detect an event in a log of the cloud computing environment based on an identifier of the workload, the log comprising a plurality of events. The system may also inspect a code object of a network security object used to deploy the workload in the cloud computing environment. The system may also associate a runtime process with the event based on identifiers of the network security object and the workload, wherein the network security object indicates an identity. The system may also generate an enriched log comprising an identifier of the runtime process associated with the event and the network security object. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0014] Implementations may include one or more of the following features. A system wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: configure a sensor to detect a cloud API call, the cloud API call including an identifier of an identity. The system wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: detect disks of a workload; generate an inspectable disk based on the detected disk; inspect the inspectable disk to detect a cybersecurity object; and, in response to the cybersecurity object detected on the inspectable disk, store a representation of the workload, a representation of the identity, and a representation of the event in a secure database. The system wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: detect only events of a predetermined event type in a log. The system wherein the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: access an Infrastructure as Code (IaC) platform to detect the code object. In the system, a cybersecurity object is any one of the following: a secret, a certificate, a key, a software application, a software library, a software binary, an operating system, a code object, a hash of an object, a signature, a software artifact, and any combination thereof. In the system, the memory includes further instructions that, when executed by the processing circuitry, further configure the system to match data received from the sensor with static analysis results of any of the following: code objects, disks, and any combination thereof. In the system, the memory includes further instructions that, when executed by the processing circuitry, further configure the system to match data received from the sensor and static analysis results with events detected in logs of the computing environment. In the system, the memory includes further instructions that, when executed by the processing circuitry, further configure the system to match identities with runtime processes and code objects. Implementations of the described techniques may include hardware, methods or processes, or computer-tangible media. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The subject matter disclosed herein is particularly pointed out and distinctly claimed in the claims at the conclusion of the specification.The foregoing and other objects, features and advantages of the disclosed embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings.

[0016] Figure 1 FIG. 1 is an exemplary diagram of a cloud computing environment in which an inspection environment monitors network security threats according to an embodiment.

[0017] Figure 2 is an example diagram of a sensor backend server communicating with multiple sensors deployed on various workloads according to an embodiment.

[0018] Figure 3is an example flow chart of a method for performing network security threat detection on resources in a cloud computing environment, according to an embodiment.

[0019] Figure 4 is an example flow chart of a method for associating a cloud identity with a workload process.

[0020] Figure 5 is an example flow chart of a method for detecting actions associated with a workload implemented according to an embodiment.

[0021] Figure 6 is an example flow chart of a method for determining an activity baseline for a workload in a computing environment, implemented according to an embodiment.

[0022] Figure 7 is an example flow chart of a method for initiating mitigation actions based on process-related events in a cloud computing environment, according to an embodiment.

[0023] Figure 8 is an exemplary schematic diagram of a check controller according to an embodiment. DETAILED DESCRIPTION

[0024] It is important to note that the embodiments disclosed herein are merely examples of the many advantageous uses of the innovative teachings herein. In general, statements made in the specification of this application do not necessarily limit any of the various claimed embodiments. Furthermore, some statements may apply to some inventive features but not to others. In general, unless otherwise indicated, singular elements may be plural, and vice versa, without loss of generality. In the drawings, like numbers refer to like parts throughout the several views.

[0025] Figure 1 1 is an example diagram of a cloud computing environment for monitoring network security threats by an inspection environment according to an embodiment. In an embodiment, the cloud computing environment 110 is implemented as a virtual private cloud (VPC), a virtual network (VNet), and a virtual private network (VPN) through a cloud computing platform. The cloud computing platform can be provided by, for example, Amazon Web Services (AWS). Web Services, AWS), Google Cloud Platform ( Cloud Platform (GCP) and Microsoft Azure ( Azure) and others.

[0026] In an embodiment, the cloud computing environment 110 includes cloud entities deployed therein. According to an embodiment, the cloud entities are, for example, entities, resources, and combinations thereof. In an embodiment, resources are cloud entities that provide access to computing resources such as processors, memory, and storage devices.

[0027] In some embodiments, the resources are virtual machines, software containers, serverless functions, etc. According to certain embodiments, the resources include software applications deployed thereon, such as web servers, gateways, load balancers, web application firewalls (WAFs), appliances, and various combinations thereof.

[0028] In some embodiments, a principal is a cloud entity authorized to initiate actions in a cloud computing environment. According to some embodiments, cloud entities include, for example, user accounts, service accounts, and roles. In some embodiments, a cloud entity is a principal relative to another cloud entity and is a resource of the other cloud entity. For example, a load balancer is a resource for a user account requesting a web page from a web server behind the load balancer, and the load balancer is a principal of the web server.

[0029] The cloud computing environment 110 includes multiple resources, such as virtual machines 112, software container orchestrators 114, and serverless functions 116. For example, To deploy virtual machine 112. For example, you can use Engine and Engine etc. to deploy the software container orchestrator 114. In an embodiment, the software container orchestrator 114 is configured to deploy a software cluster, each cluster including a plurality of nodes. In an embodiment, a node includes a plurality of pods. For example, the serverless function 116 can be connected to In one embodiment, the serverless function 116 is a serverless function container image.

[0030] In an embodiment, the cloud computing environment 110 includes a data repository 118. According to an embodiment, the data repository 118 includes code objects, software images, software libraries, software binaries, etc. In an embodiment, workloads, resources, etc. are deployed in the cloud computing environment 110 based on the code objects, software images, etc. accessed from the data repository 118.

[0031] In some embodiments, cloud computing environment 110 includes a cloud application programming interface (API). In some embodiments, cloud API 119 is used to access resources of cloud computing environment 110. For example, in some embodiments, resources are configured to generate API calls. In some embodiments, a process deployed on virtual machine 112 initiates an API call, such as to cloud API 119.

[0032] In certain embodiments, the cloud computing environment 110 is configured to utilize an identity and access management (IAM) server 140. In some embodiments, the IAM server 140 is configured to manage identities for the cloud computing environment 110. In embodiments, the IAM server 140 is configured to associate cloud identities (such as user accounts, service accounts, roles, user groups, combinations thereof, etc.) with permissions, authorizations, combinations thereof, etc.

[0033] According to an embodiment, the cloud computing environment 110 is connected to an Infrastructure as Code (IaC) platform 130. In an embodiment, the IaC platform 130 utilizes, for example, In certain embodiments, workloads are deployed in cloud computing environment 110 based on code objects from IaC platform 130 .

[0034] In some embodiments, the code object includes code instructions for assuming a role, invoking a role, initiating an action in a computing environment, combinations thereof, and the like.

[0035] In some embodiments, in the cloud computing environment 110 , workloads, processes and entities deployed on the workloads, etc. generate actions and events. In some embodiments, the cloud logging system 117 is configured to generate log events based on actions, events, and combinations thereof.

[0036] For example, in an embodiment, the serverless function 116 is configured to initiate an action using the cloud API 119. In certain embodiments, the cloud logging system 117 is configured to generate a data record (e.g., a log event) in the cloud log that includes data describing the initiated action. In some embodiments, the data record includes an identifier of the serverless function, an IP address, an identifier of the API call, a combination thereof, and the like.

[0037] According to an embodiment, cloud computing environment 110 includes multiple resources (as discussed in greater detail herein). Each of these resources is susceptible to various cybersecurity threats. For example, such threats may become apparent due to misconfigurations in the software versions of applications in software containers 114, the operating system (OS) versions of virtual machines 112, and the code of serverless functions 116. In an embodiment, cloud computing environment 110 is monitored for cybersecurity threats by inspection environment 120. In an embodiment, the inspection environment is implemented as a cloud computing environment, including a VPC, a VNet, a VPN, and the like.

[0038] In an embodiment, each of the virtual machines 112, software containers 114, and serverless functions 116 includes sensors that are configured to specific resources, resource types, combinations thereof, etc. Figure 2An example deployment of sensors is discussed in more detail in .

[0039] In an embodiment, the sensor ( Figure 1 (not shown) is configured to listen for events and data packets on the data link layer, etc. In some embodiments, the sensor is configured to detect runtime events and running processes, etc. on the resource where the sensor is deployed.

[0040] For example, according to an embodiment, the sensor is configured to utilize an extended Berkeley Packet Filter (eBPF) interface that allows for non-intrusive monitoring of data link layer communications. In certain embodiments, the sensor is further configured to send data to and receive data from a sensor backend server 128. The sensor backend server 128 is a workload deployed in the inspection environment 120, such as a virtual machine, a software container, a serverless function, or a combination thereof.

[0041] In an embodiment, the sensor backend server 128 is configured to receive data generated by sensors. For example, in an embodiment, the sensor backend server 128 is configured to receive events from sensors.

[0042] In some embodiments, the sensor is configured to request rules, definitions, etc. from the sensor backend server 128, and the sensor is configured to apply these rules, definitions, etc. to events (e.g., events detected on the eBPF interface). For example, predetermined events (such as indicating access to IP addresses and IP address ranges, etc.) can be checked according to the definitions.

[0043] According to some embodiments, a definition is a logical expression that, when applied to an event, produces a true or false result. In some embodiments, a rule is a logical expression that includes an action. For example, a rule may state that if a certain definition is true when applied to an event, then data related to the event should be sent to the sensor backend server 128.

[0044] In some embodiments, the sensor backend server 128 is configured to initiate inspections of resources deployed in the cloud computing environment 110. For example, the sensor backend server 128 may be configured to initiate such inspections in response to receiving events, data, combinations thereof, etc. from sensors deployed on the resources.

[0045] In an embodiment, the startup check of the resource is performed by generating instructions for the check controller 122 that, when executed, configure the checker 124 to check the resource.

[0046] For example, the sensor is configured to send event data to the sensor backend server 128 in response to detecting that a definition applied by the sensor to a detected event produces a "true" value when applied. As an example, the definition may be "Is the IP address in the range 127.0.0.1 to 127.0.0.99?" In this example, this corresponds to the range of IP addresses used by malware (such as cryptominers). When the definition is applied to, for example, a detected network packet and the result is "true," the sensor is configured to send data about the event to the sensor backend server 128. The data about the event may be, for example, the IP address, the event type, a combination thereof, and the like.

[0047] In an embodiment, the sensor backend server 128 is configured to receive data. In some embodiments, the sensor backend server 128 is further configured to apply rules to the received data to determine whether the workload on which the sensor is deployed should be inspected for network security threats. For example, the sensor backend server 128 is configured to generate an instruction to inspect the virtual machine 112 in response to an indication received from a sensor deployed as a service on the virtual machine indicating that communication has been detected between the virtual machine 112 and a server having a prohibited IP address (such as an IP address associated with malware).

[0048] For example, the sensor backend server 128 may generate instructions for the inspection controller 122 that, when executed by the inspection controller, generate an inspection-capable disk (e.g., utilizing a snapshot, copy, clone, etc. of a disk (not shown) associated with the virtual machine 112) and provide access to the inspection-capable disk to the inspector 124. In an embodiment, the inspector 124 is configured to detect network security threats. For example, in an embodiment, the inspector 124 is configured to receive a hash of an application stored on the inspection-capable disk and determine whether the hash matches a hash of a known malware application. In some embodiments, a persistent volume claim (PVC) for the inspection-capable disk is provided to the inspector 124.

[0049] In some embodiments, the sensor is configured to generate a hash of the application on the resource where the application is deployed (such as the virtual machine 112) and send the hash to the sensor backend server 128. The received hash can then be compared with known hash values ​​corresponding to malware applications, for example, by providing the received hash to the checker 124.

[0050] While the above examples discuss malware and password miners, it is apparent that the sensors and inspectors 124 can be used to detect other types of network security threats, such as exposures, vulnerabilities, weak passwords, exposed passwords, and misconfigurations.

[0051] In an embodiment, the inspection controller 122 is configured to dispatch an inspector (such as the inspector 124 ), initiate inspections of network security objects, provide the ability to inspect disks, combinations thereof, etc. In some embodiments, the network security objects are secrets, certificates, software applications, software libraries, software binaries, operating systems, code objects, hashes of objects, signatures, combinations thereof, etc.

[0052] In some embodiments, the inspection controller 122 is configured to inspect a workload associated with an identity. For example, in an embodiment, the inspection controller 122 is configured to detect an identity from the IAM server 140 that is associated with a permission.

[0053] In some embodiments, the inspection controller 122 is further configured to detect secrets associated with an identity. In some embodiments, the inspection controller 122 is configured to inspect code objects from the IaC platform 130 and detect API calls, role assumptions, identity identifiers, etc., and associate the code objects with identities based on such detections.

[0054] In some embodiments, the inspection environment 120 also includes a secure database 126. In some embodiments, the secure database 126 is implemented as a graphical database (such as In an embodiment, the secure database 126 is configured to generate a representation of the cloud computing environment 110, such as the cloud computing environment 110. For example, in an embodiment, the representation is based on a predefined unified data schema such that each different cloud platform is represented using the unified data schema, thereby allowing for a unified representation.

[0055] For example, according to an embodiment, a subject is represented by a predefined data structure, and each subject is represented by a node in a security graph. Similarly, according to some embodiments, a resource is represented by another predefined data structure, and each resource is represented by a node in a security graph.

[0056] In some embodiments, data received from sensors deployed on resources in a cloud computing environment can be stored in a graph database as part of a security graph. In the above example, in response to receiving data from a sensor indicating a potential malware infection of virtual machine 112, in an embodiment, sensor backend server 128 is configured to: generate a node representing the malware in security database 126, generate a node representing virtual machine 112 in security database 126, and connect the node representing the malware to the node representing virtual machine 112.

[0057] In some embodiments, the inspection environment includes a policy engine 125. In an embodiment, the policy engine 125 is configured to provide rules, conditions, policies, etc. to the sensors, which are configured to enforce these rules, conditions, policies, etc. on the workload.

[0058] Figure 2 FIG2 is an example diagram of a sensor backend server communicating with multiple sensors deployed on various workloads, according to an embodiment. In some embodiments, the sensor backend server 128 is configured to communicate with a machine (not shown) having sensors installed thereon and communicatively coupled to the sensor backend server 128. In some embodiments, the machine is a computing device such as a bare metal machine, a computer device, a networked computer device, a laptop computer, and a tablet computer.

[0059] In an embodiment, the sensor backend server 128 is implemented as a virtual machine, a software container, a serverless function, a combination thereof, etc. In some embodiments, multiple sensor backend servers 128 are implemented. In some embodiments utilizing multiple sensor backend servers 128, a first group of the multiple sensor backend servers is configured to communicate with sensors deployed on a first type of resource (e.g., a virtual machine), a second group of the sensor backend servers is configured to communicate with a second type of resource, and so on.

[0060] In an embodiment, a first set of sensor backend servers is configured to communicate with sensors deployed on resources in a first cloud computing environment, which is deployed on a first cloud platform (e.g., AWS), and a second set of sensor backend servers is configured to communicate with sensors deployed on resources in a second cloud computing environment, which is deployed on a second cloud platform (e.g., GCP).

[0061] Virtual machine 112 includes sensor 210. In an embodiment, sensor 210 is deployed as a service executing on virtual machine 112. In some embodiments, virtual machine 112 is configured to, for example, request binary code, software packages, etc. from sensor backend server 128, which, when executed by virtual machine 112, causes sensor 210 to run as a service on virtual machine 112. Sensor 210 is configured to, for example, listen for data link layer communications via an eBPF interface.

[0062] The container cluster 114 runs a daemonset and includes multiple nodes such as node 220. The daemonset ensures that each node 220 runs a daemonset pod 222, which is configured as a sensor. For example, The cluster may execute a daemon set configured to deploy a daemon set pod on each deployed node, wherein the daemon set pod is configured to listen to communications of a plurality of pods, such as pod-1 224 through pod-N 226, for example, by listening to data link layer communications via an eBPF interface, where "N" is an integer having a value of "1" or greater. In an embodiment, the daemon set pod 222 is configured to communicate with the sensor backend server 128.

[0063] In an embodiment, the serverless function 116 includes function code 232 and multiple code layers 1 through M (labeled 234 through 236, respectively), where "M" is an integer with a value of "1" or greater. For example, in an embodiment, in AWS Lambda, layers include code, content, combinations thereof, and the like. In some embodiments, layers such as layer 234 include runtime data, configuration data, and software libraries, among others.

[0064] In certain embodiments, the serverless function 116 includes a sensor layer 238. In an embodiment, the sensor layer 238 is configured to listen to the data link layer communications of the serverless function 116, for example, via an eBPF interface.

[0065] According to an embodiment, each of the sensor service 210, the daemon pod 222, and the sensor layer 238 is an implementation of a sensor. In an embodiment, the sensor is configured to communicate with the sensor backend server 128 via a transport layer protocol, such as the Transmission Control Protocol (TCP). For example, in an embodiment, the sensor backend server 128 is configured to listen to a predetermined port using the TCP protocol, and the sensors (such as the sensor 210, the daemon pod 222, and the sensor layer 238) are each configured to communicate with the backend sensor server 128, for example, by initiating communication using TCP on a predetermined port.

[0066] Figure 3 is an example flow chart 300 of a method for performing network security threat detection on resources in a cloud computing environment, implemented according to an embodiment.

[0067] At S310, resources are provided with sensor software. In an embodiment, the resource is any one of a virtual machine, a software container, and a serverless function. In some embodiments, the sensor software is provided based on the resource type. For example, a virtual machine is provided with a software package such as executable code (e.g., binary code). The software container engine is provided with a daemon set, such that in an embodiment where a node is deployed in a cluster of the software container engine, the node includes a daemon set pod 222 configured to provide the functionality of the sensor, such as described above. In an embodiment, the serverless function is provided to the sensor layer by providing code, for example, in a ZIP file.

[0068] In an embodiment, providing the sensor includes configuring resources, such as virtual machines, software containers, and serverless functions, to receive software that, when executed, configures the resource to deploy the sensor thereon.

[0069] At S320, events are detected from data link layer communications. In an embodiment, events at the data link layer are monitored via an eBPF interface. In certain embodiments, a software bill of material (SBOM) is generated. The SBOM may be implemented as a text file based on, for example, events detected via an eBPF interface. In an embodiment, the SBOM includes identifiers of libraries accessed at runtime, identifiers of binaries accessed at runtime, images of instances of which are deployed at runtime, ports accessed by runtime programs, and cryptographic hash function values ​​(such as SHA1 and SHA2 values). For example, the SBOM may include:

[0070] programs{

[0071] exe_name:" / usr / sbin / rpc.mountd"

[0072] last_seen:1663138800

[0073] exe_size:133664

[0074] exe_sha1:"200f06c12975399a4d7a32e171caabfb994f78b9"

[0075] modules{

[0076] path:" / usr / lib / libresolv-2.32.so"

[0077] last_seen:1663138800

[0078] }

[0079] modules{

[0080] path:" / usr / lib / libpthread-2.32.so"

[0081] last_seen:1663138800

[0082] }

[0083] modules{

[0084] path:" / usr / lib / ld-2.32.so"

[0085] last_seen:1663138800

[0086] }

[0087] modules{

[0088] path:" / usr / lib / libc-2.32.so"

[0089] last_seen:1663138800

[0090] }

[0091] modules{

[0092] path:" / usr / lib / libtirpc.so.3.0.0"

[0093] last_seen:1663138800

[0094] }

[0095] modules{

[0096] path:" / usr / lib / libnss_files-2.32.so"

[0097] last_seen:1663138800

[0098] }

[0099] modules{

[0100] path:" / usr / sbin / rpc.mountd"

[0101] last_seen:1663138800

[0102] }

[0103] listening_sockets{

[0104] ip_addr:"0.0.0.0"

[0105] port:60311

[0106] }

[0107] listening_sockets{

[0108] ip_addr:"0.0.0.0"

[0109] port:43639

[0110] }

[0111] This part of the SBOM indicates that a remote procedure call (RPC) was executed.

[0112] It is configured to receive client requests to mount a file system.

[0113] At S330, the event is matched to a definition. In some embodiments, the definition comprises a logical expression that, when applied to the event, produces a "true" or "false" value. For example, a definition may state that "software library xyz is accessed," which, when applied to the event, produces a true or false value. In some embodiments, rules are applied to the event. In an embodiment, a rule is a logical expression that further comprises an action. For example, in an embodiment, a rule states that "if unknown software accesses software library xyz, generate an alert." In this example, when an event is detected in which software with an unknown identifier (e.g., that does not match a pre-approved list of identifiers) attempts to access software library xyz, an alert is generated to indicate that such access was performed.

[0114] At S340, a check is performed to determine whether the data should be transmitted to the inspection environment. In some embodiments, the check is performed by applying rules to the event and determining transmission based on the output of the applied rules. If "yes", execution continues at S350, and if "no", execution continues at S360.

[0115] At S350, data corresponding to the event is transmitted to the inspection environment. In an embodiment, the data is based on the SBOM file. In some embodiments, the data includes event data, such as an identifier of a resource (e.g., a virtual machine, a software container, a serverless function, etc.), an identifier of an application, a hash value, a uniform resource locator (URL) request, a software library identifier, a software binary identifier, and a timestamp.

[0116] At S360 , a check is performed to determine whether resource monitoring should continue. For example, a container's daemon set can be configured to periodically deploy a daemon set pod to monitor pods in a node. As another example, a virtual machine can be configured to periodically deploy a sensor service running as a process on the virtual machine, terminate the process after a predetermined period of time, terminate the process after detecting a predetermined number of events, and so on.

[0117] In some embodiments, the check is performed based on a predetermined amount of elapsed time (e.g., every four hours, every day, twice a day, etc.). If "yes," execution continues at S320. If "no," in some embodiments, execution terminates. In some embodiments, if "no," another check is performed at S360, such as after a predetermined period of time has elapsed.

[0118] Figure 4

[0014] This is an example flow chart of a method for associating a cloud identity with a workload process. In an embodiment, a process is an instance of a computing program, such as executed by at least one thread. According to an embodiment, this is in contrast to a computer program, which is a passive collection of computer instructions.

[0119] In an embodiment, the workload includes multiple computing programs, only a portion of which actually run as processes on the workload. In some embodiments, the process is configured to initiate actions in a computing environment, a cloud computing environment, and the like.

[0120] At S410, a sensor is deployed on a workload. In one embodiment, the sensor is a runtime sensor. In some embodiments, the sensor is deployed as a process on the workload. In some embodiments, the sensor is a runtime process, a task, or a combination thereof.

[0121] In an embodiment, sensors deployed on a workload are configured to detect API calls. For example, in some embodiments, sensors are configured to detect cloud API calls. In an embodiment, sensors are configured to detect the principal utilized by the API call, such as a role.

[0122] At S420, an identity is detected. In embodiments, detecting the identity includes detecting a subject associated with the workload. According to some embodiments, the workload's disk is inspected to detect secrets. In embodiments, the secrets are keys, certificates, tokens, and the like. In some embodiments, the secrets are used to access resources.

[0123] In an embodiment, inspecting the disk includes generating a disk capable of being inspected based on the workload, and detecting a secret on the disk capable of being inspected. In some embodiments, an IAM server is queried to detect an identity associated with the secret. In an embodiment, the secret includes an identifier of, for example, a subject and a resource configured to utilize the secret.

[0124] In some embodiments, the identity is detected by a sensor configured to detect the identity in the API call. In some embodiments, the identity is a managed identity, a service principal, a user account, a service account, a user role, a user group, a combination thereof, or the like.

[0125] At S430, an event is detected. In an embodiment, an event is detected in a log of the computing environment. For example, in some embodiments, entities of the computing environment initiate actions and events, etc., and these are recorded in a log (such as a cloud log, etc.). In some embodiments, the cloud log is, for example, CloudTrail.

[0126] In some embodiments, the inspection controller is configured to detect events in a log of the computing environment. In some embodiments, the inspection controller is configured to detect only predetermined event types. In some embodiments, events are detected based on an identifier, such as an identifier of a subject, an identifier of a process, an IP address, an identifier of the computing environment, or a combination thereof.

[0127] At S440, a code object is detected. In an embodiment, the code object corresponds to code for deploying a workload in a computing environment. According to some embodiments, the code object is part of a code file, such as a Terraform file. In an embodiment, the code object is used to deploy multiple workloads in the computing environment.

[0128] For example, in an embodiment, a code object is a code portion of a declarative code used in an infrastructure as a code platform.In some embodiments, a code object includes multiple lines of code.

[0129] In some embodiments, the code object is detected based on an identifier of the workload, an identifier of the identity, a subject, etc. In some embodiments, the code object is associated with the workload, for example, as a representation in a secure database. In some embodiments, the representation of the code object is connected to the representation of the workload in the secure database.

[0130] At S450, the code object is inspected. In an embodiment, inspecting the code object includes detecting network security objects in the code object. In some embodiments, the network security object is a secret, a certificate, a key, a software application, a software library, a software binary, an operating system, a code object, a hash of an object, a signature, a software artifact, or a combination thereof.

[0131] In an embodiment, a representation of the code object is generated and stored in a secure database. In some embodiments, representations of the subject and API calls, etc. are stored in a secure database and connected to the representation of the code object.

[0132] At S460, the identity is matched to the process. In an embodiment, the process is a process running on the workload and is detected by the sensor as a running process. In some embodiments, the inspection controller is configured to match data received from the sensor (e.g., runtime data) with data received by performing static analysis of code objects and disks in the computing environment, and further match the runtime data and static analysis with events detected in logs of the computing environment.

[0133] For example, in one embodiment, a sensor on a workload detects a process that executes a cloud API call with a machine role to terminate an instance. In one embodiment, the instruction to terminate the instance generates an event in the cloud log. According to one embodiment, the event is matched to the process based on, for example, an identifier of the workload detected in the event log.

[0134] According to certain embodiments, identities matched to processes are stored in a secure database. In some embodiments, enriched logs are generated based on predetermined event types and sensor data, such that events from the cloud log are enriched with the process identifier of the workload based on the sensor data. In some embodiments, the enriched logs are further enriched with static analysis data detected by inspecting the workload's disk.

[0135] Figure 5 is an example flow chart of a method for detecting actions associated with a workload implemented according to an embodiment. In an embodiment, a workload is deployed as a resource comprising a plurality of nested resources.

[0136] For example, according to an embodiment, a software cluster includes multiple nodes, each node includes multiple pods, and each pod has multiple software containers. Each container is a resource, and the pods may share an IP address, a node identifier, etc. Therefore, log data alone is generally insufficient to associate actions in a computing environment with a specific container.

[0137] At S510, a workload is selected. In an embodiment, the workload is a nested workload (such as a container nested in a pod, which is nested in a node). In some embodiments, multiple workloads share a common identifier, such as an IP address, subnet mask, VPN identifier, or a combination thereof.

[0138] In some embodiments, the workload is selected by an inspection controller. In some embodiments, the workload includes a sensor that is deployed on the workload in the sensor's runtime environment. According to some embodiments, the workload includes multiple sensors. In some embodiments, the container is a resource that includes multiple nodes, each of which has a sensor deployed on it.

[0139] At S520, an identity is associated with a process from a workload. In an embodiment, the identity is a managed identity, a user account, a service account, a role, a permission, a user group, a combination thereof, or the like.

[0140] According to an embodiment, an identity is associated with a workload, for example, by inspecting the workload and detecting credentials, secrets, tokens, certificates, keys, cloud keys, combinations thereof, etc. In some embodiments, the credentials, etc. are associated with an identity. In certain embodiments, the identity is associated with the credentials, etc. using an identity and access management server.

[0141] In some embodiments, a workload is associated with multiple identities. For example, in an embodiment, a first identity is associated with a first process running on the workload, and a second identity is associated with a second process running on the workload.

[0142] At S530, an action is detected. In an embodiment, the action is detected in an event log of the computing environment. For example, according to an embodiment, the event log of the cloud computing environment is implemented as CloudTrail.

[0143] In an embodiment, an action corresponds to an event, multiple events, multiple events in a predetermined event sequence, combinations thereof, etc. In some embodiments, an action is detected based on a predetermined event type.

[0144] In certain events, actions are detected in real time, near real time, etc. For example, in some embodiments, only certain actions corresponding to predetermined types of events are monitored in the event log, thereby reducing the number of records that need to be parsed.

[0145] In an embodiment, secondary cloud logs are generated based only on events of a predetermined type (or types) corresponding to actions that should be monitored.

[0146] At S540, output is generated. In one embodiment, the output is a report including actions initiated by the process. In some embodiments, the output is an enriched cloud log. For example, according to one embodiment, the output includes events of a predetermined type. In one embodiment, each event record of the predetermined type is further enriched with an associated identity, a workload identifier, data from static analysis, and the like.

[0147] According to an embodiment, maintaining a rich log is advantageous because it allows searching the rich log for events of particular interest for cybersecurity purposes. For example, certain activities in a cloud computing environment are more likely to indicate a cybersecurity threat, so having a data record that includes only those events, without other data that is considered "noise," is advantageous.

[0148] In some embodiments, it is further advantageous to have a rich log that indicates which actions were performed by which workloads using which identities.

[0149] Figure 6 is an example flow chart of a method for determining an activity baseline for a workload in a computing environment, implemented according to an embodiment.

[0150] At S610, a workload is selected. In an embodiment, the workload is a nested workload (such as a container nested in a pod, which is nested in a node). In some embodiments, multiple workloads share a common identifier, such as an IP address, subnet mask, VPN identifier, or a combination thereof.

[0151] In some embodiments, the inspection controller selects a workload. In some embodiments, the workload includes a sensor deployed on the workload in a runtime environment of the sensor. According to some embodiments, the workload includes multiple sensors. In some embodiments, the container is a resource including multiple nodes, each node having a sensor deployed thereon.

[0152] At S620, an activity baseline is generated. In an embodiment, an activity baseline is generated for the selected workload. In some embodiments, generating the activity baseline includes generating a log and a table, etc., which include an identifier of the action type, the operation type, the communication destination identifier, and the number of such events.

[0153] For example, in an embodiment, the activity baseline of a workload includes a counter of the number of times a process accesses specific other workloads, a counter of the number of times a process accesses an IP range, a counter of the number of times a process initiates an action with a specific workload, a counter of API calls, a counter of specific types of API calls, and combinations thereof, etc.

[0154] In an embodiment, the active baseline includes an eviction policy so that the counter is refreshed periodically, continuously, etc. by removing data points above a threshold. For example, in an embodiment, data points older than 24 hours are deleted.

[0155] In some embodiments, an activity baseline is generated for each workload. In some embodiments, an activity baseline is generated for each process running on the workload. In some embodiments, an activity baseline is generated for all workloads of a particular type (e.g., a common activity baseline for all virtual machines in a cloud computing environment).

[0156] At S630, new activity is detected. In an embodiment, the new activity is detected in a cloud computing environment log. In an embodiment, the new activity is associated with a process and identity on the workload. For example, according to an embodiment, the new activity is associated with a process on the workload that utilizes runtime data received from sensors deployed on the workload, static analysis data from workload inspections, static analysis data of code objects utilized when deploying the workload, or a combination thereof.

[0157] In an embodiment, detecting new activities and associating the new activities with a process that is deployed on a workload at runtime is performed using the methods described in more detail herein.

[0158] At S640, the new activity is determined to be abnormal. In an embodiment, abnormal activity is detected by matching the data field of the abnormal activity with the generated baseline. For example, in an embodiment, a check is performed to determine how often the new activity (e.g., an event indicating the new activity) has previously occurred. In an embodiment, if the check indicates a value below a threshold, the new activity is classified as abnormal.

[0159] In some embodiments, abnormal activity is: a process calling an API with a target account that has not been called before, a process generating an API call from a location in the code where no API call has been executed before, an API call that has never been executed by the workload before, and combinations thereof, etc.

[0160] According to some embodiments, abnormal activity is detected based on rules, conditional rules, policies, and combinations thereof. For example, in some embodiments, a rule is applied to an event in an enriched log to determine whether the event complies with the rule. In some embodiments, if an event in an enriched log does not comply with the rule, a mitigation action is initiated.

[0161] Figure 7 is an example flow chart of a method for initiating mitigation actions based on process-related events in a cloud computing environment, according to an embodiment.

[0162] At S710, an activity is associated with a process. In some embodiments, the activity includes an event, multiple events, predetermined event types, combinations thereof, and the like. In some embodiments, the event is detected in a log of a computing environment, such as a cloud log of a cloud computing environment, a network log, an access log, and various combinations thereof.

[0163] In an embodiment, associating the activity with the process includes deploying a sensor on a workload that deploys a plurality of processes in a runtime environment. According to an embodiment, the runtime processes include a plurality of computer instructions actively processed by the workload, such as by processing circuitry of the workload or processing circuitry assigned to the workload.

[0164] In some embodiments, the sensor is a runtime process, a kernel process, etc. According to some embodiments, the sensor is configured to detect runtime processes, including process identifiers, API calls, and instruction execution requests, etc. In an embodiment, the sensor is deployed in a software container cluster, which further includes an admission controller.

[0165] According to an embodiment, a workload is inspected for network security objects. In an embodiment, network security objects are used to associate workloads with code objects (e.g., in an IaC platform). In an embodiment, an inspection controller is configured to analyze the code objects to detect API calls, workload identifiers, cloud service identifiers, credentials, secrets, network security objects, combinations thereof, and the like.

[0166] In some embodiments, a runtime process is associated with a code object, an identifier of a workload that executes the runtime process, a combination thereof, etc. In an embodiment, the runtime process is also associated with events in a log.

[0167] For example, in some embodiments, the computing environment includes activity logs, cloud logs, network logs, event logs, and various combinations thereof. In certain embodiments, an enriched log is generated based on events detected in the logs, and the events are associated with runtime processes. For example, in an embodiment, the event includes an identifier for a workload. Based on the identifier for the workload, sensor data is used to determine which process running on the workload is associated with the event.

[0168] At S720, the policy is applied to the associated activities. In an embodiment, the policy is applied only to activities associated with the runtime process. According to certain embodiments, the policy is applied by a policy engine. In some embodiments, the policy engine is configured to send the policy, rules, conditional rules, etc. to an admission controller, and the admission controller is configured to apply the policy, rules, conditional rules, etc.

[0169] In some embodiments, the policy engine is configured to apply policies to events of the enriched log. For example, according to an embodiment, the policy is applied by applying conditions to determine whether the event record complies with the policy.

[0170] In an embodiment, a policy is applied based on a plurality of conditions. For example, according to some embodiments, policies and rules, etc. are applied to an event, where the event is of a first type and an anomaly is detected with respect to a value of the event.

[0171] At S730, a mitigation action is initiated. In an embodiment, the mitigation action is initiated in response to the application of a policy. In some embodiments, when the policy is applied to activity and event records, etc., in response to determining that a condition of the policy is not satisfied, the mitigation action is initiated. In certain embodiments, when the policy is applied to activity and event records, etc., in response to determining that a condition of the policy is satisfied, the mitigation action is initiated.

[0172] In some embodiments, mitigation includes blocking network traffic, configuring a firewall to block network traffic to the workload, blocking network traffic from the workload, sandboxing the workload, revoking permissions, configuring an admission controller to enable instructions, combinations thereof, and the like.

[0173] For example, in an embodiment, the mitigation action includes configuring an admission controller of the software container platform to initiate instructions. In an embodiment, the admission controller is configured to perform actions on node-to-node communications, initiate actions in a container cluster, and combinations thereof, among others.

[0174] Figure 8 8 is an example schematic diagram of the inspection controller 122 according to an embodiment. According to an embodiment, the inspection controller 122 includes a processing circuit 810 coupled to a memory 820, a storage device 830, and a network interface 840. In an embodiment, the components of the inspection controller 122 are communicatively connected via a bus 850.

[0175] In some embodiments, the processing circuit 810 is implemented as one or more hardware logic components and circuits. For example, according to embodiments, illustrative types of hardware logic components include field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip systems (SOCs), graphics processing units (GPUs), tensor processing units (TPUs), artificial intelligence (AI) accelerators, general-purpose microprocessors, microcontrollers, and digital signal processors (DSPs), or are configured as any other hardware logic components that perform calculations or other information operations.

[0176] In some embodiments, the memory 820 is a volatile memory (e.g., random access memory), a non-volatile memory (e.g., read-only memory, flash memory), or a combination thereof. In some embodiments, the memory 820 is an on-chip memory, an off-chip memory, or a combination thereof. In some embodiments, the memory 820 is a temporary storage memory for the processing circuit 810.

[0177] In one configuration, software for implementing one or more embodiments disclosed herein is stored in storage device 830, memory 820, combinations thereof, and the like. Software should be broadly interpreted as any type of instructions, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. According to an embodiment, the instructions include code (e.g., in source code format, binary code format, executable code format, or any other suitable code format). According to an embodiment, when executed by processing circuit 810, these instructions cause processing circuit 810 to perform the various processes described herein.

[0178] In some embodiments, the storage device 830 is a magnetic storage device, an optical storage device, a solid-state storage device, a combination thereof, etc. Depending on the embodiment, the storage device 830 is implemented as a flash memory, a hard disk drive, another storage technology, various combinations thereof, or any other medium that can be used to store the required information.

[0179] According to an embodiment, the network interface 840 is configured to provide the inspection controller 122 with communications with, for example, the network 140 .

[0180] It should be understood that the embodiments described herein are not limited to Figure 8 While a particular architecture is shown, other architectures may equally be used without departing from the scope of the disclosed embodiments.

[0181] Furthermore, in some embodiments, the inspector 124, the policy engine 125, the sensor backend 128, the security database 126, and combinations thereof may be configured to: Figure 8 In other embodiments, other architectures may equally be used without departing from the scope of the disclosed embodiments.

[0182] The various embodiments disclosed herein may be implemented as hardware, firmware, software, or any combination thereof. In addition, the software is preferably implemented as an application program tangibly contained on a program storage unit or a computer-readable medium, which is composed of a portion or a combination of certain devices and / or devices. The application program can be uploaded to a machine comprising any suitable architecture, and the application program is executed by the machine. Preferably, the machine is implemented on a computer platform having hardware such as one or more processing units ("PUs"), a memory, and an input / output interface. The computer platform may also include an operating system and microinstruction code. The various processes and functions described herein may be part of the microinstruction code or part of the application program, or any combination thereof, which may be executed by the PU, whether or not such a computer or processor is explicitly shown. In addition, various other peripheral units may be connected to the computer platform, such as additional data storage units and printing units, etc. In addition, a non-transitory computer-readable medium is any computer-readable medium other than a temporary propagation signal.

[0183] All examples and conditional language listed herein are intended for teaching purposes to help the reader understand the principles of the disclosed embodiments and the concepts contributed by the inventors to advance this art, and should be understood as not being limited to these specifically listed examples and conditions. In addition, all statements of the principles, aspects, and embodiments of the disclosed embodiments described herein, as well as their specific examples, are intended to encompass structural and functional equivalents thereof. In addition, such equivalents are intended to include both currently known equivalents and equivalents developed in the future, that is, any element developed to perform the same function, regardless of structure.

[0184] It should be understood that any reference to an element herein using names such as "first," "second," etc. does not generally limit the number or order of those elements. Rather, these names are generally used herein as a convenient way to distinguish between two or more elements or instances of an element. Thus, a reference to a first and a second element does not mean that only two elements can be used there, or that the first element must precede the second element in some way. Furthermore, unless otherwise specified, a group of elements includes one or more elements.

[0185] As used herein, the phrase "at least one" followed by a list of items means that any of the listed items may be used alone or in any combination of two or more of the listed items. For example, if a system is described as including "at least one of A, B, and C," the system may include only A; only B; only C; 2 As; 2 Bs; 2 Cs; 3 As; a combination of A and B; a combination of B and C; a combination of A and C; a combination of A, B, and C; a combination of 2 As and Cs; a combination of A, 3 Bs, and 2 Cs, and so on.

Claims

1. A method for correlating events in a cloud computing log with processes running on a workload, comprising: configuring a workload deployed in a cloud computing environment to deploy a sensor on the workload, the sensor configured to detect a runtime process on the workload, the runtime process utilizing an identity; detecting an event in a log of the cloud computing environment based on an identifier of the workload, the log comprising a plurality of events; inspecting a code object for a network security object, the code object being used to deploy the workload in the cloud computing environment; associating the runtime process with the event based on an identifier of the network security object and the workload, wherein the network security object indicates the identity; as well as An enriched log is generated, the enriched log including an identifier of the runtime process associated with the event and the network security object.

2. The method according to claim 1, further comprising: The sensor is configured to detect a cloud API call, the cloud API call including an identifier of the identity.

3. The method according to claim 1, further comprising: detecting a disk of the workload; Generates the ability to check disks based on detected disks; checking the disk to detect the network security object; as well as Responsive to detecting the network security object on the inspection-capable disk, storing a representation of the workload, a representation of the identity, and a representation of the event in a secure database.

4. The method according to claim 1, further comprising: Only events of predetermined event types are detected in the log.

5. The method according to claim 1, further comprising: An infrastructure as code (IaC) platform is accessed to detect the code object.

6. The method according to claim 1, wherein The network security object is any one of the following: a token, a certificate, a key, a software application, a software library, a software binary, an operating system, a code object, a hash of an object, a signature, a software artifact, and any combination thereof.

7. The method according to claim 1, further comprising: Match the data received from the sensor with static analysis results of any of the following: Code objects, disks, and any combination thereof.

8. The method according to claim 7, further comprising: The data received from the sensor and the static analysis results are matched with events detected in a log of the computing environment.

9. The method according to claim 1, further comprising: The identity is matched to the runtime process and the code object.

10. A non-transitory computer-readable medium storing a set of instructions for associating events in a cloud computing log with processes running on a workload, the set of instructions comprising: One or more instructions that, when executed by one or more processors of a device, cause the device to: configuring a workload deployed in a cloud computing environment to deploy a sensor on the workload, the sensor configured to detect a runtime process on the workload, the runtime process utilizing an identity; detecting an event in a log of the cloud computing environment based on an identifier of the workload, the log comprising a plurality of events; inspecting a code object for a network security object, the code object being used to deploy the workload in the cloud computing environment; associating the runtime process with the event based on an identifier of the network security object and the workload, wherein the network security object indicates the identity; as well as An enriched log is generated, the enriched log including an identifier of the runtime process associated with the event and the network security object.

11. A system for correlating events in a cloud computing log with processes running on a workload, comprising: processing circuits; a memory containing instructions that, when executed by the processing circuit, configure the system to: configuring a workload deployed in a cloud computing environment to deploy a sensor on the workload, the sensor configured to detect a runtime process on the workload, the runtime process utilizing an identity; detecting an event in a log of the cloud computing environment based on an identifier of the workload, the log comprising a plurality of events; inspecting a code object for a network security object, the code object being used to deploy the workload in the cloud computing environment; associating the runtime process with the event based on an identifier of the network security object and the workload, wherein the network security object indicates an identity; and An enriched log is generated, the enriched log including an identifier of the runtime process associated with the event and the network security object.

12. The system according to claim 11, wherein The memory contains further instructions that, when executed by the processing circuit, further configure the system to: The sensor is configured to detect a cloud API call, the cloud API call including an identifier of the identity.

13. The system according to claim 11, wherein: The memory contains further instructions that, when executed by the processing circuit, further configure the system to: detecting a disk of the workload; Generates the ability to check disks based on detected disks; checking the disk to detect the network security object; as well as Responsive to detecting the network security object on the inspection-capable disk, storing a representation of the workload, a representation of the identity, and a representation of the event in a secure database.

14. The system according to claim 11, wherein: The memory contains further instructions that, when executed by the processing circuit, further configure the system to: Only events of predetermined event types are detected in the log.

15. The system according to claim 11, wherein The memory contains further instructions that, when executed by the processing circuit, further configure the system to: An infrastructure as code (IaC) platform is accessed to detect the code object.

16. The system according to claim 11, wherein The network security object is any of the following: Tokens, certificates, keys, software applications, software libraries, software binaries, operating systems, code objects, hashes of objects, signatures, software artifacts, and any combination thereof.

17. The system according to claim 11, wherein: The memory contains further instructions that, when executed by the processing circuit, further configure the system to: Match the data received from the sensor with static analysis results of any of the following: Code objects, disks, and any combination thereof.

18. The system according to claim 17, wherein: The memory contains further instructions that, when executed by the processing circuit, further configure the system to: The data received from the sensor and the static analysis results are matched with events detected in a log of the computing environment.

19. The system according to claim 11, wherein: The memory contains further instructions that, when executed by the processing circuit, further configure the system to: The identity is matched to the runtime process and the code object.

Citation Information

Patent Citations

  • Endpoint detection and response system with endpoint-based artifact storage

    CN110785758A

  • Malware detection verification and enhancement by coordinating endpoint and malware detection systems

    US10462173B1

  • Techniques for detecting cybersecurity events based on multiple sources

    US20230388352A1

  • Cloud resource risk scenario assessment and remediation

    WO2024044053A1