Cloud Access Key Graphs for Detecting Lateral Movement Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for detecting lateral movement in cloud computing environments are complex, costly, and fail to provide comprehensive coverage, especially for serverless applications, and existing methods are inadequate for detecting and preventing attacks that exploit cloud keys.

Innovation Solution

A method and system that utilize a security graph to detect compromised nodes and cloud keys, generating potential lateral movement paths by identifying connections between cloud entities, including cloud keys, to identify and mitigate potential lateral movement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized scanning tools and agents are deployed for cloud workload vulnerability scanning, then detection capability is improved, but device complexity and operational complexity increase significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a simplified copy or representation of cloud workload vulnerability detection by using snapshot-based scanning that captures vulnerability states without requiring complex deployed agents. This allows vulnerability detection through analysis of captured states rather than continuous complex monitoring operations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent extracts the essential vulnerability detection function from complex deployed agents by using snapshot captures that isolate vulnerability states at specific points in time. This extraction allows vulnerability analysis without the ongoing complexity of maintained scanning agents.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If snapshot-based scanning is used to supplement agent-dependent processes, then coverage is improved, but device complexity increases

Engineering Contradiction:
ImprovecoverageVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal snapshot-based scanning approach that can detect vulnerabilities across multiple cloud workload types including containers, serverless applications, and virtual machines. This single snapshot mechanism provides multi-functional coverage without requiring type-specific scanning agents for each workload category.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If cloud keys are monitored for lateral movement detection, then detection precision is improved, but measurement difficulty increases

Engineering Contradiction:
Improvedetection precisionVSAvoidmeasurement difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces cloud keys as intermediary indicators that mediate between complex lateral movement activities and detectable security events. By monitoring cloud key usage and anomalies, the system translates sophisticated attacker behaviors into measurable security signals that indicate potential lateral movement without requiring direct observation of complex attack patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250240305A1System and method for detecting lateral movement using cloud access keys
Publication Date: 2025.07.24 WIZ INC
  • US20250240305A1 patent drawing
  • US20250240305A1 patent drawing
  • US20250240305A1 patent drawing

AI summary

A system and method for detecting potential lateral movement using cloud keys in a cloud computing environment includes determining a first node in a security graph is a compromised node, wherein the security graph represents cloud entities of the cloud computing environment; detecting a cloud key node connected to the first node, wherein the cloud key node represents a cloud key of the cloud computing environment; and generating a potential lateral movement path, including the first node, and a second node, wherein the second node is connected to the cloud key node.