Cloud Security Graph Reachability for Sensitive Data Exposure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing solutions struggle to efficiently detect and secure sensitive data vulnerabilities in cloud environments, often leading to data leaks and inefficient use of network resources due to random searches and subjective human assessments.

Innovation Solution

A system and method using a security graph to represent the cloud environment, detecting sensitive data and determining reachability paths to secure it, thereby reducing network bandwidth usage and providing consistent, objective vulnerability assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external attack surface management solutions randomly guess ports, domains, and IP addresses to access secure networks, then they may locate sensitive data or compromised machines, but they drain processing resources and are intensive in network bandwidth usage

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork bandwidth usage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by constructing a graph representation of the cloud environment and pre-identifying cloud entities and their relationships before conducting vulnerability detection. This allows the system to focus detection efforts on specific targets rather than randomly probing the entire network, thereby reducing unnecessary network bandwidth consumption while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary approach by using a graph database and reachability analysis as a mediator between the detection system and the target cloud environment. Instead of directly probing network ports and IPs, the system queries the graph database to identify reachable cloud entities, significantly reducing network bandwidth usage while maintaining reliable detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If external attack surface management solutions randomly guess ports, domains, and IP addresses to access secure networks, then they may locate sensitive data or compromised machines, but they drain processing resources

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary construction of the cloud environment graph and pre-identification of cloud entities, relationships, and attributes before detection. This preliminary structuring enables efficient querying and reduces the need for resource-intensive random probing, thereby maintaining detection accuracy while reducing processing resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a graph-based copy or representation of the cloud environment structure, storing cloud entities and their relationships in a graph database. This copied representation allows the system to analyze and detect vulnerabilities by querying the graph model rather than directly probing the actual cloud environment, significantly reducing processing resource usage while maintaining detection effectiveness.

Inventive Principle:
Principle #26Copying

3Loss of information

If solutions identify sensitive data structures and mapping where such structures are stored, then they can detect databases, but they do not provide information on whether data is actually stored in such data structures or if sensitive data is externally exposed

Engineering Contradiction:
Improvedata structure identificationVSAvoidvulnerability detection accuracy
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-constructing the graph representation with cloud entities, their relationships, and attributes including data storage information. This preliminary structuring enables the system to not only identify data structures but also determine reachability and external exposure by querying the pre-built graph model, thereby providing complete vulnerability assessment information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the graph database as an intermediary that stores and connects information about cloud entities, data structures, and their relationships. This intermediary graph model enables the system to query not only where data is stored but also whether it is externally accessible, bridging the gap between data structure identification and vulnerability assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If random guessing approaches are used to access secure networks, then some vulnerabilities may be located, but many vulnerabilities in the secure network may be overlooked

Engineering Contradiction:
Improvepartial detection successVSAvoidvulnerability coverage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary construction of the cloud environment graph that includes all cloud entities, their relationships, and accessibility information. This comprehensive pre-mapping ensures that no vulnerabilities are overlooked, as the graph representation captures the entire attack surface and reachability paths, enabling complete vulnerability coverage rather than random sampling.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal graph representation that can represent any cloud entity and its relationships, making the detection system applicable to the entire cloud environment rather than relying on random probing. This universal model ensures comprehensive vulnerability coverage across all cloud entities while maintaining consistent detection methodology.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12495058B1System and method for detecting vulnerability of data in a cloud computing environment
Publication Date: 2025.12.09 WIZ INC
  • US12495058B1 patent drawing
  • US12495058B1 patent drawing
  • US12495058B1 patent drawing

AI summary

A system and method for detecting sensitive data vulnerability in a cloud computing environment detects sensitive data in the cloud computing environment, and determines reachability parameters of a workload having access to the sensitive data. The method includes detecting sensitive data associated with a cloud entity in a cloud computing environment, the cloud computing environment is being deployed with a plurality of cloud entities; querying a graph database storing a security graph to detect a node associated with the cloud entity, wherein the security graph represents the cloud computing environment; determining a reachability path to the node, wherein the reachability path allows access to the cloud entity from a network external to the cloud computing environment; and generating an instruction to secure the sensitive data in response to determining the reachability path.