WO2023094931 - DETECTING VULNERABILITIES IN CONFIGURATION CODE OF A CLOUD ENVIRONMENT UTILIZING INFRASTRUCTURE AS CODE

National phase entry:
Publication Number WO/2023/094931
Publication Date 01.06.2023
International Application No. PCT/IB2022/060940
International Filing Date 14.11.2022
Title **
[English] DETECTING VULNERABILITIES IN CONFIGURATION CODE OF A CLOUD ENVIRONMENT UTILIZING INFRASTRUCTURE AS CODE
[French] DÉTECTION DE VULNÉRABILITÉS DANS UN CODE DE CONFIGURATION D'UN ENVIRONNEMENT EN NUAGE UTILISANT UNE INFRASTRUCTURE EN TANT QUE CODE
Applicants **
WIZ, INC.
Inventors
HERZBERG, Raaz
OLIVER, Yaniv Joseph
HAZAN, Osher
BEN DAVID, Niv Roit
LUTTWAK, Ami
REZNIK, Roy
Priority Data
63/264,550   24.11.2021   US
63/283,376   26.11.2021   US
63/283,378   26.11.2021   US
63/283,379   26.11.2021   US
Application details
Total Number of Claims/PCT *
Number of Independent Claims *
Number of Priorities *
Number of Multi-Dependent Claims *
Number of Drawings *
Pages for Publication *
Number of Pages with Drawings *
Pages of Specification *
*
Number of Office Actions *
*
International Searching Authority
*
Recordal of a Change of the Applicant's Name/Address
*
Type of Assignment
*
Applicant's Legal Status
*
*
*
*
*
*
Entry into National Phase under
*
Patent Delivery
*
Translation

* The data is based on automatic recognition. Please verify and amend if necessary.

** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.

Quotation for National Phase entry

Country StagesTotal
China Filing, Examination, Granting2373
EPO Filing, Examination, Granting13667
Japan Filing, Examination, Granting2296
South Korea Filing, Examination, Granting2458
USA Filing, Examination, Granting4740
MasterCard Visa
Total: 25,534

The term for entry into the National Phase has expired. This quotation is for informational purposes only

Contact Us
Abstract[English] A system and method for detecting a vulnerable code object in configuration code for deploying instances in a cloud computing environment is disclosed. The method includes accessing a configuration code, the configuration code including a plurality of code objects, each code object of the plurality of code objects corresponding to a deployable virtual instance; querying a security graph to detect a node having an attribute value which matches a value extracted from a first code object of the plurality of code objects, wherein the security graph includes a representation of a cloud computing environment; and generating a mitigation action in response to determining that the detected node is associated with a cybersecurity issue.[French] L'invention concerne un système et un procédé pour détecter un objet de code vulnérable dans un code de configuration pour déployer des instances dans un environnement informatique en nuage. Le procédé consiste à accéder à un code de configuration, le code de configuration comprenant une pluralité d'objets de code, chaque objet de code de la pluralité d'objets de code correspondant à un instance virtuelle déployable ; à interroger un graphique de sécurité pour détecter un nœud ayant une valeur d'attribut qui correspond à une valeur extraite d'un premier objet de code de la pluralité d'objets de code, le graphique de sécurité comprenant une représentation d'un environnement informatique en nuage ; et à générer une action d'atténuation en réponse à la détermination du fait que le nœud détecté est associé à un problème de cybersécurité.

Rejoining the server...