白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Systems and methods for passive key identification

專利號
US11888888B2
公開日期
2024-01-30
申請人
Orca Security LTD.(IL Tel Aviv)
發(fā)明人
Avi Shua
IPC分類
H04L9/08; H04L9/14; H04L67/1008; H04L9/40; H04L67/101; G06F9/455; G06F21/54; G06F21/55; G06F21/56; G06F21/78; G06F21/57; G06F9/50
技術領域
cloud,may,asset,scanning,or,system,workload,in,risk,storage
地域: Tel Aviv-Jaffa

摘要

A method is disclosed for accessing a primary account maintained in a cloud environment, receiving information defining a structure of the primary account, the structure including a plurality of assets, and deploying, inside the primary account or a secondary account for which trust is established with the primary account, at least one ephemeral scanner configured to scan at least one block storage volume and output metadata defining the at least one block storage volume, the output excluding raw data of the primary account. The method further comprises receiving a transmission of the metadata from the at least one ephemeral scanner, excluding raw data of the primary account, analyzing the metadata to identify cybersecurity vulnerabilities, correlating each of the cybersecurity vulnerabilities with one of the assets, and generating a report correlating the cybersecurity vulnerabilities with the assets. Systems and computer-readable media implementing the method are also disclosed.

說明書

Identifying a key to a compute resource, as used herein, may refer to an operation or a process of locating, recognizing, or any operation or process or analyzing computerized data or information to determine that the computerized data or information is a key to the compute resources. By way of example, the at least one processor may analyze cloud infrastructure 106 in FIG. 1 to recognize a list of compute resources in cloud infrastructure 106 (e.g., scanning system 101, any of databases 103A-103D, any of virtual machines 107A-107D, any of databases 109A-109D, any of storage 111A-111D, any of keystores 113A-113D, or load balancer 115). Then, the at least one processor may read computerized data stored in a compute resource and identify that some of the computerized data are one or more keys to other compute resources in cloud infrastructure 106. For example, to recognize the keys, the at least one processor may read and compare the computerized data with records stored in keystores 113A-113D, and determine that the computerized data is a key if it matches a record in any of keystores 113A-113D. As another example, the at least one processor may read the computerized data and check its syntaxes, text string patterns, file formats, file properties, encryption manners, library versions, software versions, or any other characteristics or features of the computerized data, and determine that the computerized data is a key if its checked characteristics or features fit a predetermined pattern of a key or fit an entry in a dictionary of keys. For example, the dictionary of keys may be stored in a keystore (e.g., any of keystores 113A-113D).

權利要求

1
微信群二維碼
意見反饋