Patent · US Active

Techniques for cybersecurity identity risk detection utilizing disk cloning and unified identity mapping

US12244634B2 · kind B2 · utility

0Cited by
117References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 26, 2024
Grant dateMar 4, 2025
Priority date
Expiry dateApr 26, 2044

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/1097
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system and method for detecting a permission escalation event in a computing environment is disclosed. The method includes: generating a cloned disk based on an original disk of a resource deployed in a computing environment; detecting an identifier of a first principal on the cloned disk; detecting a second principal in the computing environment, the first principal authorized to assume the first principal; storing a representation of the computing environment in a security database, including: a first principal node representing the first principal, and a second principal node representing the second principal, further associated with a permission; querying the representation to determine a permission of the first principal; determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and generating a permission escalation event.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.