Techniques for cloud computing forensics utilizing a security graph
Abstract
A system and method for generating a compact forensic event log based on a cloud log, includes: traversing a security graph to detect a node representing a cloud entity in a cloud computing environment, wherein the security graph includes a representation of the cloud computing environment; detecting a node representing a cybersecurity threat connected to the node representing the cloud entity; parsing a cloud log of the cloud computing environment to detect a data record, the data record including an attribute of the node representing the cloud entity; and generating a compact forensic event log including the detected data record.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for generating a compact forensic event log based on a cloud log, comprising:
traversing a security graph to detect a node representing a cloud entity in a cloud computing environment, wherein the security graph includes a representation of the cloud computing environment; detecting a node representing a cybersecurity threat connected to the node representing the cloud entity; parsing a cloud log of the cloud computing environment to detect a data record, the data record including an attribute of the node representing the cloud entity; and generating a compact forensic event log including the detected data record.
2 . The method of claim 1 , further comprising:
receiving an identifier of the cloud entity; and traversing the security graph further based on the received identifier to detect the node representing the cloud entity.
3 . The method of claim 1 , further comprising:
detecting the data record further based on an identifier of the cybersecurity threat.
4 . The method of claim 1 , further comprising:
generating the compact forensic event log in response to detecting that the node representing the cloud entity is connected to the node representing the cybersecurity threat.
5 . The method of claim 1 , wherein the cloud log is any one of: a network log, and a role log.
6 . The method of claim 1 , wherein the attribute is any one of: a unique identifier, an IP address, a workload type, a user account name, a role, and an authentication status.
7 . The method of claim 1 , wherein the cybersecurity threat is any one of: a vulnerability, a misconfiguration, and an exploit.
8 . The method of claim 1 , further comprising:
generating the compact forensic event log based on a plurality of cloud logs, each cloud log parsed to detect a data record including the attribute of the node representing the cloud entity.
9 . The method of claim 1 , further comprising:
storing the compact forensic event log in a storage; and storing a time-based portion of the cloud log in the storage.
10 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:
traversing a security graph to detect a node representing a cloud entity in a cloud computing environment, wherein the security graph includes a representation of the cloud computing environment; detecting a node representing a cybersecurity threat connected to the node representing the cloud entity; parsing a cloud log of the cloud computing environment to detect a data record, the data record including an attribute of the node representing the cloud entity; and generating a compact forensic event log including the detected data record.
11 . A system for generating a compact forensic event log based on a cloud log, comprising:
a processing circuitry; and a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to: traverse a security graph to detect a node representing a cloud entity in a cloud computing environment, wherein the security graph includes a representation of the cloud computing environment; detect a node representing a cybersecurity threat connected to the node representing the cloud entity; parse a cloud log of the cloud computing environment to detect a data record, the data record including an attribute of the node representing the cloud entity; and generate a compact forensic event log including the detected data record.
12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry, further configure the system to:
receive an identifier of the cloud entity; and traverse the security graph further based on the received identifier to detect the node representing the cloud entity.
13 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry, further configure the system to:
detect the data record further based on an identifier of the cybersecurity threat.
14 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry, further configure the system to:
generate the compact forensic event log in response to detecting that the node representing the cloud entity is connected to the node representing the cybersecurity threat.
15 . The system of claim 11 , wherein the cloud log is any one of: a network log, and a role log.
16 . The system of claim 11 , wherein the attribute is any one of: a unique identifier, an IP address, a workload type, a user account name, a role, and an authentication status.
17 . The system of claim 11 , wherein the cybersecurity threat is any one of: a vulnerability, a misconfiguration, and an exploit.
18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry, further configure the system to:
generate the compact forensic event log based on a plurality of cloud logs, each cloud log parsed to detect a data record including the attribute of the node representing the cloud entity.
19 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry, further configure the system to:
store the compact forensic event log in a storage; and store a time-based portion of the cloud log in the storage.Join the waitlist — get patent alerts
Track US2023247039A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.