Invention Grant
- Patent Title: Enhanced cloud infrastructure security through runtime visibility into deployed software
-
Application No.: US17456335Application Date: 2021-11-23
-
Publication No.: US12003517B2Publication Date: 2024-06-04
- Inventor: Krishnan Shankar Narayan , Yonghui Cheng
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Gilliam IP PLLC
- Main IPC: G06F21/70
- IPC: G06F21/70 ; H04L9/40

Abstract:
A system retrieves from cloud storage a packet(s) sampled from network traffic detected for software deployed on a cloud instance within a cloud environment. Each packet is inspected with deep packet inspection (DPI) to determine characteristics of the packet from which the identity/type of the corresponding software are determined. The system correlates the data/metadata generated from DPI with data/metadata of other cloud resources of the cloud environment based on determining the cloud resources to which the cloud instance is related or which also support deployment/execution of the software. The correlated data/metadata are evaluated based on security policies which include criteria for characteristics of software running on the cloud infrastructure rather than criteria for cloud infrastructure configuration alone. The system thus determines whether a cloud resource complies with the security policies based at least partly on the types/characteristics of software with which it is correlated.
Public/Granted literature
- US20230164148A1 ENHANCED CLOUD INFRASTRUCTURE SECURITY THROUGH RUNTIME VISIBILITY INTO DEPLOYED SOFTWARE Public/Granted day:2023-05-25
Information query