-
公开(公告)号:US11637855B2
公开(公告)日:2023-04-25
申请号:US17657972
申请日:2022-04-05
Applicant: Orca Security LTD.
Inventor: Avi Shua
IPC: H04L9/40 , G06F9/455 , H04L67/1008 , H04L67/101 , G06F9/50 , G06F21/54 , G06F21/55 , G06F21/56 , G06F21/78 , G06F21/57 , H04L9/08 , H04L9/14
Abstract: Systems, methods, and computer-readable media are provided for securing cloud infrastructure, including a method comprising: establishing a trusted relationship between a source account in a cloud environment and a scanner account, using the established trust relationship, utilizing at least one cloud provider API to identify workloads in the source account, using the at least one cloud provider API to query a geographical location of at least one of the identified workloads, receiving an identification of the geographic location, using the cloud provider APIs to access block storage volumes of the at least one workload, determining a file-system of the at least one workload, mounting the block storage volumes on a scanner based on the determined file-system, activating a scanner at the geographic location, reconstructing from the block storage volumes a state of the workload, and assessing the reconstructed state of the workload to extract insights.
-
公开(公告)号:US20230093527A1
公开(公告)日:2023-03-23
申请号:US18055201
申请日:2022-11-14
Applicant: Orca Security Ltd.
Inventor: Avi Shua
Abstract: A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority.
-
公开(公告)号:US12204930B2
公开(公告)日:2025-01-21
申请号:US18470509
申请日:2023-09-20
Applicant: Orca Security Ltd.
Inventor: Avi Shua
Abstract: A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority.
-
14.
公开(公告)号:US11775326B2
公开(公告)日:2023-10-03
申请号:US18055181
申请日:2022-11-14
Applicant: Orca Security Ltd.
Inventor: Avi Shua
CPC classification number: H04L63/1416 , G06F9/45558 , G06F11/1464 , G06F16/128 , H04L63/1433 , H04L63/1441 , G06F2009/45562 , G06F2009/45583 , G06F2009/45587 , G06F2009/45591 , G06F2009/45595 , G06F2201/84
Abstract: A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority.
-
公开(公告)号:US11663031B2
公开(公告)日:2023-05-30
申请号:US17400364
申请日:2021-08-12
Applicant: Orca Security LTD.
Inventor: Avi Shua
CPC classification number: H04L63/1416 , G06F9/45558 , G06F11/1464 , G06F16/128 , H04L63/1433 , H04L63/1441 , G06F2009/45562 , G06F2009/45583 , G06F2009/45587 , G06F2009/45591 , G06F2009/45595 , G06F2201/84
Abstract: A method and system for securing virtual cloud assets at rest against cyber threats. The method comprises determining a location of a view of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is at rest and, when activated, instantiated in the cloud computing environment; accessing the view of the virtual disk based on the determined location; analyzing the view of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset, wherein the virtual cloud asset is inactive during the analysis; and alerting detected potential cyber threats based on a determined priority.
-
公开(公告)号:US20230092220A1
公开(公告)日:2023-03-23
申请号:US18055220
申请日:2022-11-14
Applicant: Orca Security Ltd.
Inventor: Avi Shua
Abstract: A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority.
-
17.
公开(公告)号:US20230087080A1
公开(公告)日:2023-03-23
申请号:US18055181
申请日:2022-11-14
Applicant: Orca Security Ltd.
Inventor: Avi Shua
Abstract: A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority.
-
公开(公告)号:US11431735B2
公开(公告)日:2022-08-30
申请号:US16585967
申请日:2019-09-27
Applicant: Orca Security LTD.
Inventor: Avi Shua
Abstract: A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority.
-
公开(公告)号:US11943251B2
公开(公告)日:2024-03-26
申请号:US17658149
申请日:2022-04-06
Applicant: Orca Security LTD.
Inventor: Avi Shua
IPC: H04L9/40 , G06F9/455 , G06F9/50 , G06F21/54 , G06F21/55 , G06F21/56 , G06F21/57 , G06F21/78 , H04L9/08 , H04L9/14 , H04L67/1008 , H04L67/101
CPC classification number: H04L63/1433 , G06F9/45558 , G06F9/5072 , G06F21/54 , G06F21/554 , G06F21/568 , G06F21/577 , G06F21/78 , H04L9/0825 , H04L9/0894 , H04L9/14 , H04L63/10 , H04L63/1441 , H04L63/145 , H04L67/1008 , H04L67/101 , G06F2009/4557 , G06F2009/45595 , G06F2221/034
Abstract: A cyber security system for a cloud environment is disclosed. In some embodiments, a method is disclosed. The method comprises utilizing a cloud provider API to access a block storage volume of a workload maintained on a target account in a target system of a cloud storage environment, utilizing a scanner at a location of the block storage volume and on a secondary system other than the target system, scanning the block storage volume for malicious code using the secondary system, identifying malicious code based on the scan, and outputting a notification of a presence of malicious code in the target system from the secondary system.
-
公开(公告)号:US11888888B2
公开(公告)日:2024-01-30
申请号:US17658156
申请日:2022-04-06
Applicant: Orca Security LTD.
Inventor: Avi Shua
IPC: H04L9/08 , H04L9/14 , H04L67/1008 , H04L9/40 , H04L67/101 , G06F9/455 , G06F21/54 , G06F21/55 , G06F21/56 , G06F21/78 , G06F21/57 , G06F9/50
CPC classification number: H04L63/1433 , G06F9/45558 , G06F9/5072 , G06F21/54 , G06F21/554 , G06F21/568 , G06F21/577 , G06F21/78 , H04L9/0825 , H04L9/0894 , H04L9/14 , H04L63/10 , H04L63/145 , H04L63/1441 , H04L67/101 , H04L67/1008 , G06F2009/4557 , G06F2009/45595 , G06F2221/034
Abstract: A method is disclosed for accessing a primary account maintained in a cloud environment, receiving information defining a structure of the primary account, the structure including a plurality of assets, and deploying, inside the primary account or a secondary account for which trust is established with the primary account, at least one ephemeral scanner configured to scan at least one block storage volume and output metadata defining the at least one block storage volume, the output excluding raw data of the primary account. The method further comprises receiving a transmission of the metadata from the at least one ephemeral scanner, excluding raw data of the primary account, analyzing the metadata to identify cybersecurity vulnerabilities, correlating each of the cybersecurity vulnerabilities with one of the assets, and generating a report correlating the cybersecurity vulnerabilities with the assets. Systems and computer-readable media implementing the method are also disclosed.
-
-
-
-
-
-
-
-
-