The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 10, 2024

Filed:

Dec. 09, 2021
Applicant:

Amazon Technologies, Inc., Seattle, WA (US);

Inventors:

Meng Li, San Jose, CA (US);

Vishal Gori, Melrose, MA (US);

Zhixing Xu, Sunnyvale, CA (US);

Niloofar Razavi, San Jose, CA (US);

Oksana Tkachuk, Palo Alto, CA (US);

Assignee:

Amazon Technologies, Inc., Seattle, WA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/60 (2013.01); G06F 21/31 (2013.01); G06F 21/45 (2013.01); G06F 21/62 (2013.01);
U.S. Cl.
CPC ...
G06F 21/604 (2013.01); G06F 21/31 (2013.01); G06F 21/45 (2013.01); G06F 21/6218 (2013.01);
Abstract

Techniques are described for analyzing privilege escalation risks within the accounts, roles, and policies that comprise an organization's cloud provider environment. Privilege escalation refers broadly to scenarios in which a principal (e.g., a person or application) is able to gain access to resources or actions in a cloud provider environment that exceed a level intended for that principal. In the context of cloud provider environments, for example, such privilege escalation risks can result from the misconfiguration of policies and permissions attached to identities (e.g., users, groups of users, or roles) within an organization's environment. A multi-layer reasoning framework is used to build an ontology model of an organization's identities and relations among the identities, including defined access relationships, permission mutation relationships, and credential mutation relationships. The framework is further used to query the ontology model to identify particular identities associated with one or more specific types of privilege escalation risks.


Find Patent Forward Citations

Loading…