US 11,750,642 B1
Automated threat modeling using machine-readable threat models
Michael Tautschnig, London (GB); Neha Rungta, San Jose, CA (US); John Cook, Brooklyn, NY (US); Pauline Virginie Bolignano, London (GB); Todd Granger MacDermid, Seattle, WA (US); and Oksana Tkachuk, Palo Alto, CA (US)
Assigned to Amazon Technologies, Inc., Seattle, WA (US)
Filed by Amazon Technologies, Inc., Seattle, WA (US)
Filed on Aug. 15, 2022, as Appl. No. 17/887,803.
Application 17/887,803 is a continuation of application No. 16/842,496, filed on Apr. 7, 2020, granted, now 11,418,532.
Application 16/842,496 is a continuation of application No. 15/907,870, filed on Feb. 28, 2018, granted, now 10,652,266, issued on May 12, 2020.
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/1433 (2013.01) [H04L 63/10 (2013.01); H04L 63/1441 (2013.01); H04L 63/20 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
allocating resources of a cloud platform to a private computing environment of a user account of the cloud platform, wherein the private computing environment includes:
a first component configured to perform first functionality of a service of the user account; and
a second component configured to perform second functionality of the service; and
receiving, from the user account, definitions of rules for preventing unsecure configurations of the resources;
receiving, from the user account, an indication that the rules are to be applied to the first component;
applying the rules against configurations of a set of the resources supporting the first component in the private computing environment associated with the user account;
scanning the resources to validate the configurations of the resources as being compliant with the rules;
determining, based at least in part on the scanning, that a particular resource has an unsecure configuration that is noncompliant with the rules; and
providing the user account with access to an indication of the unsecure configuration of the particular resource that is noncompliant.