| CPC H04L 63/145 (2013.01) [G06F 21/53 (2013.01)] | 21 Claims |

|
1. A method for detecting a malware infection path in a compute environment, comprising:
detecting a cybersecurity object, indicating a malware, on a first workload in a computing environment, the computing environment including a plurality of workloads, wherein the first workload is represented by a resource node on a security graph, the security graph further including an endpoint node representing access to a public access network;
traversing the security graph from the resource node to the endpoint node to generate a plurality of potential infection paths between the resource node and the endpoint node;
inspecting a second workload of the plurality of workloads for the cybersecurity object, wherein the second workload is represented by a second resource node, and the second resource node is on a first potential infection path of the plurality of potential infection paths;
determining that the first potential infection path is a confirmed infection path, in response to detecting the cybersecurity object on the second workload;
determining that the first potential infection path is not an infection path, in response to detecting that the second workload does not include the cybersecurity object;
monitoring the second workload for the cybersecurity object in response to determining that the first potential infection path is not an infection path; and
initiating a mitigation action in response to detecting the cybersecurity object on the second workload.
|