US 12,411,950 B2
Techniques for semantic analysis of cybersecurity event data and remediation of cybersecurity event root causes
Tomer Schwartz, Tel Aviv (IL); Eshel Yaron, Amsterdam (NL); and Barak Bercovitz, Even-Yehuda (IL)
Assigned to Wiz, Inc., New York, NY (US)
Filed by Dazz, Inc., San Francisco, CA (US)
Filed on Feb. 20, 2025, as Appl. No. 19/058,833.
Application 19/058,833 is a continuation of application No. 17/507,180, filed on Oct. 21, 2021.
Prior Publication US 2025/0190555 A1, Jun. 12, 2025
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 21/55 (2013.01); G06F 8/70 (2018.01); G06F 16/245 (2019.01); G06F 16/901 (2019.01); G06F 40/242 (2020.01); G06F 40/30 (2020.01)
CPC G06F 21/554 (2013.01) [G06F 8/70 (2013.01); G06F 16/245 (2019.01); G06F 16/9024 (2019.01); G06F 40/242 (2020.01); G06F 40/30 (2020.01); G06F 2221/033 (2013.01)] 19 Claims
OG exemplary drawing
 
1. A method for remediating cybersecurity events, comprising:
creating a semantic concepts dictionary, wherein the semantic concepts dictionary defines a plurality of semantic concepts representing characteristics of software components;
creating an entity graph based on a plurality of correlations between entities among a plurality of entities, wherein the entity graph has a plurality of nodes representing respective entities of the plurality of entities, wherein the plurality of entities includes a plurality of software components of a software infrastructure and a plurality of event logic components of cybersecurity event logic deployed with respect to the software infrastructure;
building a knowledge base such that the knowledge base includes the semantic concepts dictionary and the entity graph;
querying the knowledge base using a query generated based on at least one semantic concept and at least one entity-identifying value extracted from cybersecurity event data indicating a cybersecurity event for the software infrastructure, wherein the knowledge base returns at least one query result, wherein the query includes at least one semantic concept and at least one entity-identifying value; and
performing at least one remedial action based on the at least one query result.