US 12,445,467 B2
Entitlement-based identity power scoring system for cloud environments
Shoham Danino, Tel-Aviv (IL)
Assigned to Zscaler, Inc., San Jose, CA (US)
Filed by Zscaler, Inc., San Jose, CA (US)
Filed on Nov. 13, 2023, as Appl. No. 18/507,384.
Prior Publication US 2025/0159002 A1, May 15, 2025
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1416 (2013.01) [H04L 63/101 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors in a cloud security platform including distributed inspection nodes and a central authority to perform steps of:
collecting entitlement information associated with an identity of a cloud environment by querying cloud-provider Application Programming Interfaces (APIs) and from telemetry generated by the inspection nodes during inline traffic monitoring;
deriving a global power score of the identity, the global power score being based on the identity's entitlements in the cloud environment;
providing the global power score to security administrators of the cloud environment by way of a Graphical User Interface (GUI);
determining an action score for each of the identity's entitlements in the cloud environment;
determining one or more service scores associated with the identity's entitlements in the cloud environment based on the action scores;
determining one ore more admin category power scores based on the one or more service scores; and
determining one or more account power scores based on the one or more admin category power score, wherein the global power score, together with the admin category power scores and account power scores, are utilized within the cloud security platform to dynamically enforce security policies.