/Detecting Inter-tenancy Exfiltration In A Cloud Environment
Abstract

Techniques for detecting inter-tenancy exfiltration of data in a cloud environment are disclosed. A log that includes information associated with receipt of a service message at a gateway within a cloud environment is accessed. Based on the log, (i) originating information of the service message (such as identification of an originating tenancy of the service message) and (ii) target information of the service message (such as identification of a target tenancy of the service message) are determined. The originating information and the target information are compared. A mismatch between the originating information of the service message and the target information of the service message is detected. In response to the detected mismatch between the originating information of the service message and the target information of the service message, information indicative of the detected mismatch is caused to be presented at a user interface.

Full Text

What is claimed is:

Techniques for detecting inter-tenancy exfiltration of data in a cloud environment are disclosed. A log that includes information associated with receipt of a service message at a gateway within a cloud environment is accessed. Based on the log, (i) originating information of the service message (such as identification of an originating tenancy of the service message) and (ii) target information of the service message (such as identification of a target tenancy of the service message) are determined. The originating information and the target information are compared. A mismatch between the originating information of the service message and the target information of the service message is detected. In response to the detected mismatch between the originating information of the service message and the target information of the service message, information indicative of the detected mismatch is caused to be presented at a user interface.
Timeline
Filed
06/02/2026
Published
09/24/2026
Granted
Not Available
IPC Codes(2)
G06F 21/57:Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
G06F 21/55:Detecting local intrusion or implementing counter-measures