IP Library Granted Patent US 12684018
Granted Patent B2
US 12684018 · App. 18/732,546 · Granted Jul 14, 2026

Cloud security visual dashboard

Inventors: Krishna Narayanaswamy (Saratoga, CA); Lebin Cheng (Saratoga, CA); Abhay Kulkarni (Cupertino, CA); Ravi Ithal (Los Altos, CA); Chetan Anand (San Francisco, CA); Rajneesh Chopra (Sunnyvale, CA)
Assignee: Netskope, Inc.
H04L63/20G06F16/285G06F16/951G06F21/6209H04L63/0281H04L63/10H04L63/104H04L63/105H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12684018
App. No.
18/732,546
Granted
Jul 14, 2026
Kind
B2
Abstract

The technology disclosed relates to a proxy receiving a request to manipulate a data object on an independent object store. The proxy is interposed between a user system from which the request originates and the independent object store. The technology disclosed further relates to the proxy accessing a metadata store that contains object metadata for the data object and retrieving the object metadata. The technology disclosed further relates to the proxy enforcing a policy on the request based on the object metadata. Enforcing the policy further includes enforcing malware detection policies and threat detection policies.

Claims (49)

1 . A method, comprising:

identifying, with an inspective analyzer of a proxy device of a network security service, a plurality of file objects associated with an enterprise and stored in a cloud computing service;

determining, with the inspective analyzer, metadata associated with each of the plurality of file objects, wherein the metadata comprises a name of the respective file object, a type of the respective file object, exposure information for the respective file object, and security policies previously triggered against the respective file object; and

providing, by the network security service, a visibility dashboard comprising a graphical summary of information about the plurality of file objects generated from the metadata associated with each of the plurality of file objects.

2 . The method of claim 1 , wherein the graphical summary comprises an indication of a number of the plurality of file objects that are privately owned.

3 . The method of claim 1 , wherein the graphical summary comprises an indication of a number of the plurality of file objects that are publicly accessible.

4 . The method of claim 1 , wherein the graphical summary comprises an indication of a number of the plurality of file objects that are shared intra-organizationally.

5 . The method of claim 1 , wherein the graphical summary comprises an indication of a number of the plurality of file objects that are shared extra-organizationally.

6 . The method of claim 1 , wherein the graphical summary comprises an indication of the true file types of each of the plurality of file objects.

7 . The method of claim 1 , wherein the graphical summary comprises an indication of a number of policy violations attempted in association with the plurality of file objects.

8 . The method of claim 1 , wherein the graphical summary comprises selectable filters for viewing the metadata of subsets of the plurality of file objects.

9 . The method of claim 8 , wherein the selectable filters comprise one or more of file size, data loss prevention profile, legal hold, quarantine, malware, encryption, and collaboration.

10 . The method of claim 1 , wherein the type of each of the file objects is one of a folder, a video, an image, an audio file, a document, and a text file.

11 . The method of claim 1 , further comprising:

discovering, with the inspective analyzer, cloud applications executing in an environment of the enterprise.

12 . The method of claim 1 , wherein the identifying the plurality of file objects comprises:

accessing the cloud computing service with an application programming interface (API) connection; and

inspecting content resident in the cloud computing service.

13 . The method of claim 12 , further comprising:

identifying sensitive content in one or more of the plurality of file objects; and

in response, encrypting or quarantining the one or more of the plurality of file objects.

14 . The method of claim 1 , further comprising:

assembling the metadata, wherein the metadata comprises structured and unstructured data; and

storing the assembled metadata in a semi-structured data format.

15 . The method of claim 1 , further comprising:

applying security policies to the plurality of file objects based on the respective metadata.

16 . A network security system, comprising:

an inspective analyzer configured to:

identify a plurality of file objects associated with an enterprise and stored in a cloud computing service, and

determine metadata associated with each of the plurality of file objects, wherein the metadata comprises a name of the respective file object, a type of the respective file object, exposure information for the respective file object, and security policies previously triggered against the respective file object; and

an interface component configured to:

provide a visibility dashboard comprising a graphical summary of information about the plurality of file objects generated from the metadata associated with each of the plurality of file objects.

17 . The network security system of claim 16 , wherein the graphical summary comprises one or more of:

an indication of a number of the plurality of file objects that are privately owned;

an indication of a number of the plurality of file objects that are publicly accessible;

an indication of a number of the plurality of file objects that are shared intra-organizationally;

an indication of a number of the plurality of file objects that are shared extra-organizationally;

an indication of the true file types of each of the plurality of file objects; and

an indication of a number of policy violations attempted in association with the plurality of file objects.

18 . The network security system of claim 16 , wherein the inspective analyzer is further configured to:

discover cloud applications executing in an environment of the enterprise.

19 . The network security system of claim 16 , wherein the inspective analyzer is further configured to:

access the cloud computing service with an application programming interface (API) connection;

inspect content resident in the cloud computing service;

identify sensitive content in one or more of the plurality of file objects; and

in response, encrypt or quarantine the one or more of the plurality of file objects.

20 . The network security system of claim 16 , wherein the inspective analyzer is further configured to:

assemble the metadata, wherein the metadata comprises structured and unstructured data; and

store the assembled metadata in a semi-structured data format.