IP Library Granted Patent US 12701118
Granted Patent B2
US 12701118 · App. 18/665,647 · Granted Aug 4, 2026

User activity auditing of resource traversal across connected company nodes

Inventors: Ofer Ben-Noon (Tel Aviv, IL); Ohad Bobrov (Tel Aviv, IL); Guy Harpak (Ramat Gan, IL); Eran Rom (Tel Aviv, IL); Ido Salomon (Tel Aviv, IL)
Assignee: Palo Alto Networks, Inc.
H04L63/10G06F21/16G06F21/554G06F21/6245H04L63/105H04L63/1433H04L63/205H04L67/1396H04L67/535G06F2221/034G06F2221/2141H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701118
App. No.
18/665,647
Granted
Aug 4, 2026
Kind
B2
Abstract

Based on occurrence of audit trigger events that include uploading, downloading, modifying, copying, and pasting of resources across browsers at nodes of a company, audit records are generated that indicate user identifiers, time stamps, metadata, and content associated with the resources. The audit records specify trajectories/traversals of resources across the company that are used to determine associated users and data breaches. Pairs of audit records in the traversals have same hashes of content/metadata of a corresponding resource.

Claims (53)

1 . A method comprising:

monitoring activity across a plurality of users at a plurality of browser instances running on respective ones of a plurality of nodes in a network corresponding to a company, wherein monitoring activity of the plurality of users comprises,

detecting events at the plurality of browser instances that trigger auditing of activity of the plurality of users; and

generating records corresponding to the events, wherein each record indicates a time stamp of the corresponding one of the events, an identifier of a resource corresponding to the event, and a hash of at least a portion of content of the resource corresponding to the event; and

determining a traversal of a resource through the plurality of nodes corresponding to a potential security breach based on the records, wherein identifying the traversal of the resource comprises identifying a sequence of the records based on the time of day indicated in the records and based on each consecutive pair of records in the sequence indicating at least one of a same hash of at least a portion of content and a same identifier of the resource of the determined traversal.

2 . The method of claim 1 , wherein identifying the sequence of the records corresponding to the traversal of the resource comprises identifying the sequence of the records arranged sequentially according to the time stamps indicated in the records.

3 . The method of claim 2 , wherein identifying the sequence of the records corresponding to the traversal of the resource comprises:

identifying a first record of the records corresponding to a first node of the plurality of nodes at a first time stamp, wherein the first record indicates uploading the resource from the first node to a second node of the plurality of nodes; and

identifying a second record of the records corresponding to the second node and the resource at a second time stamp subsequent to the first time stamp.

4 . The method of claim 2 , wherein identifying the sequence of the records corresponding to the traversal of the resource comprises:

identifying a first record of the records that indicates a modification of the resource at a second node of the plurality of nodes, wherein the first record comprises at least one of a first identifier and a first hash of at least a portion of content corresponding to the resource prior to the modification and at least one of a second identifier and a second hash of at least a portion of content corresponding to the resource subsequent to the modification; and

identifying a second record of the second node or a third node subsequent to the first record that indicates at least one of the second identifier and the second hash.

5 . The method of claim 1 , wherein the events at the plurality of browser instances comprise at least one of downloading resources, modifying resources, copying resources, pasting resources to a clipboard, and uploading resources.

6 . The method of claim 1 , wherein determining the traversal of the resource comprises identifying an initial record in the sequence of the records that indicates an initial download of the resource.

7 . The method of claim 1 , wherein determining the traversal of the resource comprises identifying a final record in the sequence of the records that indicates an upload of the resource to an entity external to the company.

8 . The method of claim 1 , further comprising:

identifying at least a subset of the plurality of users being indicated in the sequence of the records; and

associating the subset of users with the potential security breach.

9 . A non-transitory machine-readable medium having program code stored thereon, the program code comprising instructions to:

monitor activity across a plurality of users at a plurality of browser instances running on respective ones of a plurality of nodes in a network corresponding to a company, wherein the instructions to monitor activity of the plurality of users comprise instructions to,

detect events at the plurality of browser instances that trigger auditing of activity of the plurality of users; and

generate records corresponding to the events, wherein each record indicates a time stamp of the corresponding one of the events, an identifier of a resource corresponding to the event, and a hash of at least a portion of content of the resource corresponding to the event; and

determine a traversal of a resource through the plurality of nodes corresponding to a potential security breach based on the records, wherein the instructions to identify the traversal of the resource comprise instructions to identify a sequence of the records based on the time of day indicated in the records and based on each consecutive pair of records in the sequence indicating at least one of a same hash of at least a portion of content and a same identifier of the resource of the determined traversal.

10 . The non-transitory machine-readable medium of claim 9 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions to identify the sequence of the records arranged sequentially according to the time stamps indicated in the records.

11 . The non-transitory machine-readable medium of claim 10 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions to:

identify a first record of the records corresponding to a first node of the plurality of nodes at a first time stamp, wherein the first record indicates uploading the resource from the first node to a second node of the plurality of nodes; and

identify a second record of the records corresponding to the second node and the resource at a second time stamp subsequent to the first time stamp.

12 . The non-transitory machine-readable medium of claim 10 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions to:

identify a first record of the records that indicates a modification of the resource at a second node of the plurality of nodes, wherein the first record comprises at least one of a first identifier and a first hash of at least a portion of content corresponding to the resource prior to the modification and at least one of a second identifier and a second hash of at least a portion of content corresponding to the resource subsequent to the modification; and

identify a second record of the second node or a third node subsequent to the first record that indicates at least one of the second identifier and the second hash.

13 . The non-transitory machine-readable medium of claim 9 , wherein the events at the plurality of browser instances comprise at least one of downloading resources, modifying resources, copying resources, pasting resources to a clipboard, and uploading resources.

14 . The non-transitory machine-readable medium of claim 9 , wherein the instructions to determine the traversal of the resource comprise instructions to identify an initial record in the sequence of the records that indicates an initial download of the resource.

15 . The non-transitory machine-readable medium of claim 9 , wherein the instructions to determine the traversal of the resource comprise instructions to identify a final record in the sequence of the records that indicates an upload of the resource to an entity external to the company.

16 . The non-transitory machine-readable medium of claim 9 , wherein the program code further comprises instructions to:

identify at least a subset of the plurality users indicated in the sequence of the records; and

associate the subset of users with the potential security breach.

17 . A apparatus comprising:

a processor; and

a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to,

monitor activity of a plurality of users at a plurality of browser instances running on respective ones of a plurality of nodes in a network corresponding to a company, wherein the instructions to monitor activity of the plurality of users comprise instructions executable by the processor to cause the apparatus to,

detect events at the plurality of browser instances that trigger auditing of activity of the plurality of users; and

generate records corresponding to the events, wherein each record indicates a time stamp of the corresponding one of the events, an identifier of a resource corresponding to the event, and a hash of at least a portion of content of the resource corresponding to the event; and

determine a traversal of a resource through the plurality of nodes corresponding to a potential security breach based on the records, wherein the instructions to identify the traversal of the resource comprise instructions executable by the processor to cause the apparatus to identify a sequence of the records based on the time of day indicated in the records and based on each consecutive pair of records in the sequence indicating at least one of a same hash of at least a portion of content and a same identifier of the resource of the determined traversal.

18 . The apparatus of claim 17 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions executable by the processor to cause the apparatus to identify the sequence of the records arranged sequentially according to the time stamps indicated in the records.

19 . The apparatus of claim 18 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions executable by the processor to cause the apparatus to:

identify a first record of the records corresponding to a first node of the plurality of nodes at a first time stamp, wherein the first record indicates uploading the resource from the first node to a second node of the plurality of nodes; and

identify a second record of the records corresponding to the second node and the resource at a second time stamp subsequent to the first time stamp.

20 . The apparatus of claim 18 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions executable by the processor to cause the apparatus to:

identify a first record of the records that indicates a modification of the resource at a second node of the plurality of nodes, wherein the first record comprises at least one of a first identifier and a first hash of at least a portion of content corresponding to the resource prior to the modification and at least one of a second identifier and a second hash of at least a portion of content corresponding to the resource subsequent to the modification; and

identify a second record of the second node or a third node subsequent to the first record that indicates at least one of the second identifier and the second hash.

21 . The apparatus of claim 17 , wherein the events at the plurality of browser instances comprise at least one of downloading resources, modifying resources, copying resources, pasting resources to a clipboard, and uploading resources.

22 . The apparatus of claim 17 , wherein the instructions to determine the traversal of the resource comprise instructions executable by the processor to cause the apparatus to identify an initial record in the sequence of the records that indicates an initial download of the resource.

23 . The apparatus of claim 17 , wherein the instructions to determine the traversal of the resource comprise instructions executable by the processor to cause the apparatus to identify a final record in the sequence of the records that indicates an upload of the resource to an entity external to the company.