IP Library Granted Patent US 10,225,740
Granted Patent B2
US 10,225,740 · App. 15/377,126 · Granted Mar 5, 2019

Multidimensional risk profiling for network access control of mobile devices through a cloud based security system

Inventors: Abhinav Bansal (San Jose, CA); Purvi Desai (Cupertino, CA)
Assignee: Zscaler, Inc.
H04W12/08G06F21/57H04L61/1511H04L63/0272H04L63/0281H04L63/0884H04L63/20H04L67/02H04L67/10H04L67/1002H04L67/125H04L67/16H04L67/22H04L67/28H04L67/2809H04L69/162H04W12/12H04L61/6063H04L63/164
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,225,740
App. No.
15/377,126
Granted
Mar 5, 2019
Kind
B2
Abstract

Systems and methods implemented in a cloud node in a cloud based security system for network access control of a mobile device based on multidimensional risk profiling thereof include receiving posture data from the mobile device; determining a device fingerprint and a risk index of the mobile device based on the posture data; and, responsive to a request by the mobile device for network resources through the cloud based security system, performing a multidimensional risk analysis based on the device fingerprint and the risk index and allowing or denying the request based on the multidimensional risk analysis.

Claims (43)

1. A method implemented in a cloud node in a cloud based security system for network access control of a mobile device based on multidimensional risk profiling thereof, the method comprising:

receiving posture data from the mobile device;

determining a device fingerprint and a risk index of the mobile device based on the posture data; and

responsive to a request by the mobile device for network resources through the cloud based security system, performing a multidimensional risk analysis based on the device fingerprint and the risk index and allowing or denying the request based on the multidimensional risk analysis,

wherein the posture data is obtained from a client application executed on the mobile device, and wherein the client application is configured to periodically capture the posture data comprising hardware parameters, applications installed, versions of the applications, and operating system parameters and patches.

2. The method of claim 1 , wherein the posture data is obtained from a client application executed on the mobile device, and wherein the client application communicatively couples the mobile device to the cloud based security system for network access therethrough.

3. The method of claim 1 , wherein the posture data comprises a hash of the information and the receiving is periodically performed for updates thereto.

4. The method of claim 1 , wherein the multidimensional risk analysis comprises a weighted combination of device risk, application risk, resource risk, user risk, and environment risk.

5. The method of claim 4 , wherein:

the device risk comprises risk involved in accessing the network resource from the mobile device based on the posture data;

the application risk comprises risk involved in using a specific application to access the network resource based on the posture data;

the resource risk comprises potential of the network resource to cause damage;

the user risk comprises risk based on a user's network behavior on the mobile device based on the posture data and based on monitoring by the cloud based security system; and

the environment risk comprises risk assessed by the cloud based security system based on geolocation and global threat conditions.

6. The method of claim 4 , wherein the weighted combination is based on enterprise policy.

7. The method of claim 1 , wherein the risk index for the mobile device is updated over time based on network access history and updates to the posture data.

8. The method of claim 7 , wherein risk score is linearly discounted and recent access is counted higher than remote access in a weighted combination of risk in the multidimensional risk analysis.

9. The method of claim 1 , wherein the multidimensional risk analysis determines a risk score associated with the request for network resources, and wherein the allowing or denying the request is based on the risk score.

10. The method of claim 1 , wherein if the risk index is higher than a threshold, the user is challenged with multifactor authentication or granted access to a quarantined version of the original resource.

11. A cloud node in a cloud based security system, configured to provide network access control of a mobile device based on multidimensional risk profiling, the cloud node comprising:

a network interface, a data store, and a processor communicatively coupled to one another; and

memory storing computer executable instructions, and in response to execution by the processor, the computer-executable instructions cause the processor to

receive posture data from the mobile device;

determine a device fingerprint and a risk index of the mobile device based on the posture data; and

responsive to a request by the mobile device for network resources through the cloud based security system, perform a multidimensional risk analysis based on the device fingerprint and the risk index and allow or deny the request based on the multidimensional risk analysis,

wherein the multidimensional risk analysis comprises a weighted combination of device risk, application risk, resource risk, user risk, and environment risk.

12. The cloud node of claim 11 , wherein the posture data is obtained from a client application executed on the mobile device, and wherein the client application communicatively couples the mobile device to the cloud based security system for network access therethrough.

13. The cloud node of claim 11 , wherein the posture data is obtained from a client application executed on the mobile device, and wherein the client application is configured to periodically capture the posture data comprising hardware parameters, applications installed, versions of the applications, and operating system parameters and patches.

14. The cloud node of claim 11 , wherein:

the device risk comprises risk involved in accessing the network resource from the mobile device based on the posture data;

the application risk comprises risk involved in using a specific application to access the network resource based on the posture data;

the resource risk comprises potential of the network resource to cause damage;

the user risk comprises risk based on a user's network behavior on the mobile device based on the posture data and based on monitoring by the cloud based security system; and

the environment risk comprises risk assessed by the cloud based security system based on geolocation and global threat conditions.

15. The cloud node of claim 11 , wherein the risk index for the mobile device is updated over time based on network access history and updates to the posture data.

16. A mobile device communicatively coupled to a cloud based security system which provides network access control based on multidimensional risk profiling, the mobile device comprising:

a network interface, a data store, and a processor communicatively coupled to one another; and

memory storing computer executable instructions, and in response to execution by the processor, the computer-executable instructions cause the processor to

obtain posture data associated with the mobile device through a client application;

provide the posture data to the cloud based security system for determination of a device fingerprint and a risk index of the mobile device based thereon; and

request network resources through the cloud based security system via the client application, wherein the request is allowed or denied by the cloud based security system based on a multidimensional risk analysis based on the device fingerprint and the risk index,

wherein the posture data is obtained from the client application executed on the mobile device, and wherein the client application is configured to periodically capture the posture data comprising hardware parameters, applications installed, versions of the applications, and operating system parameters and patches.

17. The mobile device of claim 16 , wherein the multidimensional risk analysis comprises a weighted combination of device risk, application risk, resource risk, user risk, and environment risk.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2016
From: BANSAL, ABHINAV; DESAI, PURVI
To: ZSCALER, INC.
Reel/Frame 040723/0487 →
Continuity (2)
Continuation In Part 15153108 · May 12, 2016
Related Publication 20170332238A1 · Nov 16, 2017
Cited By (6)
US 12,273,366 US 12,463,970 US 12,499,329 US 12,563,099 US 12,591,753 US 12,665,856