IP Library Granted Patent US 12,489,790
Granted Patent B2
US 12,489,790 · App. 17/375,378 · Granted Dec 2, 2025

Distributed network application security policy generation and enforcement for microsegmentation

Inventors: John H. O'Neil (Watertown, MA); Peter Smith (Acton, MA); Thomas Evan Keiser, Jr. (Boston, MA)
Assignee: Zscaler, Inc.
H04L63/20G06F21/606G06F21/6218H04L63/0263H04L63/102H04L63/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,790
App. No.
17/375,378
Granted
Dec 2, 2025
Kind
B2
Abstract

Systems and methods for microsegmentation include receiving network communication information that describes flows between hosts in a network and applications executed on the hosts; generating a network communication model based on the network communication information that labels flows; and providing polices to the hosts based on the network communication model where the policies cause performance a set of actions, locally at a host, on any of the flows based on corresponding labels. The labels are one of healthy and unhealthy. The set of actions include blocking, allowing, and allowing for a period of time before confirmation.

Claims (34)

1 . A method comprising:

receiving network communication information that describes flows between hosts in a network and applications executed on the hosts;

generating a network communication model based on the network communication information, wherein the generating the network communication model comprises automatically selecting, from among a plurality of available constraints, one or more constraints comprising at least human readability or human modifiability, and applying the selected constraints to produce labeled network flows in the network communication mode; and

providing policies to the hosts based on the network communication model where the policies cause performance a set of actions, locally at a host, on any of the flows based on corresponding labels, wherein the policies are provided to the host based on one or more automatically generated microsegments defined by an identity-based protection policy at a workload, the workload is application-centric and independent of a network structure and configured to enable granular security via the microsegments.

2 . The method of claim 1 , wherein the labeled network flows are one of healthy and unhealthy.

3 . The method of claim 1 , wherein the set of actions include blocking, allowing, and allowing for a period of time before confirmation.

4 . The method of claim 1 , wherein the labeled network flows are one of healthy and unhealthy, and wherein the set of actions include blocking, allowing, and allowing for a period of time before confirmation.

5 . The method of claim 1 , wherein the policies are configured to govern a connection between the one or more microsegments on the network by applying granular security controls at a workload level, the connection defined by an east-west connection.

6 . The method of claim 1 , wherein the labeled network flows are multiple sequential flows combined into a single flow and are internal workload communications defining east-west traffic.

7 . The method of claim 1 , further comprising

providing output to a user representing the one or more microsegments;

receiving policy decisions for hosts based on the set of actions; and

performing a reconciliation that can include causing termination of a flow after being allowed.

8 . A non-transitory computer-readable medium having computer program instructions stored thereon, the computer program instructions being executable by at least one computer processor communicatively coupled to a network to perform steps of:

receiving network communication information that describes flows between hosts in the network and applications executed on the hosts;

generating a network communication model based on the network communication information, wherein the generating the network communication model comprises automatically selecting, from among a plurality of available constraints, one or more constraints comprising at least human readability or human modifiability, and applying the selected constraints to produce labeled network flows in the network communication mode; and

providing policies to the hosts based on the network communication model where the policies cause performance a set of actions, locally at a host, on any of the flows based on corresponding labels, wherein the policies are provided to the host based on one or more automatically generated microsegments defined by an identity-based protection policy at a workload, the workload is application-centric and independent of a network structure and configured to enable granular security via the microsegments.

9 . The non-transitory computer-readable medium of claim 8 , wherein the labeled network flows are one of healthy and unhealthy.

10 . The non-transitory computer-readable medium of claim 8 , wherein the set of actions include blocking, allowing, and allowing for a period of time before confirmation.

11 . The non-transitory computer-readable medium of claim 8 , wherein the labeled network flows are one of healthy and unhealthy, and wherein the set of actions include blocking, allowing, and allowing for a period of time before confirmation.

12 . The non-transitory computer-readable medium of claim 8 , wherein the policies define microsegments on the network.

13 . The non-transitory computer-readable medium of claim 8 , wherein the labeled network flows are internal workload communications.

14 . The non-transitory computer-readable medium of claim 8 , wherein the steps further include

receiving policy decisions for hosts based on the set of actions; and

performing a reconciliation that can include causing termination of a flow after being allowed.

15 . A system comprising at least one processor and memory storing instructions that, when executed, cause the at least one processor to:

receive network communication information that describes flows between hosts in a network and applications executed on the hosts;

generate a network communication model based on the network communication information, wherein the generating the network communication model comprises automatically selecting, from among a plurality of available constraints, one or more constraints comprising at least human readability or human modifiability, and applying the selected constraints to produce labeled network flows in the network communication mode; and

provide policies to the hosts based on the network communication model where the policies cause performance a set of actions, locally at a host, on any of the flows based on corresponding labels, wherein the policies are provided to the host based on one or more automatically generated microsegments defined by an identity-based protection policy at a workload, the workload is application-centric and independent of a network structure and configured to enable granular security via the microsegments.

16 . The system of claim 15 , wherein the ed network flows are one of healthy and unhealthy.

17 . The system of claim 15 , wherein the set of actions include blocking, allowing, and allowing for a period of time before confirmation.

18 . The system of claim 15 , wherein the labeled network flows are one of healthy and unhealthy, and wherein the set of actions include blocking, allowing, and allowing for a period of time before confirmation.

19 . The system of claim 15 , wherein the policies define microsegments on the network.

20 . The system of claim 15 , wherein the labeled network flows are internal workload communications.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2021
From: O'NEIL, JOHN H.; SMITH, PETER; KEISER, THOMAS EVAN, JR.
To: ZSCALER, INC.
Reel/Frame 056852/0287 →
Continuity (9)
Continuation In Part 17101383 · Nov 23, 2020
Continuation In Part 16587839 · Sep 30, 2019
Continuation In Part 16578175 · Sep 20, 2019
Continuation In Part 16214843 · Dec 10, 2018
Continuation 15899453 · Feb 20, 2018
Continuation 15883534 · Jan 30, 2018
Provisional Application 62459248 · Feb 15, 2017
Provisional Application 62457508 · Feb 10, 2017
Related Publication 20210344723A1 · Nov 4, 2021
References Cited (36)
US 6009475A · Shrader · 1999 [cited by applicant]
US 6138162A · Pistriotto et al. · 2000 [cited by applicant]
US 7316029B1 · Parker et al. · 2008 [cited by applicant]
US 7383569B1 · Elgressy et al. · 2008 [cited by applicant]
US 7620985B1 · Bush et al. · 2009 [cited by applicant]
US 8166533B2 · Yuan · 2012 [cited by applicant]
US 8499348B1 · Rubin · 2013 [cited by applicant]
US 8677471B2 · Karels et al. · 2014 [cited by applicant]
US 8856920B2 · Khan · 2014 [cited by examiner]
US 9773107B2 · White et al. · 2017 [cited by applicant]
US 9787639B1 · Sun · 2017 [cited by examiner]
US 10154067B2 · Smith et al. · 2018 [cited by applicant]
US 10212044B2 · Mermoud · 2019 [cited by examiner]
US 10348599B2 · O'Neil et al. · 2019 [cited by applicant]
US 10362048B2 · Alexander et al. · 2019 [cited by applicant]
US 10439985B2 · O'Neil · 2019 [cited by applicant]
US 10505899B1 · Singh et al. · 2019 [cited by applicant]
US 10956513B2 · Ahmed · 2021 [cited by examiner]
US 11128664B1 · Andersson · 2021 [cited by examiner]
US 20050193222A1 · Greene · 2005 [cited by applicant]
US 20060095970A1 · Rajagopal et al. · 2006 [cited by applicant]
US 20060129670A1 · Mayer · 2006 [cited by examiner]
US 20120137375A1 · Ramachandran · 2012 [cited by examiner]
US 20140282829A1 · Dabbiere · 2014 [cited by examiner]
US 20150326486A1 · Zawadowskiy · 2015 [cited by examiner]
US 20160359897A1 · Yadav · 2016 [cited by examiner]
US 20170078329A1 · Hwang et al. · 2017 [cited by applicant]
US 20170272465A1 · Steele · 2017 [cited by applicant]
US 20180041471A1 · Sudo et al. · 2018 [cited by applicant]
US 20190349283A1 · O'Neil et al. · 2019 [cited by applicant]
US 20200021618A1 · Smith et al. · 2020 [cited by applicant]
US 20240061388A1 · Ganju · 2024 [cited by examiner]
US 20240291831A1 · Tembey · 2024 [cited by examiner]
WO 2018152303A1 · 2018 [cited by applicant]
Aug. 13, 2019, International Preliminary Report on Patentability and Written Opinion for International Application No. PCT/US2018/015902. [cited by applicant]
Aug. 20, 2019, International Preliminary Report on Patentability and Written Opinion for International Application No. PCT/US2018/018325. [cited by applicant]