IP Library Granted Patent US 12,244,613
Granted Patent B2
US 12,244,613 · App. 17/674,917 · Granted Mar 4, 2025

Maintaining dependencies in a set of rules for security scanning in could-based web applications and API protection

Inventor: Leslie Smith (San Jose, CA)
Assignee: Zscaler, Inc.
H04L63/1416H04L63/1425H04L63/1458H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,613
App. No.
17/674,917
Granted
Mar 4, 2025
Kind
B2
Abstract

Systems and methods include receiving a copy of a template file of security rules where the template file includes a plurality of rule tags and one or more dependency tags that define relationships and dependencies between any rules associated with the plurality of rule tags; scanning the template file including, for each respective rule tag of the plurality of rule tags checking if an enabled flag is set for the respective rule tag, when the enable flag is set, looking up a respective rule in a rule database and replacing the respective rule tag with the respective rule, and when the enable flag is not set, removing the respective rule tag from the template file; and providing an output file including a plurality of rules having the relationships and dependencies, where the output file is used for security scanning.

Claims (40)

1. A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

receiving a copy of a template file where the template file includes a plurality of rule tags and one or more dependency tags that define relationships and dependencies between any rules associated with the plurality of rule tags;

scanning the template file including, for each respective rule tag of the plurality of rule tags

checking if an enabled flag is set for the respective rule tag,

when the enable flag is set, looking up a respective rule in a rule database configured to enable an administrator to enable/disable rules based on the respective rule tag and replacing the respective rule tag with the respective rule text from the rule database, and

when the enable flag is not set, removing the respective rule tag from the template file;

providing an output file including a plurality of rules having the relationships and dependencies; and

utilizing the output file to provide a set of rules for performing security scanning via a cloud-based system.

2. The non-transitory computer-readable medium of claim 1 , wherein the steps further include

updating any of the rules in the rule database independently from updating the one or more dependency tags in the template file.

3. The non-transitory computer-readable medium of claim 2 , wherein the steps further include

repeating the scanning of the template file and providing an output file subsequent to the updating, wherein the output file provided subsequent to the updating includes a plurality of rules having the relationships and dependencies based on the updating.

4. The non-transitory computer-readable medium of claim 1 , wherein rules are stored in the rule database as strings.

5. The non-transitory computer-readable medium of claim 1 , wherein the rule database utilizes one of Postgres or MySQL to enable the storing and distribution of security rules.

6. The non-transitory computer-readable medium of claim 1 , wherein the output file defines functionality for any of cloud-based Web Application Firewalls (WAF), Deep Packet Inspection (DPI), Intrusion Prevention Systems (IPS), Cloud-based web application and API protection (WAAP), and Data Loss Prevention.

7. The non-transitory computer-readable medium of claim 1 , wherein the plurality of rules include detection of any of top ten OWASP web application security risks.

8. The non-transitory computer-readable medium of claim 1 , wherein the plurality of rules include anomaly detection, bot detection, Application Programming Interface (API) inspection rules, Denial of Service (DOS) detection rules, and customizable rules.

9. The non-transitory computer-readable medium of claim 1 , wherein the steps further include

updating the plurality of rules based on monitoring of other users in a cloud-based system.

10. The non-transitory computer-readable medium of claim 1 , wherein the plurality of rules include a combination of user-defined rules and pre-defined rules.

11. A method comprising steps of:

receiving a copy of a template file where the template file includes a plurality of rule tags and one or more dependency tags that define relationships and dependencies between any rules associated with the plurality of rule tags;

scanning the template file including, for each respective rule tag of the plurality of rule tags

checking if an enabled flag is set for the respective rule tag,

when the enable flag is set, looking up a respective rule in a rule database configured to enable an administrator to enable/disable rules based on the respective rule tag and replacing the respective rule tag with the respective rule text from the rule database, and

when the enable flag is not set, removing the respective rule tag from the template file;

providing an output file including a plurality of rules having the relationships and dependencies; and

utilizing the output file to provide a set of rules for performing security scanning via a cloud-based system.

12. The method of claim 11 , wherein the steps further include

updating any of the rules in the rule database independently from updating the one or more dependency tags in the template file.

13. The method of claim 12 , wherein the steps further include

repeating the scanning of the template file and providing an output file subsequent to the updating, wherein the output file provided subsequent to the updating includes a plurality of rules based on the updating.

14. The method of claim 11 , wherein rules are stored in the rule database as strings.

15. The method of claim 11 , wherein the rule database utilizes one of Postgres or MySQL.

16. The method of claim 11 , wherein the output file defines functionality for any of cloud-based Web Application Firewalls (WAF), Deep Packet Inspection (DPI), Intrusion Prevention Systems (IPS), Cloud-based web application and API protection (WAAP), and Data Loss Prevention.

17. The method of claim 11 , wherein the plurality of rules include detection of any of top ten OWASP web application security risks.

18. The method of claim 11 , wherein the plurality of rules include anomaly detection, bot detection, Application Programming Interface (API) inspection rules, Denial of Service (DOS) detection rules, and customizable rules.

19. The method of claim 11 , wherein the steps further include

updating the plurality of rules based on monitoring of other users in a cloud-based system.

20. The method of claim 11 , wherein the plurality of rules include a combination of user-defined rules and pre-defined rules.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2022
From: SMITH, LESLIE
To: ZSCALER, INC.
Reel/Frame 059043/0254 →
Continuity (2)
Continuation In Part 17367760 · Jul 6, 2021
Related Publication 20230015603A1 · Jan 19, 2023
References Cited (25)
US 6636923B1 · Meirsman et al. · 2003 [cited by applicant]
US 7516412B1 · de Waal · 2009 [cited by examiner]
US 7668953B1 · Sinclair · 2010 [cited by examiner]
US 8869259B1 · Udupa et al. · 2014 [cited by applicant]
US 11256557B1 · Amin · 2022 [cited by examiner]
US 20020049961A1 · Fang · 2002 [cited by examiner]
US 20030142672A1 · Chen · 2003 [cited by examiner]
US 20050228798A1 · Shepard · 2005 [cited by examiner]
US 20060074618A1 · Miller et al. · 2006 [cited by applicant]
US 20070042756A1 · Perfetto et al. · 2007 [cited by applicant]
US 20080307519A1 · Curcio · 2008 [cited by applicant]
US 20090129271A1 · Ramankutty et al. · 2009 [cited by applicant]
US 20110296486A1 · Burch et al. · 2011 [cited by applicant]
US 20110310899A1 · Alkhatib et al. · 2011 [cited by applicant]
US 20120023325A1 · Lai · 2012 [cited by applicant]
US 20120185913A1 · Martinez et al. · 2012 [cited by applicant]
US 20120281708A1 · Chauhan et al. · 2012 [cited by applicant]
US 20130347072A1 · Dinha · 2013 [cited by applicant]
US 20140022586A1 · Zehler · 2014 [cited by applicant]
US 20140282817A1 · Singer et al. · 2014 [cited by applicant]
US 20170366455A1 · Pongracz · 2017 [cited by examiner]
US 20210248556A1 · Venkatraman · 2021 [cited by examiner]
WO WO2004095784A2 · 2004 [cited by examiner]
J. R. Vic Winkler, “Securing the Cloud: Cloud Computer Security Techniques and Tactics”, May 2011, Syngress Publishing, Full Text. [cited by applicant]
Stephen R. Smoot, “Private Cloud Computing: Consolidation, Virtualization, and Service-Oriented Infrastructure”, Oct. 2011, Morgan Kaufman Publishers, Inc. Full Text. [cited by applicant]