IP Library Granted Patent US 12,309,203
Granted Patent B2
US 12,309,203 · App. 17/863,531 · Granted May 20, 2025

Statistical network application security policy generation

Inventor: John O'Neil (Watertown, MA)
Assignee: Zscaler, Inc.
H04L63/20G06N5/04G06N20/00H04L41/0894H04L41/16H04L47/20H04L47/2483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,203
App. No.
17/863,531
Granted
May 20, 2025
Kind
B2
Abstract

Embodiments of the present invention generate network communication policies by applying machine learning to existing network communications, and without using information that labels such communications as healthy or unhealthy. The resulting policies may be used to validate communication between applications (or services) over a network.

Claims (33)

1. A method performed by at least one computer processor executing computer program instructions stored in at least one non-transitory computer-readable medium, the method comprising:

collecting network communication information and flow data from at least one computer systems operating on a network, wherein the flow data defines data representing a flow for the computer program instructions;

storing the network communication information and flow data collected from the computer systems operating on the network;

creating policies for a network communication model by applying Machine Learning (ML) to the stored information and flow data;

producing match data containing a plurality of match objects, wherein each of the match objects represents a first flow object and a second flow object in the flow data, the first flow object representing a first end of an application-to-application communication; and the second flow object representing a second end of the application-to-application communication; and

updating the policies for the network communication model based on the match data via a communication model generator.

2. The method of claim 1 , wherein the computer systems is a device or software application that is addressable over an Internet Protocol (IP) network.

3. The method of claim 1 , wherein some or all of the network communication information is transmitted to a remote server disposed between a source and a destination.

4. The method of claim 1 , wherein the plurality of match objects do not include labels labeling communications as healthy or unhealthy.

5. The method of claim 1 , wherein the communication information includes identifying information about applications that communicate with each other over a network collected with a network information collection agent.

6. The method of claim 1 , wherein the communication information includes network communication information collected at the source and the destination computer system collected with the network information collection agent.

7. The method of claim 1 , wherein creating the policies for the network communication model utilizes an unsupervised decision tree.

8. The method of claim 1 , wherein creating the policies for the network communication model utilizes frequent itemset discovery.

9. The method of claim 1 , wherein creating the policies for the network communication model utilizes one of a greedy algorithm and a stochastic optimization model.

10. A system comprising:

at least one processor; and

memory having computer program instructions stored thereon, the computer program instructions being executable by the at least one processor to:

collect network communication information and flow data from at least one computer systems operating on a network, wherein the flow data defines data representing a flow for the computer program instructions;

store the network communication information and flow data collected from the computer systems operating on the network; and

create policies for a network communication model by applying Machine Learning (ML) to the stored information and flow data;

produce match data containing a plurality of match objects, wherein each of the match objects represents a first flow object and a second flow object in the flow data, the first flow object representing a first end of an application-to-application communication, and the second flow object representing a second end of the application-to-application communication; and

update the policies for the network communication model based on the match data via a communication model generator.

11. The system of claim 10 , wherein the computer systems is a device or software application that is addressable over an Internet Protocol (IP) network.

12. The system of claim 10 , wherein some or all of the network communication information is transmitted to a remote server.

13. The system of claim 10 , wherein the computer program instructions further cause the processor to:

produce match data containing a plurality of match objects, wherein each of the match objects represents a pair of flow objects in the flow data, representing opposite ends of a network communication; and

create the policies for the network communication model based on the match data.

14. The system of claim 13 , wherein the plurality of match objects do not include labels labeling communications as healthy or unhealthy.

15. The system of claim 10 , wherein the communication information includes information about applications that communicate with each other over a network.

16. The system of claim 10 , wherein the communication information includes network communication information collected at a source and a destination computer system.

17. The system of claim 10 , wherein creating the policies for the network communication model utilizes an unsupervised decision tree.

18. The system of claim 10 , wherein creating the policies for the network communication model utilizes frequent itemset discovery.

19. The system of claim 10 , wherein creating the policies for the network communication model utilizes one of a greedy algorithm and a stochastic optimization model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2022
From: O'NEIL, JOHN
To: ZSCALER, INC.
Reel/Frame 060492/0276 →
Continuity (3)
Continuation 16898006 · Jun 10, 2020
Provisional Application 62859627 · Jun 10, 2019
Related Publication 20220353299A1 · Nov 3, 2022
References Cited (14)
US 8682812B1 · Ranjan · 2014 [cited by applicant]
US 10154067B2 · Smith et al. · 2018 [cited by applicant]
US 10439985B2 · O'Neil · 2019 [cited by applicant]
US 20130107715A1 · Szabo et al. · 2013 [cited by applicant]
US 20180103888A1 · Cogill · 2018 [cited by examiner]
US 20180234385A1 · O'Neil · 2018 [cited by applicant]
US 20190294995A1 · Pastor Perales et al. · 2019 [cited by applicant]
US 20190349283A1 · O'Neil et al. · 2019 [cited by applicant]
US 20200021618A1 · Smith et al. · 2020 [cited by applicant]
US 20200328978A1 · Gupta · 2020 [cited by examiner]
US 20200366559A1 · Parvataneni · 2020 [cited by examiner]
US 20200366717A1 · Chaubey · 2020 [cited by applicant]
US 20210367871A1 · Musa · 2021 [cited by applicant]
WO 2018152303A1 · 2018 [cited by applicant]