IP Library › Granted Patent US 12,395,531
Granted Patent B2
US 12,395,531 · App. 17/949,522 · Granted Aug 19, 2025

Cloud access security broker user interface and analytics systems and methods

Inventor: Pooja Deshmukh (Sunnyvale, CA)
Assignee: Zscaler, Inc.
H04L63/20H04L63/1433H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,531
App. No.
17/949,522
Granted
Aug 19, 2025
Kind
B2
Abstract

Systems and methods include, providing a UI for a tenant to input one or more malware and DLP rules, and trusted user exceptions; responsive to a scan by the CASB system of a plurality of users associated with a tenant in a SaaS application where the scan includes identifying malware in content in the SaaS application and performing DLP in the content in the SaaS application based on the one or more malware and DLP rules and trusted user exceptions, maintaining records associated with a plurality of incidents for the malware and the DLP; and providing the UI for the tenant including an analytics view with a plurality of summary tiles including visualizations of the plurality of incidents for the malware and DLP for the tenant and a table listing any of the plurality of incidents for the malware and the DLP for the tenant.

Claims (38)

1. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming one or more processors associated with a Cloud Access Security Broker (CASB) system to perform steps of:

providing a User Interface (UI) for a tenant to input one or more malware and Data Loss Prevention (DLP) rules, and trusted user exceptions, wherein the trusted user exceptions identify one or more specific users and rule exceptions for the specific users;

responsive to a scan by the CASB system of a plurality of users associated with a tenant in a Software-as-a-Service (SaaS) application where the scan includes identifying malware in content in the SaaS application and performing DLP in the content in the SaaS application based on the one or more malware and DLP rules and trusted user exceptions, maintaining records associated with a plurality of incidents for the malware and the DLP; and

providing the UI for the tenant including an analytics view with a plurality of summary tiles including visualizations of the plurality of incidents for the malware and DLP for the tenant and a table listing any of the plurality of incidents for the malware and the DLP for the tenant, including any of unique data objects, unique users internal to the tenant, and unique external entities, associated with the plurality of incidents.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

performing remediation of the plurality of incidents.

3. The non-transitory computer-readable storage medium of claim 2 , wherein the remediation of the plurality of incidents includes granular remediation.

4. The non-transitory computer-readable storage medium of claim 2 , wherein the remediation of the plurality of incidents includes tombstoning one or more files for better user experience.

5. The non-transitory computer-readable storage medium of claim 1 , wherein a scheduler is configured to control historic and ongoing scans of content of the plurality of users.

6. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

providing the UI for the tenant to onboard a plurality of SaaS applications including the SaaS application.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

responsive to a selection of any entry in the table, providing a popup listing details associated with the corresponding incident.

8. A method comprising steps of:

providing a User Interface (UI) for a tenant to input one or more malware and Data Loss Prevention (DLP) rules, and trusted user exceptions, wherein the trusted user exceptions identify one or more specific users and rule exceptions for the specific users;

responsive to a scan by the CASB system of a plurality of users associated with a tenant in a Software-as-a-Service (SaaS) application where the scan includes identifying malware in content in the SaaS application and performing DLP in the content in the SaaS application based on the one or more malware and DLP rules and trusted user exceptions, maintaining records associated with a plurality of incidents for the malware and the DLP; and

providing the UI for the tenant including an analytics view with a plurality of summary tiles including visualizations of the plurality of incidents for the malware and DLP for the tenant and a table listing any of the plurality of incidents for the malware and the DLP for the tenant, including any of unique data objects, unique users internal to the tenant, and unique external entities, associated with the plurality of incidents.

9. The method of claim 8 , wherein the steps further include

performing remediation of the plurality of incidents.

10. The method of claim 9 , wherein the remediation of the plurality of incidents includes granular remediation.

11. The method of claim 9 , wherein the remediation of the plurality of incidents includes tombstoning one or more files for better user experience.

12. The method of claim 8 , wherein a scheduler is configured to control historic and ongoing scans of content of the plurality of users.

13. The method of claim 8 , wherein the steps further include

providing the UI for the tenant to onboard a plurality of SaaS applications including the SaaS application.

14. The method of claim 8 , wherein the steps further include

responsive to a selection of any entry in the table, providing a popup listing details associated with the corresponding incident.

15. A system associated with a Cloud Access Security Broker (CASB) system, comprising:

one or more processors and memory storing instructions that, when executed, cause the one or more processors to

provide a User Interface (UI) for a tenant to input one or more malware and Data Loss Prevention (DLP) rules, and trusted user exceptions, wherein the trusted user exceptions identify one or more specific users and rule exceptions for the specific users;

responsive to a scan by the CASB system of a plurality of users associated with a tenant in a Software-as-a-Service (SaaS) application where the scan includes identifying malware in content in the SaaS application and performing DLP in the content in the SaaS application based on the one or more malware and DLP rules and trusted user exceptions, maintain records associated with a plurality of incidents for the malware and the DLP; and

provide the UI for the tenant including an analytics view with a plurality of summary tiles including visualizations of the plurality of incidents for the malware and DLP for the tenant and a table listing any of the plurality of incidents for the malware and the DLP for the tenant, including any of unique data objects, unique users internal to the tenant, and unique external entities, associated with the plurality of incidents.

16. The system of claim 15 , wherein the instructions that, when executed, further cause the one or more processors to

perform remediation of the plurality of incidents.

17. The system of claim 16 , wherein the remediation of the plurality of incidents includes granular remediation.

18. The system of claim 16 , wherein the remediation of the plurality of incidents includes tombstoning one or more files for better user experience.

19. The system of claim 15 , wherein a scheduler is configured to control historic and ongoing scans of content of the plurality of users.

20. The system of claim 15 , wherein the instructions that, when executed, further cause the one or more processors to

responsive to a selection of any entry in the table, provide a popup listing details associated with the corresponding incident.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2022
From: DESHMUKH, POOJA
To: ZSCALER, INC.
Reel/Frame 061167/0832 →
Continuity (2)
Continuation In Part 16950136 · Nov 17, 2020
Related Publication 20230018809A1 · Jan 19, 2023
References Cited (14)
US 8185510B2 · Chaudhry et al. · 2012 [cited by applicant]
US 8429111B1 · Kailash et al. · 2013 [cited by applicant]
US 8869259B1 · Udupa et al. · 2014 [cited by applicant]
US 8887249B1 · Schekochikhin et al. · 2014 [cited by applicant]
US 9152789B2 · Natarajan et al. · 2015 [cited by applicant]
US 9154475B1 · Kailash et al. · 2015 [cited by applicant]
US 9473537B2 · Sinha et al. · 2016 [cited by applicant]
US 9609015B2 · Natarajan et al. · 2017 [cited by applicant]
US 10523710B2 · Sinha et al. · 2019 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by examiner]
US 20170372070A1 · Burdett · 2017 [cited by examiner]
US 20200259792A1 · Devarajan · 2020 [cited by examiner]
US 20200389496A1 · Xuan · 2020 [cited by examiner]
Tahboub et al., “Data Leakage/Loss Prevention Systems (DLP)”, Oct. 24, 2014, IEEE, 2014 World Congress on Computer Applications and Information Systems (WCCAIS) (2014, pp. 1-6) (Year: 2014). [cited by examiner]