IP Library Granted Patent US 12,341,794
Granted Patent B2
US 12,341,794 · App. 17/979,439 · Granted Jun 24, 2025

Automated estimation of network security policy risk

Inventors: John O'Neil (Watertown, MA); Michael J. Melson (Arlington, VA)
Assignee: Zscaler, Inc.
H04L63/1425H04L41/142H04L41/145H04L61/5007
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,794
App. No.
17/979,439
Granted
Jun 24, 2025
Kind
B2
Abstract

A computer system automatically tests a network communication model by predicting whether particular traffic (whether actual or simulated) should be allowed on the network, and then estimating the accuracy of the network communication model based on the prediction. Such an estimate may be generated even before the model has been applied to traffic on the network. For example, steps can include observing positive data associated with a network; generating a network communication model based on the positive data; generating negative data based on the network communication model; calculating a precision of the network communication model based on the network communication model and the negative data; and calculating an accuracy of the network communication model based on one or more of the precision of the network communication model, or the network communication model and the positive data.

Claims (40)

1. A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

collecting and storing positive data associated with real observed communications over a network;

generating a network communication model based on the positive data;

generating negative data based on the network communication model, the negative data representing traffic that the network communication model should not allow, wherein the negative data is generated by collecting all unique pairs from the observed positive data, and generating a plurality of new unique pairs which do not exist in the network communication model, and wherein a unique pair represents a connection between a source host and application and a destination host and application;

calculating a precision of the network communication model based on the network communication model and the negative data; and

calculating an accuracy of the network communication model based on one or more of the precision of the network communication model, or the network communication model and the positive data.

2. The non-transitory computer-readable medium of claim 1 , wherein the negative data is generated to represent negative data that could be observed on the network.

3. The non-transitory computer-readable medium of claim 1 , wherein the negative data is generated based on all of the received positive data, or a portion of the received positive data.

4. The non-transitory computer-readable medium of claim 1 , wherein the network communication model is generated based on positive flow match data representing some or all of observed communications data observed on the network, and wherein observed communications data includes, for each of the plurality of observed communications: data representing a source application of the observed communication, data representing a destination application of the observed communication, data representing a local Internet Protocol (IP) address of the observed communication, and data representing a remote IP address of the observed communication.

5. The non-transitory computer-readable medium of claim 1 , wherein an initial set of negative data is generated, and wherein a subset of the initial negative data is used for the calculating.

6. The non-transitory computer-readable medium of claim 1 , wherein the instructions further cause the one or more processors to perform steps of:

calculating a value of recall for the network communication model; and

calculating the accuracy of the network communication model based on the recall, or based on a combination of the precision and the recall.

7. A method comprising steps of:

collecting and storing positive data associated with real observed communications over a network;

generating a network communication model based on the positive data;

generating negative data based on the network communication model, the negative data representing traffic that the network communication model should not allow, wherein the negative data is generated by collecting all unique pairs from the observed positive data, and generating a plurality of new unique pairs which do not exist in the network communication model, and wherein a unique pair represents a connection between a source host and application and a destination host and application;

calculating a precision of the network communication model based on the network communication model and the negative data; and

calculating an accuracy of the network communication model based on one or more of the precision of the network communication model, or the network communication model and the positive data.

8. The method of claim 7 , wherein the negative data is generated to represent negative data that could be observed on the network.

9. The method of claim 7 , wherein the negative data is generated based on all of the received positive data, or a portion of the received positive data.

10. The method of claim 7 , wherein the network communication model is generated based on positive flow match data representing some or all of observed communications data observed on the network, and wherein observed communications data includes, for each of the plurality of observed communications: data representing a source application of the observed communication, data representing a destination application of the observed communication, data representing a local Internet Protocol (IP) address of the observed communication, and data representing a remote IP address of the observed communication.

11. The method of claim 7 , wherein an initial set of negative data is generated, and wherein a subset of the initial negative data is used for the calculating.

12. The method of claim 7 , further comprising the steps of:

calculating a value of recall for the network communication model; and

calculating the accuracy of the network communication model based on the recall, or based on a combination of the precision and the recall.

13. A system comprising:

one or more processors; and

memory storing computer-executable instructions that, when executed, cause the one or more processors to:

collect and store positive data associated with real observed communications over a network;

generate a network communication model based on the positive data;

generate negative data based on the network communication model, the negative data representing traffic that the network communication model should not allow, wherein the negative data is generated by collecting all unique pairs from the observed positive data, and generating a plurality of new unique pairs which do not exist in the network communication model, and wherein a unique pair represents a connection between a source host and application and a destination host and application;

calculate a precision of the network communication model based on the network communication model and the negative data; and

calculate an accuracy of the network communication model based on one or more of the precision of the network communication model, or the network communication model and the positive data.

14. The system of claim 13 , wherein the negative data is generated to represent negative data that could be observed on the network.

15. The system of claim 13 , wherein the negative data is generated based on all of the received positive data, or a portion of the received positive data.

16. The system of claim 13 , wherein the network communication model is generated based on positive flow match data representing some or all of observed communications data observed on the network, and wherein observed communications data includes, for each of the plurality of observed communications: data representing a source application of the observed communication, data representing a destination application of the observed communication, data representing a local Internet Protocol (IP) address of the observed communication, and data representing a remote IP address of the observed communication.

17. The system of claim 13 , further comprising the steps of:

calculating a value of recall for the network communication model; and

calculating the accuracy of the network communication model based on the recall, or based on a combination of the precision and the recall.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2022
From: O'NEIL, JOHN; MELSON, MICHAEL J.
To: ZSCALER, INC.
Reel/Frame 061634/0391 →
Continuity (3)
Continuation 16898760 · Jun 11, 2020
Provisional Application 62860094 · Jun 11, 2019
Related Publication 20230056212A1 · Feb 23, 2023
References Cited (44)
US 6914905B1 · Yip · 2005 [cited by examiner]
US 7664879B2 · Chan · 2010 [cited by examiner]
US 7725934B2 · Kumar · 2010 [cited by examiner]
US 7962582B2 · Potti · 2011 [cited by examiner]
US 8010085B2 · Apte · 2011 [cited by examiner]
US 8464335B1 · Sinha · 2013 [cited by examiner]
US 8656154B1 · Kailash · 2014 [cited by examiner]
US 8868757B1 · Liu · 2014 [cited by examiner]
US 8869259B1 · Udupa · 2014 [cited by examiner]
US 8869262B2 · Mullick · 2014 [cited by examiner]
US 8955091B2 · Kailash · 2015 [cited by examiner]
US 9065800B2 · Devarajan · 2015 [cited by examiner]
US 9100424B1 · Thomas · 2015 [cited by examiner]
US 9124586B2 · Randriamasy · 2015 [cited by examiner]
US 9344393B2 · Boynton · 2016 [cited by examiner]
US 9531758B2 · Devarajan · 2016 [cited by examiner]
US 9654507B2 · Gangadharappa · 2017 [cited by examiner]
US 9712486B2 · Johnson · 2017 [cited by examiner]
US 9882767B1 · Foxhoven · 2018 [cited by examiner]
US 9935955B2 · Desai · 2018 [cited by examiner]
US 10044719B2 · Desai · 2018 [cited by examiner]
US 10091169B2 · Cohen · 2018 [cited by examiner]
US 10142362B2 · Weith · 2018 [cited by examiner]
US 10154067B2 · Smith · 2018 [cited by examiner]
US 10313397B2 · Komu · 2019 [cited by examiner]
US 10333988B2 · Porras · 2019 [cited by examiner]
US 10439985B2 · O'Neil · 2019 [cited by examiner]
US 10637724B2 · Johnson · 2020 [cited by examiner]
US 20020091921A1 · Kunzinger · 2002 [cited by examiner]
US 20030028616A1 · Aoki · 2003 [cited by examiner]
US 20050088977A1 · Roch · 2005 [cited by examiner]
US 20120255036A1 · Kidder · 2012 [cited by examiner]
US 20140026206A1 · Pazhyannur · 2014 [cited by examiner]
US 20140259093A1 · Narayanaswamy · 2014 [cited by examiner]
US 20170054594A1 · Decenzo · 2017 [cited by examiner]
US 20170244737A1 · Kuperman · 2017 [cited by examiner]
US 20180309795A1 · Ithal · 2018 [cited by examiner]
US 20180316723A1 · Murgia · 2018 [cited by examiner]
US 20180359323A1 · Madden · 2018 [cited by examiner]
US 20190349283A1 · O'Neil · 2019 [cited by examiner]
US 20200021618A1 · Smith · 2020 [cited by examiner]
US 20200112487A1 · Inamdar · 2020 [cited by examiner]
US 20200322357A1 · Bryan · 2020 [cited by examiner]
WO 2018152303A1 · 2018 [cited by applicant]