IP Library Granted Patent US 12,592,930
Granted Patent B2
US 12,592,930 · App. 18/098,464 · Granted Mar 31, 2026

Generating zero-trust policy for application access based on sequence-based application segmentation

Inventors: Chenhui Hu (Lexington, MA); Devesh Solanki (Mohali, IN); Gaurav Garg (Bengaluru, IN); Shikhar Omar (Bengaluru, IN); Raimi Shah (Austin, TX); Dianhuan Lin (Sunnyvale, CA); Rex Shang (Los Altos, CA); Howie Xu (Palo Alto, CA)
Assignee: Zscaler, Inc.
H04L63/104H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,930
App. No.
18/098,464
Granted
Mar 31, 2026
Kind
B2
Abstract

Systems and methods include obtaining log data for a plurality of users of an enterprise where the log data relates to usage of a plurality of applications by the plurality of users and user metadata; analyzing the log data to determine one or more sequential patterns of application access; determining i) app-segments that are groupings of application of the plurality of applications and ii) user-groups that are groupings of users of the plurality of users, based on the log data and the one or more sequential patterns of application access; and providing access policy of the plurality of applications based on the user-groups and the app-segments. The one or more sequential patterns of application access include a sequence of accessing a plurality of applications in a given time period.

Claims (32)

1 . A non-transitory computer-readable storage medium having computer readable code stored thereon for programming at least one processor to perform steps of:

obtaining log data for a plurality of users of an enterprise where the log data relates to usage of a plurality of applications by the plurality of users and user metadata;

analyzing the log data to determine one or more sequential patterns of ordered transitions of application access;

determining i) app-segments that are groupings of application of the plurality of applications and ii) user-groups that are groupings of users of the plurality of users, based on the log data and the one or more sequential patterns of application access, wherein the sequential patterns are used to compute transition probabilities or transition-likelihood metrics between applications to infer application similarity and correlated user roles; and

providing access policy of the plurality of applications based on the user-groups and the app-segments.

2 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

monitoring the access policy over time based on ongoing log data, manual verification of the access policy defining human intervention for refining of the policy, and incidents where users are prevented from accessing any application; and

adjusting any of the determined app-segments and the user-groups, based on the monitoring.

3 . The non-transitory computer-readable storage medium of claim 1 , wherein the one or more sequential patterns of application access include a sequence of accessing a plurality of applications in a given time period and are configured to define a role of the user and a similarity between the applications.

4 . The non-transitory computer-readable storage medium of claim 1 , wherein the usage of the plurality of applications by the plurality of users is via wildcard rules allowing a large subset of users to access the plurality of applications.

5 . The non-transitory computer-readable storage medium of claim 4 , wherein the access policy of the plurality of applications has less access than via the wildcard rules.

6 . The non-transitory computer-readable storage medium of claim 1 , wherein the log data and the one or more sequential patterns of application access is transformed to feature vectors, and wherein the determining includes clustering with the feature vectors.

7 . The non-transitory computer-readable storage medium of claim 1 , wherein the log data is obtained over a period of time and the determining and providing is performed over the period of time until the access policy meets a quality threshold.

8 . The non-transitory computer-readable storage medium of claim 1 , wherein the enterprise is an existing customer of a cloud service and the access policy is for one of existing applications and new applications, and wherein the determining is based on a similarity metric with existing user-groups.

9 . The non-transitory computer-readable storage medium of claim 1 , wherein the enterprise is a new customer of a cloud service, and wherein the determining is based on clustering to determine the user-groups and the app-segments.

10 . The non-transitory computer-readable storage medium of claim 9 , wherein user-groups are fixed to determine the app-segments.

11 . The non-transitory computer-readable storage medium of claim 1 , wherein the access policy includes which user-groups can access which app-segments on which ports.

12 . The non-transitory computer-readable storage medium of claim 1 , wherein the determining is via a machine learning model that uses features including any of port and protocol usage pattern; the computer process that initiated the connection to the application; similarity based on domain names; Internet Protocol (IP) address; an organization's network addressing structure; app location; user location; job title; department; manager; and behavior patterns.

13 . The non-transitory computer-readable storage medium of claim 12 , wherein the machine learning model includes an ensemble of different models.

14 . A method comprising steps of:

obtaining log data for a plurality of users of an enterprise where the log data relates to usage of a plurality of applications by the plurality of users and user metadata;

analyzing the log data to determine one or more sequential patterns of ordered transitions of application access;

determining i) app-segments that are groupings of application of the plurality of applications and ii) user-groups that are groupings of users of the plurality of users, based on the log data and the one or more sequential patterns of application access, wherein the sequential patterns are used to compute transition probabilities or transition-likelihood metrics between applications to infer application similarity and correlated user roles; and

providing access policy of the plurality of applications based on the user-groups and the app-segments.

15 . The method of claim 14 , wherein the steps further include

monitoring the access policy over time based on ongoing log data, manual verification of the access policy, and incidents where users are prevented from accessing any application; and

adjusting any of the determined app-segments and the user-groups, based on the monitoring.

16 . The method of claim 14 , wherein the one or more sequential patterns of application access include a sequence of accessing a plurality of applications in a given time period.

17 . The method of claim 14 , wherein the usage of the plurality of applications by the plurality of users is via wildcard rules allowing a large subset of users to access the plurality of applications.

18 . The method of claim 14 , wherein the log data and the one or more sequential patterns of application access is transformed to feature vectors, and wherein the determining includes clustering with the feature vectors.

19 . The method of claim 14 , wherein the log data is obtained over a period of time and the determining and providing is performed over the period of time until the access policy meets a quality threshold.

20 . The method of claim 14 , wherein the enterprise is an existing customer of a cloud service and the access policy is for one of existing applications and new applications, and wherein the determining is based on a similarity metric with existing user-groups.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2023
From: HU, CHENHUI; SOLANKI, DEVESH; GARG, GAURAV; OMAR, SHIKHAR; SHAH, RAIMI; LIN, DIANHUAN; SHANG, REX; XU, HOWIE
To: ZSCALER, INC.
Reel/Frame 062412/0055 →
Priority Claims (2)
IN 202214042160 · Jul 22, 2022 · national
IN 202211061820 · Oct 31, 2022 · national
Continuity (2)
Continuation In Part 17499942 · Oct 13, 2021
Related Publication 20230254318A1 · Aug 10, 2023
References Cited (57)
US 6009475A · Shrader · 1999 [cited by applicant]
US 6138162A · Pistriotto et al. · 2000 [cited by applicant]
US 7316029B1 · Parker et al. · 2008 [cited by applicant]
US 7350229B1 · Lander · 2008 [cited by examiner]
US 7383569B1 · Elgressy et al. · 2008 [cited by applicant]
US 7620985B1 · Bush et al. · 2009 [cited by applicant]
US 7647318B1 · Enns · 2010 [cited by examiner]
US 8166533B2 · Yuan · 2012 [cited by applicant]
US 8499348B1 · Rubin · 2013 [cited by applicant]
US 8677471B2 · Karels et al. · 2014 [cited by applicant]
US 9065850B1 · Sobrier · 2015 [cited by applicant]
US 9152789B2 · Natarajan et al. · 2015 [cited by applicant]
US 9773107B2 · White et al. · 2017 [cited by applicant]
US 10142362B2 · Weith et al. · 2018 [cited by applicant]
US 10154067B2 · Smith et al. · 2018 [cited by applicant]
US 10348599B2 · O'Neil et al. · 2019 [cited by applicant]
US 10362048B2 · Alexander et al. · 2019 [cited by applicant]
US 10419477B2 · Desai et al. · 2019 [cited by applicant]
US 10439985B2 · O'Neil · 2019 [cited by applicant]
US 10498605B2 · Weith et al. · 2019 [cited by applicant]
US 10505899B1 · Singh et al. · 2019 [cited by applicant]
US 11381603B2 · Kirner · 2022 [cited by examiner]
US 20050193222A1 · Greene · 2005 [cited by applicant]
US 20060095970A1 · Rajagopal et al. · 2006 [cited by applicant]
US 20060117390A1 · Shrivastava · 2006 [cited by examiner]
US 20070233477A1 · Halowani et al. · 2007 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20120246098A1 · Chari · 2012 [cited by examiner]
US 20140095894A1 · Barton · 2014 [cited by examiner]
US 20150242486A1 · Chari · 2015 [cited by examiner]
US 20160344770A1 · Verma et al. · 2016 [cited by applicant]
US 20170063886A1 · Muddu et al. · 2017 [cited by applicant]
US 20170078329A1 · Hwang et al. · 2017 [cited by applicant]
US 20170272465A1 · Steele · 2017 [cited by applicant]
US 20180041471A1 · Sudo et al. · 2018 [cited by applicant]
US 20180150758A1 · Niininen et al. · 2018 [cited by applicant]
US 20180293381A1 · Tseng et al. · 2018 [cited by applicant]
US 20190158513A1 · Shtar · 2019 [cited by examiner]
US 20190163929A1 · Miller · 2019 [cited by examiner]
US 20190281073A1 · Weith et al. · 2019 [cited by applicant]
US 20190318100A1 · Bhatia · 2019 [cited by examiner]
US 20190319972A1 · Desai · 2019 [cited by applicant]
US 20190349283A1 · O'Neil et al. · 2019 [cited by applicant]
US 20200021618A1 · Smith et al. · 2020 [cited by applicant]
US 20200236112A1 · Pularikkal et al. · 2020 [cited by applicant]
US 20200252405A1 · Sankavaram · 2020 [cited by examiner]
US 20200387956A1 · Toh · 2020 [cited by examiner]
US 20210168150A1 · Ross · 2021 [cited by examiner]
US 20210248053A1 · Wei · 2021 [cited by examiner]
WO 2018053337A1 · 2018 [cited by applicant]
WO 2018152303A1 · 2018 [cited by applicant]
Jordaney, Roberto, et al., “Transcend: Detecting concept drift in malware classification models,” 26th {USENIX} Security Symposium ({USENIX} Security 17), 2017. [cited by applicant]
Kantchelian, Alex, J. D. Tygar, and Anthony Joseph, “Evasion and hardening of tree ensemble classifiers,” International Conference on Machine Learning, 2016. [cited by applicant]
Tolomei, Gabriele, et al., “Interpretable predictions of tree-based ensembles via actionable feature tweaking,” Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. ACM, 20… [cited by applicant]
Aug. 13, 2019, International Preliminary Report on Patentability and Written Opinion for International Application No. PCT/US2018/015902. [cited by applicant]
Aug. 20, 2019, International Preliminary Report on Patentability and Written Opinion for International Application No. PCT/US2018/018325. [cited by applicant]
Feb. 28, 2023, European Search Report for European Patent Application No. 22 18 7223. [cited by applicant]