IP Library Granted Patent US 11,979,473
Granted Patent B2
US 11,979,473 · App. 18/122,354 · Granted May 7, 2024

Cloud access security broker systems and methods with an in-memory data store

Inventors: Abhishek Bathla (Panipat, IN); Kumar Gaurav (Cupertino, CA); Raman Madaan (Bengaluru, IN); Chakkaravarthy Periyasamy Balaiah (Sunnyvale, CA); Shweta Gupta (Chandigarh, IN)
Assignee: Zscaler, Inc.
H04L67/562G06F21/552G06F21/568H04L63/145H04L67/1095H04L67/563
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,979,473
App. No.
18/122,354
Filed
Mar 16, 2023
Granted
May 7, 2024
Kind
B2
Art Unit
2457
USPC
709/223
Abstract

A method performed by a Cloud Access Security Broker (CASB) service includes scanning data stored in one of a cloud provider and a Software-as-a-Service (SaaS) application, wherein the data is for a user associated with a company of a plurality of companies; detecting an incident in a file or email in the data during the scanning; maintaining details of the incident in an in-memory data store, including a current snapshot of the file or email; and providing a notification to the tenant of the incident. The method can further include, subsequent to the incident and while the file or email is being updated, updating the details of the incident in the in-memory data store.

Claims (39)

1. A method performed by a Cloud Access Security Broker (CASB) service, the method comprising steps of:

scanning data stored in one of a cloud provider and a Software-as-a-Service (SaaS) application, wherein the data is for a user associated with a company of a plurality of companies;

detecting an incident in a file or email in the data during the scanning;

maintaining details of the incident in an in-memory data store, including a current snapshot of the file or email; and

providing a notification to the tenant of the incident.

2. The method of claim 1 , wherein the steps further include:

subsequent to the incident and while the file or email is being updated, updating the details of the incident in the in-memory data store.

3. The method of claim 1 , wherein the incident is one of a Data Loss or Leakage Prevention (DLP) violation and malware.

4. The method of claim 1 , wherein the steps further include:

periodically storing records in the in-memory data store in a file for recovery.

5. The method of claim 1 , wherein the in-memory data store includes a multi-level hash for a record, for the incident.

6. The method of claim 5 , wherein the maintaining includes performing any of inserting, deleting, and updating the record, for the incident.

7. The method of claim 5 , wherein the multi-level hash include at least a hash based on the company and a hash based on an application name.

8. A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to implement a Cloud Access Security Broker (CASB) service, the CASB service comprising steps of:

scanning data stored in one of a cloud provider and a Software-as-a-Service (SaaS) application, wherein the data is for a user associated with a company of a plurality of companies;

detecting an incident in a file or email in the data during the scanning;

maintaining details of the incident in an in-memory data store, including a current snapshot of the file or email; and

providing a notification to the tenant of the incident.

9. The non-transitory computer-readable medium of claim 8 , wherein the steps further include:

subsequent to the incident and while the file or email is being updated, updating the details of the incident in the in-memory data store.

10. The non-transitory computer-readable medium of claim 8 , wherein the incident is one of a Data Loss or Leakage Prevention (DLP) violation and malware.

11. The non-transitory computer-readable medium of claim 8 , wherein the steps further include:

periodically storing records in the in-memory data store in a file for recovery.

12. The non-transitory computer-readable medium of claim 8 , wherein the in-memory data store includes a multi-level hash for a record, for the incident.

13. The non-transitory computer-readable medium of claim 12 , wherein the maintaining includes performing any of inserting, deleting, and updating the record, for the incident.

14. The non-transitory computer-readable medium of claim 12 , wherein the multi-level hash include at least a hash based on the company and a hash based on an application name.

15. A cloud-based system comprising:

a plurality of nodes communicatively coupled to one another, wherein the plurality of nodes include one or more processors configured to implement a Cloud Access Security Broker (CASB) service, where one or more nodes are configured to

scan data stored in one of a cloud provider and a Software-as-a-Service (SaaS) application, wherein the data is for a user associated with a company of a plurality of companies;

detect an incident in a file or email in the data during the scanning;

maintain details of the incident in an in-memory data store, including a current snapshot of the file or email; and

provide a notification to the tenant of the incident.

16. The cloud-based system of claim 15 , wherein one or more nodes are further configured to:

subsequent to the incident and while the file or email is being updated, update the details of the incident in the in-memory data store.

17. The cloud-based system of claim 15 , wherein the incident is one of a Data Loss or Leakage Prevention (DLP) violation and malware.

18. The cloud-based system of claim 15 , wherein one or more nodes are further configured to:

periodically storing records in the in-memory data store in a file for recovery.

19. The cloud-based system of claim 15 , wherein the in-memory data store includes a multi-level hash for a record, for the incident.

20. The cloud-based system of claim 19 , wherein the maintaining includes performing any of inserting, deleting, and updating the record, for the incident.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: BATHLA, ABHISHEK; GAURAV, KUMAR; MADAAN, RAMAN; BALAIAH, CHAKKARAVARTHY PERIYASAMY; GUPTA, SHWETA
To: ZSCALER, INC.
Reel/Frame 063002/0570 →
Priority Claims (1)
IN 202011035829 · Aug 20, 2020 · national
Continuity (2)
Continuation 17061704 · Oct 2, 2020
Related Publication 20230224377A1 · Jul 13, 2023
Cited By (1)
US 12,278,834