IP Library Granted Patent US 12,407,730
Granted Patent B2
US 12,407,730 · App. 18/127,681 · Granted Sep 2, 2025

Data security

Inventors: Ofer Ben-Noon (Tel Aviv, IL); Ohad Bobrov (Tel Aviv, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/57G06F16/955G06F21/44G06F21/53H04L41/16H04L63/0428H04L63/08H04L63/083H04L63/10H04L63/102H04L63/1416H04L63/1425H04L63/1433H04L63/20H04L67/125H04L67/55H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,730
App. No.
18/127,681
Filed
Mar 29, 2023
Granted
Sep 2, 2025
Kind
B2
Art Unit
2493
USPC
726/4
Abstract

A communications system for providing secure access to a digital resource of a group of digital resources accessible via a communications network, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the communications network, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.

Claims (26)

1. A communications system for providing secure access to a group of digital resources accessible via the internet, the system comprising:

a data processing hub accessible via an IP (internet protocol) address;

a plurality of user equipment (UEs) useable to communicate with websites via the internet, each of the plurality of UEs configured to have a cyber isolated secure environment (CISE) isolated from ambient software in the UE, and the CISE of each UE comprising a secure web browser (SWB) that the corresponding UE is required to use to access one or more of the group of digital resources; and

a security policy implemented to protect the group of digital resources, wherein the security policy is a function of characterizing features that characterize communications between websites and users who communicate with the websites using the UEs;

wherein the hub and each CISE are configured so that any one or more of the group of digital resources in motion and at rest in each CISE are visible to the hub and each CISE and each SWB monitors communications between its corresponding UE and a given website and vets the communications responsive to the security policy, wherein the SWB vets communications responsive to the security policy comprises the SWB processing at least one of the characterizing features using a neural network to estimate a risk of cyber damage to one or more of the group of digital resources associated with the communications and wherein if the estimated risk is greater than a predetermined threshold the hub and/or the SWB undertakes an action to mitigate the risk.

2. The communications system according to claim 1 wherein at least a first of the CISEs comprises at least one shared secure service that communicates with the corresponding SWB via a secure channel and is isolated from the ambient software.

3. The communications system according to claim 2 wherein the first CISE comprises at least one software application that communicates with the corresponding SWB via the secure channel, is wrapped to conform with security constraints defined by the security policy and is isolated from the ambient software.

4. The communications system according to claim 1 wherein the security policy is a function of a set of features characterizing at least the given website.

5. The communications system according to claim 4 wherein the security policy is a function of a URL associated with the given website.

6. The communications system according to claim 4 wherein the set of features comprises features characterizing a plurality of websites.

7. The communications system according to claim 4 wherein the hub processes monitored communications between two or more of the plurality of the UEs with the given website to determine features in the set of features characterizing the given website.

8. The communications system according to claim 7 wherein the security policy is a function of a set of features characterizing a user.

9. The communications system according to claim 8 wherein the hub and/or the SWB monitors interaction of the user with the SWB when operating the SWB to communicate with the given website to determine a feature of the set of features characterizing the user.

10. The communications system according to claim 9 wherein the hub and/or the SWB monitors interaction of at least one other user using a SWB in a UE of the plurality of UEs when operating the SWB to communicate with the given website to determine a feature of the set of features characterizing the user.

11. The communications system according to claim 9 wherein the hub and/or the SWB monitors browsing behavior of a plurality of users of the UEs to determine a feature of the set of features characterizing the user.

12. The communications system according to claim 11 wherein the CISE comprises a secure sandbox.

13. The communications system according to claim 12 wherein vetting communications responsive to the security policy comprises:

generating an emulation of the given website based on the set of features characterizing the given website;

generating an avatar of the user based on the set of features characterizing the user;

staging an interaction of the avatar and emulation in the sandbox; and

based on the staged interaction determining a probability of an interaction between the user and the given website resulting in cyber damage to one or more of the group of digital resources.

14. The communications system according to claim 1 wherein the security policy is a function of features characterizing metadata associated with communication sessions between the user and the given website.

15. The communications system according to claim 14 wherein the security policy is a function of features characterizing metadata associated with communication sessions between the user and at least one website other than the given website.

16. The communications system according to claim 15 wherein the security policy is a function of features characterizing metadata associated with communication sessions between at least one other user and the given website.

17. The communications system according to claim 16 wherein the security policy is a function of features characterizing metadata associated with communication sessions between the at least one other user and the at least one website other than the given website.

18. The communications system according to claim 1 wherein the security policy is a function of features characterizing a cyberattack landscape in which the UE is operating.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2025
From: TALON CYBER SECURITY LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 069993/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2023
From: BEN-NOON, OFER; BOBROV, OHAD; HARPAK, GUY; SALOMON, IDO; ROTH, GILAD
To: TALON CYBER SECURITY LTD.
Reel/Frame 063560/0233 →
Continuity (3)
Continuation PCTIL2022050416 · Apr 22, 2022
Provisional Application 63177998 · Apr 22, 2021
Related Publication 20230308451A1 · Sep 28, 2023
References Cited (91)
US 7698398B1 · Lai · 2010 [cited by examiner]
US 8069435B1 · Lai · 2011 [cited by examiner]
US 8132242B1 · Wu · 2012 [cited by examiner]
US 8151349B1 · Yee · 2012 [cited by examiner]
US 8346929B1 · Lai · 2013 [cited by examiner]
US 8607306B1 · Bridge et al. · 2013 [cited by applicant]
US 8752183B1 · Heiderich et al. · 2014 [cited by applicant]
US 9021254B2 · Bokarius et al. · 2015 [cited by applicant]
US 9032519B1 · Maher et al. · 2015 [cited by applicant]
US 9348663B1 · Boodman et al. · 2016 [cited by applicant]
US 9521032B1 · Worsley · 2016 [cited by applicant]
US 9547769B2 · Aissi · 2017 [cited by examiner]
US 9635041B1 · Warman · 2017 [cited by examiner]
US 9948612B1 · Jawahar · 2018 [cited by examiner]
US 10356693B2 · Reith · 2019 [cited by examiner]
US 10599486B1 · Borkar · 2020 [cited by examiner]
US 10798140B1 · Mercier · 2020 [cited by examiner]
US 10848571B2 · Fleck · 2020 [cited by examiner]
US 10855754B1 · Mercier · 2020 [cited by examiner]
US 10908785B2 · Borkar · 2021 [cited by examiner]
US 10963532B2 · Borkar · 2021 [cited by examiner]
US 11019066B2 · Borkar · 2021 [cited by examiner]
US 11061999B2 · Borkar · 2021 [cited by examiner]
US 11075984B1 · Mercier · 2021 [cited by examiner]
US 11087008B2 · Borkar · 2021 [cited by examiner]
US 11093570B2 · Chauhan · 2021 [cited by examiner]
US 11153285B2 · Chauhan · 2021 [cited by examiner]
US 11153306B2 · Chauhan · 2021 [cited by examiner]
US 11159552B2 · Fleck · 2021 [cited by examiner]
US 11233832B2 · Chauhan · 2022 [cited by examiner]
US 11265337B2 · Smelov · 2022 [cited by examiner]
US 11275811B2 · Borkar · 2022 [cited by examiner]
US 11323327B1 · Chitalia · 2022 [cited by examiner]
US 11328077B2 · Fleck · 2022 [cited by examiner]
US 11381610B2 · Le Strat · 2022 [cited by examiner]
US 11412003B1 · Lyon · 2022 [cited by examiner]
US 11429243B2 · Fleck · 2022 [cited by examiner]
US 11450069B2 · Chauhan · 2022 [cited by examiner]
US 11469979B2 · Chauhan · 2022 [cited by examiner]
US 11475146B2 · Chauhan · 2022 [cited by examiner]
US 12026711B2 · Lebel et al. · 2024 [cited by applicant]
US 20050044197A1 · Lai · 2005 [cited by examiner]
US 20080301794A1 · Lee · 2008 [cited by examiner]
US 20090138804A1 · Shepherd · 2009 [cited by examiner]
US 20090216910A1 · Duchesneau · 2009 [cited by examiner]
US 20100050244A1 · Tarkhanyan · 2010 [cited by examiner]
US 20120084184A1 · Raleigh · 2012 [cited by examiner]
US 20130297700A1 · Hayton · 2013 [cited by examiner]
US 20140237576A1 · Zhang et al. · 2014 [cited by applicant]
US 20150007291A1 · Miller · 2015 [cited by examiner]
US 20150113092A1 · Chadha · 2015 [cited by examiner]
US 20150201417A1 · Raleigh · 2015 [cited by examiner]
US 20150237049A1 · Grajek et al. · 2015 [cited by applicant]
US 20160261627A1 · Lin · 2016 [cited by examiner]
US 20170111322A1 · Patidar et al. · 2017 [cited by applicant]
US 20170118239A1 · Most et al. · 2017 [cited by applicant]
US 20170187839A1 · Raleigh · 2017 [cited by examiner]
US 20180359244A1 · Cockerill · 2018 [cited by examiner]
US 20190065177A1 · Khoongumjorn et al. · 2019 [cited by applicant]
US 20190261169A1 · Kamal et al. · 2019 [cited by applicant]
US 20200092382A1 · Borkar · 2020 [cited by examiner]
US 20200097614A1 · Borkar · 2020 [cited by examiner]
US 20200106842A1 · Chauhan · 2020 [cited by applicant]
US 20200177546A1 · Petry et al. · 2020 [cited by applicant]
US 20200296776A1 · Raleigh · 2020 [cited by examiner]
US 20210176336A1 · Fleck · 2021 [cited by examiner]
US 20210185015A1 · Sapp · 2021 [cited by examiner]
US 20220038282A1 · Teramoto · 2022 [cited by examiner]
US 20220094547A1 · Duchastel · 2022 [cited by examiner]
US 20220116345A1 · Xu · 2022 [cited by examiner]
US 20220217169A1 · Varanda · 2022 [cited by applicant]
US 20220366050A1 · Ben-Noon · 2022 [cited by examiner]
US 20220368689A1 · Ben-Noon et al. · 2022 [cited by applicant]
US 20230308451A1 · Ben-Noon · 2023 [cited by examiner]
JP 2016526201A · 2016 [cited by applicant]
KR 102038842 · 2019 [cited by applicant]
WO 0175564 · 2001 [cited by applicant]
WO 2014048751A1 · 2014 [cited by applicant]
WO 2022224262A1 · 2022 [cited by applicant]
“Azure AD Conditional Access Documention”, Microsoft Docs, (downloaded May 25, 2022) https://docs.microsoft.com/en-US/azure/active-directory/conditional-access/. [cited by applicant]
Barth A., et al., “The Security Architecture of the Chromium Browser” https://seclab.stanford.edu/websec/chromium/chromium-security-architecture.pdf. [cited by applicant]
International Search Report dated Aug. 12, 2022 for applicatiion No. PCT/IL2022/050416 filed Apr. 22, 2022. [cited by applicant]
International Preliminary Report on Patentability dated Aug. 8, 2023 for application No. PCT/IL2022/050416 filed Apr. 22, 2022. [cited by applicant]
JP Application No. 2023565437, Office Action mailed Nov. 12, 2024, 23 pages, including English translation. [cited by applicant]
U.S. Appl. No. 17/726,579, Non-Final Office Action mailed Apr. 25, 2024, 18 pages. [cited by applicant]
U.S. Appl. No. 17/726,579, Notice of Allowance mailed Oct. 28, 2024, 14 pages. [cited by applicant]
U.S. Appl. No. 17/841,727, Non-Final Office Action mailed May 8, 2024, 20 pages. [cited by applicant]
U.S. Appl. No. 17/893,226, Non-Final Office Action mailed Jul. 3, 2024, 11 pages. [cited by applicant]
U.S. Appl. No. 18/081,725, Non-Final Office Action mailed Oct. 23, 2024, 13 pages. [cited by applicant]
EP Application No. 22725568.4, Communication Pursuant to Article 94(3) EPC mailed May 9, 2025, 6 pages. [cited by applicant]
JP Application No. 2023565437, Office Action mailed May 20, 2025, 21 pages, including English translation. [cited by applicant]
Cited By (1)
US 12,665,907