IP Library › Granted Patent US 12,634,349
Granted Patent B2
US 12,634,349 · App. 18/508,150 · Granted May 19, 2026

Systems and methods for abnormal Classless Inter-Domain Routing (CIDR) access detection

Inventors: Jonathan Assayag (Ofaqim, IL); Shoham Danino (Tel-Aviv, IL)
Assignee: Zscaler, Inc.
H04L63/20H04L63/0236H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,349
App. No.
18/508,150
Granted
May 19, 2026
Kind
B2
Abstract

Systems and methods for abnormal Classless Inter-Domain Routing (CIDR) access detection. The present systems and methods are configured to perform the steps of scanning one or more security groups associated with a cloud environment; assigning a score to one or more Classless Inter-Domain Routing (CIDR) groups within the one or more security groups; and providing one or more suggested actions based on the score of the one or more CIDR groups.

Claims (34)

1 . A method executed by one or more processors of a cloud-based security system, the method comprising steps of:

automatically scanning, by retrieving via cloud provider application programming interfaces (APIs), one or more security group rules, access control lists, and routing table configurations associated with a cloud environment;

determining, for each of one or more Classless Inter-Domain Routing (CIDR) groups within the one or more security groups, a score based on a plurality of weighted categories, the categories including at least one of Internet Protocol (IP) reputation, geo-location, public exposure of an associated compute instance, vulnerability information, or exclusion of Internet Protocol (IP) addresses contained in a customer-defined allow list;

assigning the calculated score to each of the one or more CIDR groups; and

providing, via a user interface connected to the cloud-based security system, one or more suggested actions based on the score of the one or more CIDR groups, the one or more suggested actions comprising automatically modifying or removing a security group rule permitting access from a CIDR group having a score above a predefined threshold.

2 . The method of claim 1 , wherein the one or more suggested actions include removing a specific CIDR from a security group rule by issuing an update to the cloud provider API.

3 . The method of claim 2 , wherein suggesting the removal of the CIDR is based on the CIDR's score exceeding a predefined threshold and the CIDR not being included in a customer-defined allow list.

4 . The method of claim 1 , wherein the steps comprise:

calculating a score for each of the one or more CIDR groups within the one or more security groups based on analysis of associated access control lists (ACLs) and routing table configurations; and

assigning the calculated score to each of the one or more CIDR groups.

5 . The method of claim 4 , wherein each of the CIDR groups include one or more Internet Protocol (IP) addresses, and wherein the score is based on a risk associated with each of the IP addresses, the risk being determined from flow log data including traffic amount, session length, or session times.

6 . The method of claim 5 , wherein IP addresses in a customer allow list are excluded when calculating the score, the customer allow list being configurable via the user interface of the cloud-based security system.

7 . The method of claim 5 , wherein the score is based on a plurality of categories, wherein each of the categories is assigned a weight and a category score, the categories including at least one of: (i) Internet Protocol reputation, (ii) vulnerability severity of associated compute instances, or (iii) public exposure state of an instance.

8 . The method of claim 7 , wherein each of the categories include a plurality of parameters, the parameters determining the category score assigned to each of the categories, the parameters including at least one of: TOR network detection, VPN detection, or geolocation rarity of an Internet Protocol address.

9 . The method of claim 1 , wherein the steps further comprise:

performing the one or more suggested actions automatically including automatically disabling or modifying a security group rule in response to detection of a CIDR group with a score above the predefined threshold.

10 . The method of claim 1 , wherein the assigned score is a score between 0 and 100, and wherein the score indicates how risky a CIDR group is.

11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors of a cloud-based security system to perform steps of:

automatically scanning, by retrieving via cloud provider application programming interfaces (APIs), one or more security group rules, access control lists, and routing table configurations associated with a cloud environment;

determining, for each of one or more Classless Inter-Domain Routing (CIDR) groups within the one or more security groups, a score based on a plurality of weighted categories, the categories including at least one of Internet Protocol (IP) reputation, geo-location, public exposure of an associated compute instance, vulnerability information, or exclusion of Internet Protocol (IP) addresses contained in a customer-defined allow list;

assigning the calculated score to each of the one or more CIDR groups; and

providing, via a user interface connected to the cloud-based security system, one or more suggested actions based on the score of the one or more CIDR groups, the one or more suggested actions comprising automatically modifying or removing a security group rule permitting access from a CIDR group having a score above a predefined threshold.

12 . The non-transitory computer-readable medium of claim 11 , wherein the one or more suggested actions include removing a specific CIDR from a security group rule by issuing an update to the cloud provider API.

13 . The non-transitory computer-readable medium of claim 12 , wherein suggesting the removal of the CIDR is based on the CIDR's score exceeding a predefined threshold and the CIDR not being included in a customer-defined allow list.

14 . The non-transitory computer-readable medium of claim 11 , wherein the steps comprise:

calculating a score for each of the one or more CIDR groups within the one or more security groups based on analysis of associated access control lists (ACLs) and routing table configurations; and

assigning the calculated score to each of the one or more CIDR groups.

15 . The non-transitory computer-readable medium of claim 14 , wherein each of the CIDR groups include one or more Internet Protocol (IP) addresses, and wherein the score is based on a risk associated with each of the IP addresses, the risk being determined from flow log data including traffic amount, session length, or session times.

16 . The non-transitory computer-readable medium of claim 15 , wherein IP addresses in a customer allow list are excluded when calculating the score, the customer allow list being configurable via the user interface of the cloud-based security system.

17 . The non-transitory computer-readable medium of claim 15 , wherein the score is based on a plurality of categories, wherein each of the categories is assigned a weight and a category score, the categories including at least one of: (i) Internet Protocol reputation, (ii) vulnerability severity of associated compute instances, or (iii) public exposure state of an instance.

18 . The non-transitory computer-readable medium of claim 17 , wherein each of the categories include a plurality of parameters, the parameters determining the category score assigned to each of the categories, the parameters including at least one of: TOR network detection, VPN detection, or geolocation rarity of an Internet Protocol address.

19 . The non-transitory computer-readable medium of claim 11 , wherein the steps further comprise:

performing the one or more suggested actions automatically including automatically disabling or modifying a security group rule in response to detection of a CIDR group with a score above the predefined threshold.

20 . The non-transitory computer-readable medium of claim 11 , wherein the assigned score is a score between 0 and 100, and wherein the score indicates how risky a CIDR group is.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2023
From: ASSAYAG, JONATHAN; DANINO, SHOHAM
To: ZSCALER, INC.
Reel/Frame 065572/0915 →
Continuity (1)
Related Publication 20250159024A1 · May 15, 2025
References Cited (8)
US 8286239B1 · Sutton · 2012 [cited by examiner]
US 11632346B1 · Mahapatra et al. · 2023 [cited by applicant]
US 20100250726A1 · Moses et al. · 2010 [cited by applicant]
US 20110167474A1 · Sinha · 2011 [cited by examiner]
US 20150163235A1 · Coskun · 2015 [cited by examiner]
US 20180063170A1 · Truvé · 2018 [cited by examiner]
US 20250055869A1 · Barel · 2025 [cited by examiner]
US 20250159002A1 · Danino · 2025 [cited by examiner]