IP Library › Granted Patent US 12,634,200
Granted Patent B2
US 12,634,200 · App. 18/645,656 · Granted May 19, 2026

Systems and methods for configuration management database (CMDB) based application segmentation

Inventors: Chenhui Hu (Lexington, MA); Shikhar Omar (Bangalore, IN); Raimi Shah (Austin, TX); Vivek Bitla (San Jose, CA); Shujaat Ali Jaffrey (Bangalore, IN); Rex Shang (San Jose, CA)
Assignee: Zscaler, Inc.
H04L41/0893
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,200
App. No.
18/645,656
Granted
May 19, 2026
Kind
B2
Abstract

Systems and methods for Configuration Management Database (CMDB) based application segmentation include obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users; obtaining Configuration Management Database (CMDB) data of the enterprise, wherein the CMDB data includes information about hardware and software assets of the enterprise; matching application information within the transactional data and the CMDB data; and generating one or more application segments based on the matching.

Claims (46)

1 . A non-transitory computer-readable storage medium having computer readable code stored thereon for programming at least one processor to perform steps of:

obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users;

obtaining Configuration Management Database (CMDB) data of the enterprise, wherein the CMDB data includes information about hardware and software assets of the enterprise;

matching application information within the transactional data and the CMDB data, the matching comprising performing, in an order of decreasing confidence, a plurality of matching techniques including at least:

(i) matching directly using Fully Qualified Domain Names (FQDNs) in both the transactional data and the CMDB data;

(ii) matching application Internet Protocol (IP) addresses present in the CMDB data using app-server IP mappings from the transactional data;

(iii) matching based on FQDN prefixes;

(iv) matching using a one-to-one mapping between FQDNs and IP addresses for applications;

(v) matching FQDNs in the CMDB data using app-server IP address mappings from the transactional data;

generating one or more application segments based on the matching; and

using the one or more application segments to define access to the plurality of applications by the plurality of users.

2 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further comprise:

providing an access policy for the plurality of applications based on the one or more application segments.

3 . The non-transitory computer-readable storage medium of claim 1 , wherein performing the plurality of matching techniques comprise performing a plurality of matching techniques between the transactional data and the CMDB data.

4 . The non-transitory computer-readable storage medium of claim 3 , wherein the plurality of matching techniques are performed in an order based on a confidence of each of the plurality of matching techniques, wherein direct FQDN matching is prioritized over IP-based matching, prefix-based matching, and one-to-one FQDN-IP mapping.

5 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching directly using FQDNs in both the transactional data and the CMDB data, including exact-string matching of FQDNs appearing in both data sets.

6 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching application IP addresses present in the CMDB data using app-server IP mappings from the transactional data.

7 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching based on FQDN prefixes.

8 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching using a 1-to-1 mapping between FQDN and IP addresses for applications in transactional data and the CMDB data.

9 . The non-transitory computer-readable storage medium of claim 3 , wherein one of the plurality of matching techniques includes matching FQDNs in the CMDB data using app-server Internet IP address mappings from the transactional data.

10 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further comprise:

generating a segmentation report; and

providing the segmentation report to users of the enterprise, including port-protocol usage and transaction volume for use in configuring the access.

11 . A method comprising steps of:

obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users;

obtaining Configuration Management Database (CMDB) data of the enterprise, wherein the CMDB data includes information about hardware and software assets of the enterprise;

matching application information within the transactional data and the CMDB data, the matching comprising performing, in an order of decreasing confidence, a plurality of matching techniques including at least:

(i) matching directly using Fully Qualified Domain Names (FQDNs) in both the transactional data and the CMDB data;

(ii), matching application Internet Protocol (IP) addresses present in the CMDB data using app-server IP mappings from the transactional data;

(iii) matching based on FQDN prefixes;

(iv) matching using a one-to-one mapping between FQDNs and IP addresses for applications; and

(v) matching FQDNs in the CMDB data using app-server IP address mappings from the transactional data;

generating one or more application segments based on the matching; and

using the one or more application segments to define access to the plurality of applications by the plurality of users.

12 . The method of claim 11 , wherein the steps further comprise:

providing an access policy for the plurality of applications based on the one or more application segments.

13 . The method of claim 11 , wherein performing the plurality of matching techniques comprise performing a plurality of matching techniques between the transactional data and the CMDB data.

14 . The method of claim 13 , wherein the plurality of matching techniques are performed in an order based on a confidence of each of the plurality of matching techniques, wherein direct FQDN matching is prioritized over IP-based matching, prefix-based matching, and one-to-one FQDN-IP mapping.

15 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching directly using FQDNs in both the transactional data and the CMDB data, including exact-string matching of FQDNs appearing in both data sets.

16 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching application IP addresses present in the CMDB data using app-server IP mappings from the transactional data.

17 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching based on FQDN prefixes.

18 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching using a 1-to-1 mapping between FQDN and IP addresses for applications in transactional data and the CMDB data.

19 . The method of claim 13 , wherein one of the plurality of matching techniques includes matching FQDNs in the CMDB data using app-server IP address mappings from the transactional data.

20 . The method of claim 11 , wherein the steps further comprise:

generating a segmentation report; and

providing the segmentation report to users of the enterprise, including port-protocol usage and transaction volume for use in configuring the access.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2024
From: HU, CHENHUI; OMAR, SHIKHAR; SHAH, RAIMI; BITLA, VIVEK; JAFFREY, SHUJAAT ALI; SHANG, REX
To: ZSCALER, INC.
Reel/Frame 067223/0183 →
Priority Claims (1)
IN 202441018477 · Mar 14, 2024 · national
Continuity (1)
Related Publication 20250293931A1 · Sep 18, 2025
References Cited (25)
US 11669779B2 · Lin et al. · 2023 [cited by applicant]
US 11785022B2 · Ma et al. · 2023 [cited by applicant]
US 20090012997A1 · Rajaraman · 2009 [cited by examiner]
US 20190104024A1 · Biran · 2019 [cited by examiner]
US 20190356697A1 · Chougule · 2019 [cited by examiner]
US 20200059491A1 · Nukala · 2020 [cited by examiner]
US 20210049413A1 · Ma et al. · 2021 [cited by applicant]
US 20210377303A1 · Bui et al. · 2021 [cited by applicant]
US 20210377304A1 · Ma et al. · 2021 [cited by applicant]
US 20210392146A1 · Lin et al. · 2021 [cited by applicant]
US 20220067581A1 · Kumar et al. · 2022 [cited by applicant]
US 20220083661A1 · Ma et al. · 2022 [cited by applicant]
US 20230018188A1 · Shang et al. · 2023 [cited by applicant]
US 20230036680A1 · Hayes · 2023 [cited by examiner]
US 20230115982A1 · Lin et al. · 2023 [cited by applicant]
US 20230247003A1 · Chanak et al. · 2023 [cited by applicant]
US 20230254318A1 · Hu et al. · 2023 [cited by applicant]
US 20230353587A1 · Bui et al. · 2023 [cited by applicant]
US 20230370495A1 · Desai et al. · 2023 [cited by applicant]
US 20230376592A1 · Ma et al. · 2023 [cited by applicant]
US 20240013221A1 · Kruse · 2024 [cited by examiner]
US 20240028721A1 · Ma et al. · 2024 [cited by applicant]
US 20240323096A1 · Vasseur · 2024 [cited by examiner]
EP 3926502A1 · 2021 [cited by applicant]
EP 3965362A1 · 2022 [cited by applicant]