IP Library Patent Application 19092316
Patent Application
App. No. 19/092,316

SOFTWARE-AS-A-SERVICE USAGE MONITORING WITH SECURE BROWSER OR BROWSER ENVIRONMENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/092,316
Filed
Mar 27, 2025
Art Unit
2407
USPC
726/26
Abstract

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.

Claims (37)

1 . A method comprising:

verifying, by a backend of an organization, a web browser on an endpoint that hosts a first environment that comprises the web browser;

communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser; and

monitoring and managing, with at least one of the first environment and the web browser, usage of Software-as-a-Service applications (SaaS) based, at least in part, on the one or more security policies.

2 . The method of claim 1 , wherein monitoring usage of SaaS applications comprises tracking which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization.

3 . The method of claim 1 , wherein monitoring usage of SaaS applications further comprises tracking at least one of use of the SaaS applications and resources of the organization involved in use of the SaaS applications.

4 . The method of claim 1 , wherein monitoring usage of SaaS applications comprises monitoring OAuth requests and connections and identifying third party SaaS applications being used based on monitoring the OAuth requests and connections.

5 . The method of claim 1 , wherein managing usage of SaaS applications comprises at last one of:

executing requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and

using API keys to administer the SaaS application.

6 . The method of claim 5 , wherein managing usage of SaaS applications further comprises at least one of analyzing configurations of the SaaS application and scanning for persistence of exploits of the SaaS application.

7 . The method of claim 6 , wherein analyzing configurations comprises analyzing forwarding rules and alias rules of an e-mail SaaS application.

8 . A non-transitory, machine-readable medium having stored thereon program code comprising instructions to:

authenticate a web browser with a backend of an organization;

obtain from the backend one or more security policies of the organization after authentication of the web browser; and

monitor and manage, with at least the web browser, usage of Software-as-a-Service applications (SaaS) based, at least in part, on the one or more security policies.

9 . The non-transitory, machine-readable medium of claim 8 , wherein the instructions to monitor usage of SaaS applications comprise instructions to track which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization.

10 . The non-transitory, machine-readable medium of claim 8 , wherein the instructions to monitor usage of SaaS applications further comprise instructions to track at least one of use of the SaaS applications and resources of the organization involved in use of the SaaS applications.

11 . The non-transitory, machine-readable medium of claim 8 , wherein the instructions to monitor usage of SaaS applications comprises instructions to monitor OAuth requests and connections and identify third party SaaS applications being used based on monitoring the OAuth requests and connections.

12 . The non-transitory, machine-readable medium of claim 8 , wherein the instructions to manage usage of SaaS applications comprise at last one of:

instructions to execute requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and

instructions to use API keys to administer the SaaS application.

13 . The non-transitory, machine-readable medium of claim 12 , wherein the instructions to manage usage of SaaS applications further comprise instructions to, at least one of, analyze configurations of the SaaS application and scan for persistence of exploits of the SaaS application.

14 . The non-transitory, machine-readable medium of claim 13 , wherein the instructions to analyze configurations comprise instructions to analyze forwarding rules and alias rules of an e-mail SaaS application.

15 . An apparatus comprising:

a processor; and

a machine-readable medium having stored thereon instructions executable by the processor to cause the apparatus to,

authenticate a web browser with a backend of an organization;

obtain from the backend one or more security policies of the organization after authentication of the web browser; and

monitor and manage, with at least the web browser, usage of Software-as-a-Service applications (SaaS) based, at least in part, on the one or more security policies.

16 . The apparatus of claim 15 , wherein the instructions to monitor usage of SaaS applications comprise instructions executable by the processor to cause the apparatus to track which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization.

17 . The apparatus of claim 15 , wherein the instructions to monitor usage of SaaS applications further comprise instructions executable by the processor to cause the apparatus to track at least one of use of the SaaS applications and resources of the organization involved in use of the SaaS applications.

18 . The apparatus of claim 15 , wherein the instructions to monitor usage of SaaS applications comprises instructions executable by the processor to cause the apparatus to monitor OAuth requests and connections and identify third party SaaS applications being used based on monitoring the OAuth requests and connections.

19 . The apparatus of claim 15 , wherein the instructions to manage usage of SaaS applications comprise at last one of:

instructions executable by the processor to cause the apparatus to execute requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and

instructions executable by the processor to cause the apparatus to use API keys to administer the SaaS application.

20 . The apparatus of claim 19 , wherein the instructions to manage usage of SaaS applications further comprise instructions executable by the processor to cause the apparatus to, at least one of, analyze configurations of the SaaS application and scan for persistence of exploits of the SaaS application.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2025
From: TALON CYBER SECURITY LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 070664/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2025
From: BEN-NOON, OFER; BOBROV, OHAD
To: TALON CYBER SECURITY LTD.
Reel/Frame 070650/0431 →