IP Library › Granted Patent US 11,755,726
Granted Patent B2
US 11,755,726 · App. 16/902,759 · Granted Sep 12, 2023

Utilizing machine learning for smart quarantining of potentially malicious files

Inventors: Changsha Ma (Campbell, CA); Rex Shang (Los Altos, CA); Douglas A. Koch (Santa Clara, CA); Dianhuan Lin (Sunnyvale, CA); Howie Xu (Palo Alto, CA); Bharath Kumar (Bengaluru, IN); Shashank Gupta (San Jose, CA); Parnit Sainion (San Jose, CA); Narinder Paul (Sunnyvale, CA); Deepen Desai (San Ramon, CA)
Assignee: Zscaler, Inc.
G06F21/554G06F21/53G06N5/04G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,726
App. No.
16/902,759
Filed
Jun 16, 2020
Granted
Sep 12, 2023
Kind
B2
Art Unit
2499
USPC
726/24
Abstract

Systems and methods include obtaining a file associated with a user for processing; utilizing a combination of policy for the user and machine learning to determine whether to i) quarantine the file and scan the file in a sandbox, ii) allow the file to the user and scan the file in the sandbox, and iii) allow the file to the user without the scan; responsive to the quarantine of the file and the sandbox determining the file is malicious, blocking the file; and, responsive to the quarantine of the file and the sandbox determining the file is benign, allowing the file.

Claims (50)

1. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming one or more processors to perform steps of:

obtaining a file associated with a user for processing;

utilizing a combination of policy for the user and processing of the file with machine learning to determine whether to

i) quarantine the file and scan the file in a sandbox,

ii) allow the file to the user and scan the file in the sandbox, and

iii) allow the file to the user without the scan;

responsive to the allow the file, sending the file to the user independent of the sandbox;

responsive to the quarantine of the file and the sandbox determining the file is malicious, blocking the file; and

responsive to the quarantine of the file and the sandbox determining the file is benign, allowing the file.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

responsive to the file being allowed and the sandbox determining the file is malicious, marking the file as malicious and blocking the file a next time.

3. The non-transitory computer-readable storage medium of claim 1 , wherein the policy is used to determine whether to i) quarantine and iii) allow, and the machine learning is used to determine whether to ii) allow.

4. The non-transitory computer-readable storage medium of claim 1 , wherein the policy is used to determine whether to iii) allow, and the machine learning is used to determine whether to i) quarantine and ii) allow.

5. The non-transitory computer-readable storage medium of claim 1 , wherein the policy is used to determine whether to iii) allow, and the machine learning is used to determine whether to i) quarantine, ii) allow, and iii) allow.

6. The non-transitory computer-readable storage medium of claim 1 , wherein the machine learning includes a trained machine learning ensemble model configured to determine whether the file is malicious.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the obtaining is based on inline monitoring of the user by a cloud-based system.

8. An apparatus comprising:

a network interface communicatively coupled to a network;

a processor communicatively coupled to the network interface; and

memory storing computer-executable instructions that, when executed, cause the processor to

obtain a file associated with a user for processing;

utilize a combination of policy for the user and processing of the file with machine learning to determine whether to

i) quarantine the file and scan the file in a sandbox,

ii) allow the file to the user and scan the file in the sandbox, and

iii) allow the file to the user without the scan;

responsive to the allow the file, sending the file to the user independent of the sandbox;

responsive to the quarantine of the file and the sandbox determining the file is malicious, block the file; and

responsive to the quarantine of the file and the sandbox determining the file is benign, allow the file.

9. The apparatus of claim 8 , wherein the computer-executable instructions that, when executed, further cause the processor to

responsive to the file being allowed and the sandbox determining the file is malicious, mark the file as malicious and block the file a next time.

10. The apparatus of claim 8 , wherein the policy is used to determine whether to i) quarantine and iii) allow, and the machine learning is used to determine whether to ii) allow.

11. The apparatus of claim 8 , wherein the policy is used to determine whether to iii) allow, and the machine learning is used to determine whether to i) quarantine and ii) allow.

12. The apparatus of claim 8 , wherein the policy is used to determine whether to iii) allow, and the machine learning is used to determine whether to i) quarantine, ii) allow, and iii) allow.

13. The apparatus of claim 8 , wherein the machine learning includes a trained machine learning ensemble model configured to determine whether the file is malicious.

14. The apparatus of claim 8 , wherein the apparatus is a node in a cloud-based system.

15. A method comprising:

obtaining a file associated with a user for processing;

utilizing a combination of policy for the user and processing of the file with machine learning to determine whether to

i) quarantine the file and scan the file in a sandbox,

ii) allow the file to the user and scan the file in the sandbox, and

iii) allow the file to the user without the scan;

responsive to the allow the file, sending the file to the user independent of the sandbox;

responsive to the quarantine of the file and the sandbox determining the file is malicious, blocking the file; and

responsive to the quarantine of the file and the sandbox determining the file is benign, allowing the file.

16. The method of claim 15 , further comprising

responsive to the file being allowed and the sandbox determining the file is malicious, marking the file as malicious and blocking the file a next time.

17. The method of claim 15 , wherein the policy is used to determine whether to i) quarantine and iii) allow, and the machine learning is used to determine whether to ii) allow.

18. The method of claim 15 , wherein the policy is used to determine whether to iii) allow, and the machine learning is used to determine whether to i) quarantine and ii) allow.

19. The method of claim 15 , wherein the policy is used to determine whether to iii) allow, and the machine learning is used to determine whether to i) quarantine, ii) allow, and iii) allow.

20. The method of claim 15 , wherein the machine learning includes a trained machine learning ensemble model configured to determine whether the file is malicious.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2020
From: KUMAR, BHARATH; GUPTA, SHASHANK; SAINION, PARNIT; PAUL, NARINDER; DESAI, DEEPEN
To: ZSCALER, INC.
Reel/Frame 053164/0226 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2020
From: MA, CHANGSHA; SHANG, REX; KOCH, DOUGLAS A.; LIN, DIANHUAN; XU, HOWIE
To: ZSCALER, INC.
Reel/Frame 052952/0017 →
Continuity (2)
Continuation In Part 16377129 · Apr 5, 2019
Related Publication 20200320192A1 · Oct 8, 2020
Cited By (4)
US 12,346,432 US 12,613,955 US 12,657,402 US 12,671,710