IP Library › Granted Patent US 12,273,392
Granted Patent B1
US 12,273,392 · App. 18/669,980 · Granted Apr 8, 2025

Security and privacy inspection of bidirectional generative artificial intelligence traffic using a forward proxy

Inventors: Siying Yang (Saratoga, CA); Krishna Narayanaswamy (Saratoga, CA)
Assignee: Netskope, Inc.
H04L63/20H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,392
App. No.
18/669,980
Filed
May 21, 2024
Granted
Apr 8, 2025
Kind
B1
Art Unit
2435
USPC
726/1
Abstract

Disclosed is a cloud-based security system implemented in a forward proxy that provides generative artificial intelligence (GenAI) traffic inspection to protect against security and privacy concerns related to GenAI use for protected endpoints. The security system intercepts requests and determines whether those requests are directed to a GenAI application. The security system includes a GenAI request classifier trained to classify prompts submitted to GenAI applications as one of benign, prompt injection attack, or uploaded files. The security system further includes a GenAI response classifier trained to classify responses from GenAI applications as one of normal, leaked system prompt, leaked user uploaded files, or leaked training data. Based on the classification, and optionally other security analysis, the security system may enforce security policies on both the requests and responses that block the traffic, trigger alerts to administrators, and the like to enforce security and privacy protection on bidirectional traffic.

Claims (106)

1. A method, comprising:

intercepting, with a forward proxy at a network security system interposed on a network between client devices and hosted services, a request transmitted from a first client device of the client devices to a first hosted service of the hosted services, wherein the hosted services comprise a plurality of generative artificial intelligence applications and a plurality of other hosted applications;

determining, by the network security system, the first hosted service is a first generative artificial intelligence application of the plurality of generative artificial intelligence applications and determining the request comprises a generative artificial intelligence prompt for submission to the first generative artificial intelligence application;

based on the determining, classifying the generative artificial intelligence prompt with a machine learning model classifier trained to receive requests and classify the generative artificial intelligence prompts of the requests directed to any of the plurality of generative artificial intelligence applications as one of a benign prompt, an injection attack prompt, and an uploaded files prompt; and

applying, by the network security system, a security policy to the request based on the classification of the generative artificial intelligence prompt.

2. The method of claim 1 , wherein the applying the security policy comprises:

in response to classifying the generative artificial intelligence prompt as the uploaded files prompt:

extracting, by the network security system, one or more files from the request;

scanning, by the network security system, the one or more files for sensitive information;

scanning, by the network security system, the request for sensitive information; and

applying, by the network security system, a second security policy to the request based on the scanning the one or more files, the scanning the request, or a combination.

3. The method of claim 2 , wherein the applying the second security policy to the request comprises:

increasing, by the network security system, a risk score associated with a user account associated with the request based on the classifying the generative artificial intelligence prompt as the uploaded files prompt, a result of the scanning the one or more files, a result of the scanning the request, or a combination.

4. The method of claim 1 , wherein the applying the security policy comprises:

in response to classifying the generative artificial intelligence prompt as the injection attack prompt:

blocking, by the network security system, transmission of the request to the first hosted service.

5. The method of claim 1 , wherein the applying the security policy comprises:

in response to classifying the generative artificial intelligence prompt as the injection attack prompt:

increasing, by the network security system, a risk score associated with a user account associated with the request.

6. The method of claim 1 , further comprising:

in response to classifying the generative artificial intelligence prompt as the benign prompt:

scanning, by the network security system, the request for sensitive information; and

applying, by the network security system, a second security policy to the request based on the scanning.

7. The method of claim 6 , wherein the applying the second security policy to the request comprises:

based on a result of the scanning, modifying, by the network security system, a risk score associated with a user account associated with the request.

8. The method of claim 1 , wherein the determining the first hosted service is the first generative artificial intelligence application comprises:

comparing a Uniform Resource Locator (URL) of the first hosted service with a list of URLs comprising URLs for at least a subset of the plurality of generative artificial intelligence applications.

9. The method of claim 1 , further comprising:

intercepting, at the network security system, a plurality of prior requests prior to intercepting the request, wherein the plurality of prior requests are transmitted from one or more of the client devices to the first hosted service;

for each prior request of the plurality of prior requests:

comparing, by the network security system, a Uniform Resource Locator (URL) of the first hosted service with a list of URLs comprising URLs for at least a subset of the plurality of generative artificial intelligence applications,

in response to not finding the URL of the first hosted service on the list of URLs, classifying, by the network security system, the request as one of suspected request and not suspected request, and

in response to classifying the request as the suspected request, increasing, by the network security system, a score of the first hosted service; and

in response to the score of the first hosted service exceeding a threshold value, adding, by the network security system, the URL of the first hosted service to the list of URLs.

10. The method of claim 1 , wherein the applying the security policy comprises:

modifying, by the network security system, a risk score associated with a user account associated with the request based on the classification of the generative artificial intelligence prompt; and

applying, by the network security system, a second security policy to the request based on the modified risk score.

11. The method of claim 1 , further comprising:

transmitting, by the network security system, the request to the first hosted service;

intercepting, at the network security system, a response from the first hosted service;

classifying the response with a second machine learning model classifier trained to classify responses from any of the plurality of generative artificial intelligence applications as one of a benign response, a leaked system prompt response, a leaked file response, and a leaked training data response; and

applying, by the network security system, a second security policy to the response based on the classification of the response.

12. The method of claim 11 , wherein the applying the second security policy comprises:

in response to classifying the response as the benign response:

scanning, by the network security system, the response for sensitive information; and

applying, by the network security system, a third security policy to the response based on the scanning.

13. The method of claim 12 , further comprising:

based on a result of the scanning the response, modifying, by the network security system, a risk score associated with the first generative artificial intelligence application.

14. The method of claim 11 , wherein the applying the second security policy comprises:

in response to classifying the response as the leaked system prompt response:

blocking transmission of the response to the first client device; and

increasing, by the network security system, a risk score associated with the first generative artificial intelligence application.

15. The method of claim 11 , wherein the applying the second security policy comprises:

in response to classifying the response as the leaked file response:

extracting, by the network security system, one or more files from the response;

scanning, by the network security system, the one or more files for sensitive information;

scanning, by the network security system, the response for sensitive information;

applying, by the network security system, a third security policy to the response based on the scanning the one or more files, the scanning the response, or a combination; and

increasing, by the network security system, a risk score associated with the first generative artificial intelligence application based on the classifying the response as the leaked file response, a result of the scanning the one or more files, a result of the scanning the response, or a combination.

16. The method of claim 11 , wherein the applying the second security policy comprises:

in response to classifying the response as the leaked training data response:

scanning, by the network security system, the response for sensitive information;

applying, by the network security system, a third security policy to the response based on the scanning; and

increasing, by the network security system, a risk score associated with the first generative artificial intelligence application based on the classifying the response as the leaked training data response, a result of the scanning, or a combination.

17. The method of claim 11 , wherein the applying the second security policy comprises:

modifying, by the network security system, a risk score associated with the first generative artificial intelligence application based on the classification of the response;

in response to the risk score associated with the first generative artificial intelligence application exceeding a threshold value, adding, by the network security system, a Uniform Resource Locator (URL) of the first generative artificial intelligence application to a blacklist; and

blocking, by the network security system, future requests intended for the first generative artificial intelligence application based on finding the URL in the blacklist.

18. A network security system interposed on a network between client devices and hosted services, the network security system comprising:

a forward proxy configured to:

intercept requests transmitted from the client devices to the hosted services;

a filtering component configured to:

for each request of the requests:

determine whether the hosted service of the hosted services identified by the respective request is one of a plurality of generative artificial intelligence applications,

route the respective request to a classifier based on a determination that the respective request is directed to one of the plurality of generative artificial intelligence applications, and

route the respective request to a security policy enforcement component based on a determination that the respective request is not directed to one of the plurality of generative artificial intelligence applications;

the classifier trained to:

for each request routed to the classifier:

classify a generative artificial intelligence prompt of the respective request as one of a benign prompt, an injection attack prompt, and an uploaded files prompt, and

provide the classification to the security policy enforcement component; and

the security policy enforcement component configured to:

apply a security policy to the classified requests based on the classification.

19. The network security system of claim 18 , wherein the security policy enforcement component is further configured to:

in response to the generative artificial intelligence prompt of the request being classified as the uploaded files prompt:

extract one or more files from the request,

scan the one or more files for sensitive information,

scan the request for sensitive information,

apply a second security policy to the request based on the scan of the one or more files, the scan of the request, or a combination, and

increase a risk score associated with a user account associated with the request;

in response to the generative artificial intelligence prompt of the request being classified as the injection attack prompt:

block transmission of the request to the hosted service of the hosted services identified by the respective request, and

increase the risk score associated with the user account associated with the request; and

in response to the generative artificial intelligence prompt of the request response being classified as the benign prompt:

scan the request for sensitive information,

apply a third security policy to the request based on the scan of the request, and

modify the risk score associated with the user account associated with the request based on the scan of the request.

20. The network security system of claim 18 , wherein:

the security policy enforcement component is further configured to:

transmit the request to the hosted service of the hosted services identified by the respective request based on a result of applying the security policy;

the forward proxy is further configured to:

intercept responses to the classified requests; and

the network security system further comprising:

a response classifier trained to:

classify the responses as one of a benign response, a leaked system prompt response, a leaked file response, and a leaked training data response; and

a response security enforcement component configured to:

apply a second security policy to the response based on the classification of the response.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2024
From: YANG, SIYING; NARAYANASWAMY, KRISHNA
To: NETSKOPE, INC.
Reel/Frame 068317/0076 →
References Cited (140)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7558796B1 · Bromwich et al. · 2009 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8225402B1 · Averbuch et al. · 2012 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11405423B2 · Narayanaswamy et al. · 2022 [cited by applicant]
US 11947902B1 · Grimshaw et al. · 2024 [cited by applicant]
US 11960514B1 · Taylert et al. · 2024 [cited by applicant]
US 11995180B1 · Cappel · 2024 [cited by examiner]
US 11997059B1 · Su et al. · 2024 [cited by applicant]
US 12045610B1 · Myers et al. · 2024 [cited by applicant]
US 12052206B1 · Lai · 2024 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170346851A1 · Drake · 2017 [cited by applicant]
US 20190327272A1 · Narayanaswamy · 2019 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200120120A1 · Cybulski · 2020 [cited by applicant]
US 20210226990A1 · Devi et al. · 2021 [cited by applicant]
US 20220232015A1 · Kumar et al. · 2022 [cited by applicant]
US 20220345463A1 · Wu et al. · 2022 [cited by applicant]
US 20230283629A1 · Boyer et al. · 2023 [cited by applicant]
US 20230291766A1 · Turgeman et al. · 2023 [cited by applicant]
US 20230359903A1 · Cefalu · 2023 [cited by examiner]
US 20230385085A1 · Singh · 2023 [cited by examiner]
US 20230385815A1 · Jakobsson et al. · 2023 [cited by applicant]
US 20240022577A1 · Fu et al. · 2024 [cited by applicant]
US 20240039905A1 · Talavera · 2024 [cited by examiner]
US 20240039954A1 · Shete et al. · 2024 [cited by applicant]
US 20240045990A1 · Boyer et al. · 2024 [cited by applicant]
US 20240056458A1 · Lee et al. · 2024 [cited by applicant]
US 20240078337A1 · Kamyshenko · 2024 [cited by examiner]
US 20240160902A1 · Padgett · 2024 [cited by examiner]
US 20240169088A1 · Neelappa · 2024 [cited by applicant]
US 20240202464A1 · Poirier · 2024 [cited by examiner]
US 20240265114A1 · Lambotte · 2024 [cited by applicant]
US 20240267344A1 · Mulligan et al. · 2024 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-, What are the different email protoc… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 18/670,003 Non-Final Office Action mailed Aug. 22, 2024, 21 pages. [cited by applicant]
U.S. Appl. No. 18/670,016 Non-Final Office Action mailed Aug. 15, 2024, 14 pages. [cited by applicant]
U.S. Appl. No. 18/670,032 Non-Final Office Action mailed Aug. 26, 2024, 27 pages. [cited by applicant]
Cited By (2)
US 12,688,280 US 12,726,509