IP Library Granted Patent US 12,355,767
Granted Patent B2
US 12,355,767 · App. 17/231,060 · Granted Jul 8, 2025

Securing local network traffic using cloud computing

Inventors: Abhinav Bansal (San Jose, CA); Rohit Goyal (Mohali, IN)
Assignee: Zscaler, Inc.
H04L63/0884H04L61/4511H04L63/0272H04L63/0281H04L67/02H04L67/10H04L67/1001H04L67/125H04L67/51H04L67/56H04L67/563H04L67/564H04L69/162H04L2101/663
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,767
App. No.
17/231,060
Filed
Apr 15, 2021
Granted
Jul 8, 2025
Kind
B2
Art Unit
2439
USPC
726/12
Abstract

Systems and methods for securely handling data traffic on local or private networks, such as by using cloud computing, are provided. A non-transitory computer-readable medium, according to one implementation, may be configured to store executable instructions enabling a processor of a user device to perform the step of discovering an origin of a source application associated with network packets bound for a private address space. The executable instructions may further enable the processor to send a tuple regarding the discovered origin to a cloud server to request an analysis of the tuple. Upon receiving an allow instruction from the cloud server, the instructions enable the processor to allow the network packets to flow normally to a destination associated with the private address space. Upon receiving a deny instruction from the cloud server, the instructions enable the processor to drop the network packets.

Claims (55)

1. A non-transitory computer-readable medium configured to store executable instructions enabling a processor of a user device to perform the steps of:

intercepting network packets originating from one or more source applications operating on the user device,

discovering an origin source application of the one or more source applications associated with the network packets bound for a private address space,

recording a tuple associated with the discovered origin source application, the tuple defining a sequenced list related to the source application comprising any of an application name and a network type,

sending the tuple regarding the discovered origin source application to a cloud server to request an analysis of the tuple,

upon receiving an allow instruction from the cloud server, allowing the network packets to flow normally to a destination associated with the private address space, and

upon receiving a deny instruction from the cloud server, dropping the network packets, wherein upon receiving a caution instruction from the cloud server, the executable instructions further enable the processor to allow the network packets to flow normally and redirect a copy of the network packets and additional network transaction information to the cloud server for further analysis of the tuple.

2. The non-transitory computer-readable medium of claim 1 , wherein, upon receiving an allow instruction from the cloud server based on the further analysis, the executable instructions further enable the processor to allow the network packets to flow normally to the destination associated with the private address space, and, upon receiving a deny instruction from the cloud server based on the further analysis, the executable instructions further enable the processor to drop the network packets.

3. The non-transitory computer-readable medium of claim 1 , wherein the executable instructions further enable the processor to:

intercept incoming and outgoing network packets at the user device,

open a tunnel with the cloud server, and

download, via a procedure to receive executed on the user device, configuration information, policy information, and traffic rules from the cloud server for the user device to use thereon.

4. The non-transitory computer-readable medium of claim 3 , wherein the executable instructions further enable the processor to:

determine where the incoming and outgoing network packets are to be transmitted,

upon determining that the incoming and outgoing network packets are to be transmitted to a public address space, send the incoming and outgoing network packets via the cloud server, and

upon determining that the incoming and outgoing network packets are to be transmitted to the private address space, perform the step of discovering the origin of the source application associated with the network packets.

5. A user device configured to execute an application for securing local network traffic, the user device comprising:

a processor; and

memory configured to store executable instructions enabling the processor to:

intercept network packets originating from one or more source applications operating on the user device,

discover an origin source application of the one or more source applications associated with the network packets bound for a private address space,

record a tuple associated with the discovered origin source application, the tuple defining a sequenced list related to the source application comprising any of an application name and a network type,

send the tuple regarding the discovered origin source application to a cloud server to request an analysis of the tuple,

upon receiving an allow instruction from the cloud server, allow the network packets to flow normally to a destination associated with the private address space, and

upon receiving a deny instruction from the cloud server, drop the network packets; wherein, upon receiving a caution instruction from the cloud server the executable instructions further enable the processor to allow the network packets to flow normally and redirect a copy of the network packets and additional network transaction information to the cloud server for further analysis of the tuple.

6. The user device of claim 5 , wherein, upon receiving an allow instruction from the cloud server based on the further analysis, the executable instructions further enable the processor to allow the network packets to flow normally to the destination associated with the private address space, and, upon receiving a deny instruction from the cloud server based on the further analysis, the executable instructions further enable the processor to drop the network packets.

7. The user device of claim 5 , wherein the executable instructions further enable the processor to:

intercept incoming and outgoing network packets,

open a tunnel with the cloud server,

download configuration information, policy information, and traffic rules from the cloud server for the user device to use thereon,

determine where the incoming and outgoing network packets are to be transmitted,

upon determining that the incoming and outgoing network packets are to be transmitted to a public address space, send the incoming and outgoing network packets via the cloud server, and

upon determining that the incoming and outgoing network packets are to be transmitted to the private address space, perform the step of discovering the origin of the source application associated with the network packets.

8. The user device of claim 5 , further comprising a network interface configured to communicate with the cloud server.

9. The user device of claim 5 , wherein the user device is configured to enable a remote user to access an enterprise network from outside a physical perimeter of the enterprise network.

10. The user device of claim 5 , wherein the user device is one of a laptop, smartphone, tablet, netbook, personal digital assistant, MP3 player, cell phone, e-book reader, IoT device, server, desktop, printer, television, and streaming media device.

11. A cloud server configured to execute an application for securing local network traffic, the cloud server comprising:

a processor; and

memory configured to store executable instructions enabling the processor to:

receive a tuple from a user device, the tuple including information regarding an origin source application executing on the user device associated with network packets bound for a private address space, the tuple defining a sequenced list related to the source application comprising any of an application name and a network type,

comprising any of an application name and a network type,

perform an analysis of the information of the tuple to identify potential malware and/or policy violations, and

provide results of the analysis to the user device by sending the user device one of an allow instruction and a deny instruction, the allow instruction configured to instruct the user device to perform an action of allowing the network packets to flow normally via the cloud server to a destination, the deny instruction configured to instruct the user device to perform an action of dropping the network packets, wherein, upon receiving a caution instruction from the cloud server the executable instructions further enable the processor to allow the network packets to flow normally and redirect a copy of the network packets and additional network transaction information to the cloud server for further analysis of the tuple.

12. The cloud server of claim 11 , wherein the executable instructions further enable the processor to

open a tunnel with the user device in response to a request for assistance, and

download configuration information, policy information, and traffic rules to the user device for the user device to use thereon.

13. The cloud server of claim 11 , wherein, upon receiving the network packets and additional network transaction information from the user device in response to the caution instruction, the instructions further enable the processor to perform a further analysis using a deep packet inspection of a network transaction associated with the network packets.

14. The cloud server of claim 13 , wherein the deep packet inspection includes determining whether malicious behavior is detected, sending the user device an allow instruction for allowing the network packets to flow normally via the cloud server to the destination in response to determining that the source application does not exhibit malicious behavior, and sending the user device a deny instruction for dropping the network packets in response to determining that the source application exhibits malicious behavior.

15. The cloud server of claim 14 , further comprising a malware repository, wherein the deep packet inspection includes designating the source application as safe in the malware repository in response to determining that the source application does not exhibit malicious behavior and designating the source application as unsafe in the malware repository in response to determining that the source application exhibits malicious behavior.

16. The cloud server of claim 11 , further comprising a malware repository, wherein performing the analysis of the information of the tuple to identify potential malware and/or policy violations includes

comparing the information of the tuple with information stored in the malware repository,

sending the allow instruction when the information of the tuple is designated as safe in the malware repository,

sending the deny instruction when the information of the tuple is designated as unsafe in the malware repository, and

sending a caution instruction when the information of the tuple is not present in the malware repository.

17. The cloud server of claim 11 , wherein the private address space is part of a Virtual Private Network (VPN).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2021
From: BANSAL, ABHINAV; GOYAL, ROHIT
To: ZSCALER, INC.
Reel/Frame 055925/0679 →
Priority Claims (2)
IN 201611010521 · Mar 28, 2016 · national
IN 202111008924 · Mar 3, 2021 · national
Continuity (4)
Continuation In Part 16922353 · Jul 7, 2020
Continuation In Part 15900951 · Feb 21, 2018
Continuation 15153108 · May 12, 2016
Related Publication 20210234860A1 · Jul 29, 2021
References Cited (32)
US 7693059B2 · Osenbach et al. · 2010 [cited by applicant]
US 8695059B2 · Kopti · 2014 [cited by applicant]
US 8892766B1 · Wei · 2014 [cited by examiner]
US 9019962B1 · Ghosh · 2015 [cited by applicant]
US 9083740B1 · Ma · 2015 [cited by examiner]
US 9621574B2 · Desai et al. · 2017 [cited by applicant]
US 9935955B2 · Desai et al. · 2018 [cited by applicant]
US 10243997B2 · Desai et al. · 2019 [cited by applicant]
US 10505903B1 · Pednekar · 2019 [cited by examiner]
US 10511590B1 · Bosch · 2019 [cited by examiner]
US 20080148381A1 · Aaron · 2008 [cited by examiner]
US 20100027549A1 · Satterlee et al. · 2010 [cited by applicant]
US 20100125903A1 · Devarajan et al. · 2010 [cited by applicant]
US 20120281706A1 · Agarwal et al. · 2012 [cited by applicant]
US 20130061306A1 · Sinn · 2013 [cited by applicant]
US 20140020062A1 · Tumula et al. · 2014 [cited by applicant]
US 20140053280A1 · Durazzo · 2014 [cited by examiner]
US 20150026289A1 · Nordness · 2015 [cited by examiner]
US 20150135302A1 · Cohen et al. · 2015 [cited by applicant]
US 20150282041A1 · Batchu et al. · 2015 [cited by applicant]
US 20160142374A1 · Clark · 2016 [cited by applicant]
US 20170279803A1 · Desai et al. · 2017 [cited by applicant]
US 20170331859A1 · Bansal et al. · 2017 [cited by applicant]
US 20170366646A1 · Bradley · 2017 [cited by examiner]
US 20180288062A1 · Goyal et al. · 2018 [cited by applicant]
US 20210234860A1 · Bansal · 2021 [cited by examiner]
US 20220303244A1 · Wondra · 2022 [cited by examiner]
Network-Independent Support for Using Multiple IP Interface in Applications, IEEE Conference Paper, 2011 Conference on Network and Information Systems Security, Famulari, A, Hecker, A. Abstract Only (Year: 2011). [cited by applicant]
Multipath cloud federation Publication Date: Sep. 1, 2017, Electronic Publication Date: Oct. 18, 2017 Published in: 2017 IEEE 6th International Conference on Cloud Networking (CioudNet) (pp. 1-6), Mael Kimmerlin, Peer H… [cited by applicant]
Tsunami: A parasitic, indestructible botnet on Kad, Author: Memon, Ghulam; Li, Jun; Rejaie, Reza, Abstract Only Publication info: Peer-to-Peer Networking and Applications 7.4: 444-455, Springer Science & Business Media,… [cited by applicant]
A cluster-based countermeasure against blackhole attacks in MANETs, Author: Shi, Fei; Liu, Weijie; Jin, Dongxu; Song, Jooseok, Abstract Only, Publication info: Telecommunication Systems 57.2: 119-136. Springer Science &… [cited by applicant]
Remote access VPNs: Selection and deployment issues, Author: King, Christopher M, Abstract Only Publication info: Business Communications Review 30.6: 52-56. UBM LLC. (Jun. 2000) (Year: 2000). [cited by applicant]