IP Library › Granted Patent US 12,563,011
Granted Patent B2
US 12,563,011 · App. 18/522,786 · Granted Feb 24, 2026

Systems and methods for continuous fingerprinting to detect session hijacking inside zero trust private networks

Inventors: Nikhil Bhatia (San Jose, CA); Sandip Davara (San Jose, CA); Pankaj Kumar (San Jose, CA); Vivek Ashwin Raman (San Jose, CA); Abhinav Bansal (San Jose, CA)
Assignee: Zscaler, Inc.
H04L61/4511G06F21/57H04L63/0272H04L63/0281H04L63/0884H04L63/20H04L67/02H04L67/10H04L67/1001H04L67/125H04L67/51H04L67/535H04L67/56H04L67/562H04L69/162H04W12/086H04W12/088H04W12/122H04L63/164H04L2101/663
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,011
App. No.
18/522,786
Filed
Nov 29, 2023
Granted
Feb 24, 2026
Kind
B2
Art Unit
2499
USPC
726/4
Abstract

Systems and methods include responsive to a user initiating a session with a resource, determining a master fingerprint of a device associated with the user; collecting, at predefined time intervals, one or more additional fingerprints during the session; comparing the one or more additional fingerprints with the master fingerprint; and performing one or more actions based on the comparing.

Claims (36)

1 . A method implemented by a cloud-based system, the method comprising steps of:

responsive to a user initiating a session with a resource, collecting a master fingerprint of a device associated with the user, wherein the collecting is performed by the cloud-based system located between the device and the resource;

collecting, at predefined time intervals, one or more additional fingerprints during the session, wherein the master fingerprint and one or more additional fingerprints include any of a location of the device, a browser used to access the resource, and an Operating System (OS) of the device;

comparing the one or more additional fingerprints with the master fingerprint;

dynamically adjusting, based upon the comparing indicating contextual changes exceeding a predetermined threshold, a security policy associated with the session, wherein the security policy is continuously adapted during the session based on a zero trust architecture that re-evaluates user privileges according to changes in one or more contextual attributes including user role, resource sensitivity, or device risk posture; and

enforcing the dynamically adjusted security policy by selectively allowing, limiting, or denying user access to the resource based on the continuously reassessed contextual attributes.

2 . The method of claim 1 , wherein the comparing includes comparing attributes of the one or more additional fingerprints with attributes of the master fingerprint.

3 . The method of claim 2 , wherein the steps further comprise:

receiving a policy profile at the cloud-based system, the policy profile defining which attributes to collect when collecting the one or more additional fingerprints and the master fingerprint; and

collecting one or more attributes of the master fingerprint and collecting one or more attributes of the one or more additional fingerprints based on the policy profile.

4 . The method of claim 3 , wherein the attributes include any of a location of the device, a browser used to access the resource, and an Operating System (OS) of the device, and wherein the comparing includes comparing a location of the device, a browser used to access the resource, and an OS from the master fingerprint to a location of the device, a browser used to access the resource, and an OS from the one or more additional fingerprints.

5 . The method of claim 3 , wherein the policy profile defines the time intervals, and wherein the collecting one or more additional fingerprints during the session is performed based on the time intervals defined by the profile policy.

6 . The method of claim 1 , wherein responsive to identifying no changes between the one or more additional fingerprints and the master fingerprint, the one or more actions include maintaining the session and continuing to collect additional fingerprints during the session.

7 . The method of claim 1 , wherein responsive to identifying changes between the one or more additional fingerprints and the master fingerprint, the one or more actions include any of blocking the user, terminating the session, and sending an alert to an administrator.

8 . The method of claim 1 , wherein the collecting one or more additional fingerprints during the session is performed based on detecting abnormal behavior of the user during the session, wherein abnormal behavior is determined by comparing real time user behavior to historical user behavior vie one or more machine learning models.

9 . The method of claim 1 , wherein the session is initiated responsive to the user accessing an application.

10 . The method of claim 1 , wherein the steps further comprise:

calculating a risk score based on the comparing and performing one or more actions based thereon.

11 . A non-transitory computer-readable storage medium having computer readable code stored thereon for programming at least one processor of a cloud-based system to perform steps of:

responsive to a user initiating a session with a resource, collecting a master fingerprint of a device associated with the user, wherein the collecting is performed by the cloud-based system located between the device and the resource;

collecting, at predefined time intervals, one or more additional fingerprints during the session, wherein the master fingerprint and one or more additional fingerprints include any of a location of the device, a browser used to access the resource, and an Operating System (OS) of the device;

comparing the one or more additional fingerprints with the master fingerprint; and

dynamically adjusting, based upon the comparing indicating contextual changes exceeding a predetermined threshold, a security policy associated with the session, wherein the security policy is continuously adapted during the session based on a zero trust architecture that re-evaluates user privileges according to changes in one or more contextual attributes including user role, resource sensitivity, or device risk posture; and

enforcing the dynamically adjusted security policy by selectively allowing, limiting, or denying user access to the resource based on the continuously reassessed contextual attributes.

12 . The non-transitory computer-readable storage medium of claim 11 , wherein the comparing includes comparing attributes of the one or more additional fingerprints with attributes of the master fingerprint.

13 . The non-transitory computer-readable storage medium of claim 12 , wherein the steps further comprise:

receiving a policy profile at the cloud-based system, the policy profile defining which attributes to collect when collecting the one or more additional fingerprints and the master fingerprint; and

collecting one or more attributes of the master fingerprint and collecting one or more attributes of the one or more additional fingerprints based on the policy profile.

14 . The non-transitory computer-readable storage medium of claim 13 , wherein the attributes include any of a location of the device, a browser used to access the resource, and an Operating System (OS) of the device, and wherein the comparing includes comparing a location of the device, a browser used to access the resource, and an OS from the master fingerprint to a location of the device, a browser used to access the resource, and an OS from the one or more additional fingerprints.

15 . The non-transitory computer-readable storage medium of claim 13 , wherein the policy profile defines the time intervals, and wherein the collecting one or more additional fingerprints during the session is performed based on the time intervals defined by the profile policy.

16 . The non-transitory computer-readable storage medium of claim 11 , wherein responsive to identifying no changes between the one or more additional fingerprints and the master fingerprint, the one or more actions include maintaining the session and continuing to collect additional fingerprints during the session.

17 . The non-transitory computer-readable storage medium of claim 11 , wherein responsive to identifying changes between the one or more additional fingerprints and the master fingerprint, the one or more actions include any of blocking the user, terminating the session, and sending an alert to an administrator.

18 . The non-transitory computer-readable storage medium of claim 11 , wherein the collecting one or more additional fingerprints during the session is performed based on detecting abnormal behavior of the user during the session, wherein abnormal behavior is determined by comparing real time user behavior to historical user behavior vie one or more machine learning models.

19 . The non-transitory computer-readable storage medium of claim 11 , wherein the session is initiated responsive to the user accessing an application.

20 . The non-transitory computer-readable storage medium of claim 11 , wherein the steps further comprise:

calculating a risk score based on the comparing and performing one or more actions based thereon.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2023
From: BHATIA, NIKHIL; DAVARA, SANDIP; KUMAR, PANKAJ; RAMAN, VIVEK ASHWIN; BANSAL, ABHINAV
To: ZSCALER, INC.
Reel/Frame 065699/0876 →
Continuity (5)
Continuation 17402933 · Aug 16, 2021
Continuation In Part 16674111 · Nov 5, 2019
Continuation In Part 16252961 · Jan 21, 2019
Continuation 15377126 · Dec 13, 2016
Related Publication 20240121211A1 · Apr 11, 2024
References Cited (31)
US 1021099A · Hogan · 1912 [cited by examiner]
US 8464335B1 · Sinha et al. · 2013 [cited by applicant]
US 8495737B2 · Sinha et al. · 2013 [cited by applicant]
US 8955091B2 · Kailash et al. · 2015 [cited by applicant]
US 9058495B2 · Brannon et al. · 2015 [cited by applicant]
US 9060239B1 · Sinha et al. · 2015 [cited by applicant]
US 9118689B1 · Desai et al. · 2015 [cited by applicant]
US 9350644B2 · Desai et al. · 2016 [cited by applicant]
US 9369433B1 · Paul et al. · 2016 [cited by applicant]
US 9378350B2 · Stuntebeck · 2016 [cited by applicant]
US 9413754B2 · Stuntebeck et al. · 2016 [cited by applicant]
US 9473537B2 · Sinha et al. · 2016 [cited by applicant]
US 9516005B2 · DiRico et al. · 2016 [cited by applicant]
US 9516066B2 · Brannon et al. · 2016 [cited by applicant]
US 9584964B2 · Pelkey · 2017 [cited by applicant]
US 9665576B2 · Kapoor et al. · 2017 [cited by applicant]
US 9665577B2 · Kapoor et al. · 2017 [cited by applicant]
US 9813247B2 · Stuntebeck et al. · 2017 [cited by applicant]
US 9819682B2 · Dabbiere et al. · 2017 [cited by applicant]
US 9825996B2 · Brannon et al. · 2017 [cited by applicant]
US 9916446B2 · Phanse et al. · 2018 [cited by applicant]
US 10091312B1 · Khanwalkar · 2018 [cited by examiner]
US 10298682B2 · Sims · 2019 [cited by examiner]
US 10341344B2 · Eisen · 2019 [cited by examiner]
US 10728350B1 · Khanwalkar · 2020 [cited by examiner]
US 10862889B2 · Eisen · 2020 [cited by examiner]
US 11240326B1 · Khanwalkar · 2022 [cited by examiner]
US 20110167474A1 · Sinha et al. · 2011 [cited by applicant]
US 20150326613A1 · Devarajan et al. · 2015 [cited by applicant]
US 20160203487A1 · Eisen · 2016 [cited by examiner]
US 20160261564A1 · Foxhoven et al. · 2016 [cited by applicant]