IP Library Granted Patent US 12,580,921
Granted Patent B2
US 12,580,921 · App. 18/390,187 · Granted Mar 17, 2026

Generating zero-trust policy for application access utilizing knowledge graph based application segmentation

Inventors: Manikya Bardhan (Bengaluru, IN); Raimi Shah (Austin, TX); Chenhui Hu (Boston, MA); Hanchen Xiong (London, GB)
Assignee: Zscaler, Inc.
H04L63/104H04L63/20H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,921
App. No.
18/390,187
Granted
Mar 17, 2026
Kind
B2
Abstract

Systems and methods include obtaining log data for a plurality of users of an enterprise, wherein the log data relates to usage of a plurality of applications by the plurality of users; analyzing the log data to determine one or more relations between the plurality of users and the plurality of applications; determining one or more app-segments that are groupings of application of the plurality of applications based on the log data and the one or more relations between the plurality of users and the plurality of applications; and providing access policy of the plurality of applications based on the one or more app-segments.

Claims (40)

1 . A non-transitory computer-readable storage medium having computer readable code stored thereon for programming at least one processor to perform steps of:

obtaining log data for a plurality of users of an enterprise, wherein the log data relates to usage of a plurality of applications by the plurality of users;

analyzing the log data to determine one or more relations between the plurality of users and the plurality of applications;

determining one or more app-segments that are groupings of application of the plurality of applications based on the log data and the one or more relations between the plurality of users and the plurality of applications;

determining one or more user-groups based on the log data and the one or more relations between the plurality of users and the plurality of applications;

generating the one or more app-segments and the one or more user-groups using a machine learning model trained on the log data, wherein the log data is transformed into feature vectors and clustered to group users and applications based on access patterns; and

providing access policy of the plurality of applications based on the one or more app-segments and the one or more user-groups, wherein the access policy reduces wildcard access and supports zero-trust by granting application access to only specific user-groups.

2 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further comprise:

training an embedding model; and

utilizing the trained embedding model on the obtained log data to produce vector representations of the plurality of users, the plurality of applications, and the relations therebetween.

3 . The non-transitory computer-readable storage medium of claim 1 , wherein the log data and the one or more relations between the plurality of users and the plurality of applications is transformed to feature vectors, and wherein the determining includes clustering with the feature vectors.

4 . The non-transitory computer-readable storage medium of claim 1 , wherein the log data includes metadata of the plurality of users and metadata of the plurality of applications.

5 . The non-transitory computer-readable storage medium of claim 4 , wherein the metadata of the plurality of users includes a department associated with each of the plurality of users.

6 . The non-transitory computer-readable storage medium of claim 4 , wherein the metadata of the plurality of applications includes a server Internet Protocol (IP) address, a port, and a protocol used by each of the plurality of applications.

7 . The non-transitory computer-readable storage medium of claim 1 , wherein the determining further includes determining one or more user-groups based on the log data and the one or more relations between the plurality of users and the plurality of applications.

8 . The non-transitory computer-readable storage medium of claim 7 , wherein the providing access policy of the plurality of applications is based on the one or more app-segments and the one or more user-groups.

9 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further comprise:

monitoring the access policy over time based on ongoing log data, manual verification of the access policy, and incidents where users are prevented from accessing any application; and

adjusting any of the determined app-segments based on the monitoring.

10 . The non-transitory computer-readable storage medium of claim 1 , wherein the log data is obtained over a period of time and the determining and providing is performed over the period of time until the access policy meets a quality threshold.

11 . A method comprising steps of:

obtaining log data for a plurality of users of an enterprise, wherein the log data relates to usage of a plurality of applications by the plurality of users;

analyzing the log data to determine one or more relations between the plurality of users and the plurality of applications;

determining one or more app-segments that are groupings of application of the plurality of applications based on the log data and the one or more relations between the plurality of users and the plurality of applications;

determining one or more user-groups based on the log data and the one or more relations between the plurality of users and the plurality of applications;

generating the one or more app-segments and the one or more user-groups using a machine learning model trained on the log data, wherein the log data is transformed into feature vectors and clustered to group users and applications based on access patterns; and

providing access policy of the plurality of applications based on the one or more app-segments and the one or more user-groups, wherein the access policy reduces wildcard access and supports zero-trust by granting application access to only specific user-groups.

12 . The method of claim 11 , wherein the steps further comprise:

training an embedding model; and

utilizing the trained embedding model on the obtained log data to produce vector representations of the plurality of users, the plurality of applications, and the relations therebetween.

13 . The method of claim 11 , wherein the log data and the one or more relations between the plurality of users and the plurality of applications is transformed to feature vectors, and wherein the determining includes clustering with the feature vectors.

14 . The method of claim 11 , wherein the log data includes metadata of the plurality of users and metadata of the plurality of applications.

15 . The method of claim 14 , wherein the metadata of the plurality of users includes a department associated with each of the plurality of users.

16 . The method of claim 14 , wherein the metadata of the plurality of applications includes a server Internet Protocol (IP) address, a port, and a protocol used by each of the plurality of applications.

17 . The method of claim 11 , wherein the determining further includes determining one or more user-groups based on the log data and the one or more relations between the plurality of users and the plurality of applications.

18 . The method of claim 17 , wherein the providing access policy of the plurality of applications is based on the one or more app-segments and the one or more user-groups.

19 . The method of claim 11 , wherein the steps further comprise:

monitoring the access policy over time based on ongoing log data, manual verification of the access policy, and incidents where users are prevented from accessing any application; and

adjusting any of the determined app-segments based on the monitoring.

20 . The method of claim 11 , wherein the log data is obtained over a period of time and the determining and providing is performed over the period of time until the access policy meets a quality threshold.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2023
From: BARDHAN, MANIKYA; SHAH, RAIMI; HU, CHENHUI; XIONG, HANCHEN
To: ZSCALER, INC.
Reel/Frame 065918/0725 →
Continuity (3)
Continuation In Part 18098464 · Jan 18, 2023
Continuation In Part 17499942 · Oct 13, 2021
Related Publication 20240205231A1 · Jun 20, 2024
References Cited (54)
US 6009475A · Shrader · 1999 [cited by applicant]
US 6138162A · Pistriotto et al. · 2000 [cited by applicant]
US 7316029B1 · Parker et al. · 2008 [cited by applicant]
US 7383569B1 · Elgressy et al. · 2008 [cited by applicant]
US 7620985B1 · Bush et al. · 2009 [cited by applicant]
US 8166533B2 · Yuan · 2012 [cited by applicant]
US 8499348B1 · Rubin · 2013 [cited by applicant]
US 8677471B2 · Karels et al. · 2014 [cited by applicant]
US 9065850B1 · Sobrier · 2015 [cited by applicant]
US 9152789B2 · Natarajan et al. · 2015 [cited by applicant]
US 9773107B2 · White et al. · 2017 [cited by applicant]
US 10142362B2 · Weith et al. · 2018 [cited by applicant]
US 10154067B2 · Smith et al. · 2018 [cited by applicant]
US 10348599B2 · O'Neil et al. · 2019 [cited by applicant]
US 10362048B2 · Alexander et al. · 2019 [cited by applicant]
US 10419477B2 · Desai et al. · 2019 [cited by applicant]
US 10439985B2 · O'Neil · 2019 [cited by applicant]
US 10498605B2 · Weith et al. · 2019 [cited by applicant]
US 10505899B1 · Singh et al. · 2019 [cited by applicant]
US 11055417B2 · Bhatia · 2021 [cited by examiner]
US 11533314B2 · Badawy · 2022 [cited by examiner]
US 20050193222A1 · Greene · 2005 [cited by applicant]
US 20060095970A1 · Rajagopal et al. · 2006 [cited by applicant]
US 20070233477A1 · Halowani et al. · 2007 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20120246098A1 · Chari et al. · 2012 [cited by applicant]
US 20150242486A1 · Chari · 2015 [cited by examiner]
US 20160344770A1 · Verma et al. · 2016 [cited by applicant]
US 20170063886A1 · Muddu et al. · 2017 [cited by applicant]
US 20170078329A1 · Hwang et al. · 2017 [cited by applicant]
US 20170272465A1 · Steele · 2017 [cited by applicant]
US 20180041471A1 · Sudo et al. · 2018 [cited by applicant]
US 20180150758A1 · Niininen et al. · 2018 [cited by applicant]
US 20180293381A1 · Tseng et al. · 2018 [cited by applicant]
US 20190281073A1 · Weith et al. · 2019 [cited by applicant]
US 20190319972A1 · Desai · 2019 [cited by applicant]
US 20190349283A1 · O'Neil et al. · 2019 [cited by applicant]
US 20190349391A1 · Elsner · 2019 [cited by examiner]
US 20200021618A1 · Smith et al. · 2020 [cited by applicant]
US 20200133641A1 · Sinn · 2020 [cited by examiner]
US 20200236112A1 · Pularikkal et al. · 2020 [cited by applicant]
US 20200252405A1 · Sankavaram · 2020 [cited by examiner]
US 20200387956A1 · Toh · 2020 [cited by examiner]
US 20210168150A1 · Ross · 2021 [cited by examiner]
US 20230254318A1 · Hu et al. · 2023 [cited by applicant]
EP 4167116A1 · 2023 [cited by applicant]
WO 2018053337A1 · 2018 [cited by applicant]
WO 2018152303A1 · 2018 [cited by applicant]
Jordaney, Roberto, et al., “Transcend: Detecting concept drift in malware classification models,” 26th {USENIX} Security Symposium ({USENIX} Security 17), 2017. [cited by applicant]
Kantchelian, Alex, J. D. Tygar, and Anthony Joseph, “Evasion and hardening of tree ensemble classifiers,” International Conference on Machine Learning, 2016. [cited by applicant]
Tolomei, Gabriele, et al., “Interpretable predictions of tree-based ensembles via actionable feature tweaking,” Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. ACM, 20… [cited by applicant]
Aug. 13, 2019, International Preliminary Report on Patentability and Written Opinion for International Application No. PCT/US2018/015902. [cited by applicant]
Aug. 20, 2019, International Preliminary Report on Patentability and Written Opinion for International Application No. PCT/US2018/018325. [cited by applicant]
Feb. 28, 2023, European Search Report for European Patent Application No. 22 18 7223. [cited by applicant]