IP Library › Granted Patent US 12,598,216
Granted Patent B2
US 12,598,216 · App. 18/631,478 · Granted Apr 7, 2026

Small-footprint endpoint data loss prevention

Inventors: Krishna Narayanaswamy (Saratoga, CA); Ajay Agrawal (Bangalore, IN)
Assignee: Netskope, Inc.
H04L63/20G06F16/285G06F16/951G06F21/6209H04L63/0281H04L63/10H04L63/104H04L63/105H04L63/12G06F16/1734
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,216
App. No.
18/631,478
Granted
Apr 7, 2026
Kind
B2
Abstract

The technology disclosed relates to endpoint data loss prevention (DLP). In particular, the technology disclosed relates to enforcing data loss prevention policies at an endpoint without needing to perform content sensitivity scan at the endpoint.

Claims (75)

1 . An endpoint data loss prevention system, comprising:

a monitor, executing on an endpoint, configured to detect data egress requests from the endpoint to uncontrolled destinations, wherein each data egress request comprises an associated file;

a local metadata store on the endpoint having stored therein sensitivity metadata, wherein:

the sensitivity metadata classifies a sensitivity of a respective file and is generated by a cloud-based content sensitivity scanner using deep inspection of the respective file and stored in a cloud-based metadata store, and

the local metadata store is synchronized with the cloud-based metadata store periodically;

an endpoint policy enforcer, executing on the endpoint, configured to:

receive an indication of the data egress requests from the monitor,

in response to each data egress request, obtain the sensitivity metadata for the associated file of the data egress request, and

enforce data loss prevention policies on the data egress requests based on the sensitivity metadata; and

an anchor pattern scanner, executing on the endpoint, configured to:

in response to scan requests associated with unscanned files, classifying the unscanned file as sensitive or non-sensitive based on an anchor pattern scan,

in response to the unscanned file being classified as non-sensitive, transmit a non-sensitive indication to the endpoint policy enforcer as the sensitivity metadata, and

in response to the unscanned file being classified as sensitive:

transmit the unscanned file to the cloud-based content sensitivity scanner;

receive the sensitivity metadata for the unscanned file from the cloud-based content sensitivity scanner; and

transmit the sensitivity metadata provided by the cloud-based content sensitivity scanner to the endpoint policy enforcer.

2 . The endpoint data loss prevention system of claim 1 , wherein the endpoint policy enforcer is further configured to:

request the sensitivity metadata from the local metadata store.

3 . The endpoint data loss prevention system of claim 2 , wherein the endpoint policy enforcer is further configured to:

in response to a negative response from the local metadata store, request the sensitivity metadata from the cloud-based metadata store.

4 . The endpoint data loss prevention system of claim 3 , wherein the endpoint policy enforcer is further configured to:

in response to a negative response from the cloud-based metadata store, send a scan request to the anchor pattern scanner indicating the associated file is an unscanned file.

5 . The endpoint data loss prevention system of claim 4 , wherein the endpoint policy enforcer is further configured to:

in response to receiving the non-sensitive indication from the anchor pattern scanner, allow the data egress request.

6 . The endpoint data loss prevention system of claim 4 , wherein the endpoint policy enforcer is further configured to:

in response to receiving the sensitivity metadata from the anchor pattern scanner, store the sensitivity metadata in the local metadata store.

7 . The endpoint data loss prevention system of claim 1 , wherein the monitor is a file system monitor.

8 . The endpoint data loss prevention system of claim 1 , wherein the monitor is an endpoint traffic monitor.

9 . The endpoint data loss prevention system of claim 1 , wherein the endpoint policy enforcer is further configured to:

for each data egress request, put the data egress request on hold until the sensitivity metadata for the associated file is obtained.

10 . The endpoint data loss prevention system of claim 1 , wherein the anchor pattern scan comprises scanning the unscanned file for:

social security numbers;

credit card numbers;

bank account numbers;

dates of birth;

passwords;

source code; or

a combination thereof.

11 . The endpoint data loss prevention system of claim 1 , wherein the sensitivity metadata in the local metadata store comprises data generated by the cloud-based content sensitivity scanner while the respective files were resident in a cloud-based document store.

12 . The endpoint data loss prevention system of claim 1 , wherein the sensitivity metadata in the local metadata store comprises data generated by the cloud-based content sensitivity scanner in response to the respective files being transmitted to or from a cloud-based document store.

13 . A method for enforcing data loss prevention at an endpoint, the method comprising:

maintaining, on the endpoint, a local metadata store comprising sensitivity metadata, wherein:

the sensitivity metadata classifies a sensitivity of a respective file and is generated by a cloud-based content sensitivity scanner using deep inspection of the respective file and stored in a cloud-based metadata store, and

the local metadata store is synchronized with the cloud-based metadata store periodically;

intercepting, with a monitor executing on the endpoint, data egress requests from the endpoint to uncontrolled destinations, wherein each data egress request comprises an associated file;

receiving, by an endpoint policy enforcer, an indication of the data egress requests from the monitor;

in response to each data egress request, obtaining, by the endpoint policy enforcer, the sensitivity metadata for the associated file of the data egress request; and

enforcing, by the endpoint policy enforcer, data loss prevention policies on the data egress requests based on the sensitivity metadata.

14 . The method of claim 13 , wherein the obtaining the sensitivity metadata comprises:

requesting, by the endpoint policy enforcer, the sensitivity metadata from the local metadata store.

15 . The method of claim 14 , wherein the obtaining the sensitivity metadata further comprises:

in response to a negative response from the local metadata store, requesting, by the endpoint policy enforcer, the sensitivity metadata from the cloud-based metadata store.

16 . The method of claim 15 , wherein the obtaining the sensitivity metadata further comprises:

in response to a negative response from the cloud-based metadata store, determining, by the endpoint policy enforcer, that the associated file is an unscanned file;

transmitting, by the endpoint policy enforcer, a request to scan the unscanned file to an anchor pattern scanner;

classifying, by the anchor pattern scanner, the unscanned file as sensitive or non-sensitive based on an anchor pattern scan, wherein the classifying comprises:

in response to the unscanned file being classified as non-sensitive, transmit a non-sensitive indication to the endpoint policy enforcer as the sensitivity metadata, and

in response to the unscanned file being classified as sensitive:

transmit the unscanned file to the cloud-based content sensitivity scanner;

receive the sensitivity metadata for the unscanned file from the cloud-based content sensitivity scanner; and

transmit the sensitivity metadata provided by the cloud-based content sensitivity scanner to the endpoint policy enforcer.

17 . The method of claim 16 , further comprising:

in response to receiving the non-sensitive indication from the anchor pattern scanner, allowing, by the endpoint policy enforcer, the data egress request.

18 . The method of claim 16 , further comprising:

in response to receiving the sensitivity metadata from the anchor pattern scanner, storing, by the endpoint policy enforcer, the sensitivity metadata in the local metadata store.

19 . The method of claim 16 , wherein the anchor pattern scanner scans the unscanned file for:

social security numbers;

credit card numbers;

bank account numbers;

dates of birth;

passwords;

source code; or

a combination thereof.

20 . The method of claim 13 , further comprising:

for each data egress request, putting, by the endpoint policy enforcer, the data egress request on hold until the sensitivity metadata for the associated file is obtained.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2024
From: NARAYANASWAMY, KRISHNA; AGRAWAL, AJAY
To: NETSKOPE, INC.
Reel/Frame 067279/0486 →
Continuity (8)
Continuation 17831437 · Jun 2, 2022
Continuation 16408215 · May 9, 2019
Continuation In Part 16000132 · Jun 5, 2018
Continuation 15368240 · Dec 2, 2016
Continuation 15368246 · Dec 2, 2016
Provisional Application 62675692 · May 23, 2018
Provisional Application 62307305 · Mar 11, 2016
Related Publication 20240259434A1 · Aug 1, 2024
References Cited (144)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 7996373B1 · Zoppas et al. · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8321560B1 · Pai et al. · 2012 [cited by applicant]
US 8365243B1 · Lu et al. · 2013 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8800024B2 · Cooper et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9076004B1 · Bogorad · 2015 [cited by applicant]
US 9141808B1 · Agrawal et al. · 2015 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9219715B2 · Lester et al. · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9692759B1 · Chandrasekhar · 2017 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10079835B1 · Dodke et al. · 2018 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10148694B1 · Sarin et al. · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10248797B1 · Shinde et al. · 2019 [cited by applicant]
US 10284586B1 · Shinde et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10366242B2 · Balinsky et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10447720B1 · Evans et al. · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11019101B2 · Narayanaswamy et al. · 2021 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11425169B2 · Narayanaswamy · 2022 [cited by examiner]
US 11595312B2 · Savarese et al. · 2023 [cited by applicant]
US 11985170B2 · Narayanaswamy · 2024 [cited by examiner]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030145226A1 · Bruton, III · 2003 [cited by examiner]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-LeMair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20040183815A1 · Ebert · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140007182A1 · Qureshi et al. · 2014 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140337808A1 · Armitage · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150074409A1 · Reid et al. · 2015 [cited by applicant]
US 20150074744A1 · Mclean et al. · 2015 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160171239A1 · Li et al. · 2016 [cited by applicant]
US 20160275303A1 · Narayanaswamy et al. · 2016 [cited by applicant]
US 20160285835A1 · Linga et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170264619A1 · Narayanaswamy et al. · 2017 [cited by applicant]
US 20170264640A1 · Narayanaswamy et al. · 2017 [cited by applicant]
US 20170353496A1 · Pai et al. · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20190268379A1 · Narayanaswamy · 2019 [cited by examiner]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20210314342A1 · Oberg · 2021 [cited by examiner]
US 20210367976A1 · Khurshid et al. · 2021 [cited by applicant]
US 20210400071A1 · Ray · 2021 [cited by examiner]
EP 1063833A2 · 2000 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
Mccullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜: text=mode of communication.-, What are the different email proto… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 17/878,875 Notice of Allowance mailed Sep. 18, 2024, 18 pages. [cited by applicant]
European Application No. 21191734.9 Communication pursuant to Article 94(3) EPC mailed Dec. 18, 2024, 4 pages. [cited by applicant]
“Eleven Essential Findings from Skyhigh's Q4 2015 Cloud Report”, Cloud Security Alliance, Nov. 4, 2015, 7 pages. [cited by applicant]