IP Library › Granted Patent US 12,647,392
Granted Patent B2
US 12,647,392 · App. 18/307,303 · Granted Jun 2, 2026

Disaster recovery for cloud-based monitoring of internet access

Inventors: Abhinav Bansal (San Jose, CA); Paul Yun Ling (San Jose, CA); Vikas Mahajan (Ludhiana, IN)
Assignee: Zscaler, Inc.
H04L63/0254G06F11/0709G06F11/0793
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,392
App. No.
18/307,303
Granted
Jun 2, 2026
Kind
B2
Abstract

Systems and methods include receiving one or more disaster recovery configurations; identifying activation of a disaster recovery mode; and controlling traffic flow such that the traffic is any of blocked to all destinations, allowed to all destinations, and allowed to preselected destinations based on the one or more received disaster recovery configurations.

Claims (34)

1 . A non-transitory computer-readable medium including instructions that, when executed, cause one or more processors to perform steps of:

receiving one or more disaster recovery configurations;

identifying activation of a disaster recovery mode, wherein the disaster recovery mode is triggered based on detection that a cloud-based system is unavailable to perform security processing for network traffic associated with a user device, the detection comprising receipt of or query of a Domain Name System (DNS) record signaling the unavailability; and

controlling traffic flow such that the traffic is any of blocked to all destinations, allowed to all destinations, and allowed to preselected destinations based on the one or more received disaster recovery configurations, wherein the disaster recovery configurations include preconfigured actions for the user device to perform local security processing based on cached policies when the cloud-based system is unavailable, the cached policies being dynamically updated based on prior cloud-enforced actions and tenant-specific configurations, and wherein conflicts between customer-defined and global default destination lists are deterministically resolved in favor of the customer-defined lists.

2 . The non-transitory computer-readable medium of claim 1 , wherein the steps further include:

updating a cache based on the actions taken during activation of the disaster recovery mode, wherein the actions include locally allowing or blocking traffic based on a previously cached policy when the cloud-based system is unavailable.

3 . The non-transitory computer-readable medium of claim 1 , wherein the one or more disaster recovery configurations are each associated with one or more specific tenants of a cloud-based system.

4 . The non-transitory computer-readable medium of claim 1 , wherein the one or more disaster recovery configurations include a list of global default destinations preselected by a cloud provider.

5 . The non-transitory computer-readable medium of claim 4 , wherein the one or more disaster recovery configurations additionally include one or more customer defined destination lists.

6 . The non-transitory computer-readable medium of claim 5 , wherein the one or more customer defined destination lists take priority over the list of global default destinations, and wherein conflicting entries between the lists are resolved in favor of the customer defined destination lists.

7 . The non-transitory computer-readable medium of claim 5 , wherein the list of global default destinations and the customer defined destination lists include domains which are instructed to be one of blocked or allowed.

8 . A cloud-based system comprising:

one or more processors; and

memory storing computer-executable instructions, wherein the computer-executable instructions cause the one or more processors to:

receive one or more disaster recovery configurations;

identify activation of a disaster recovery mode, wherein the disaster recovery mode is triggered based on detection that the cloud-based system is unavailable to perform security processing for network traffic associated with a user device, the detection comprising receipt of or query of a Domain Name System (DNS) record signaling the unavailability; and

control traffic flow such that the traffic is any of blocked to all destinations, allowed to all destinations, and allowed to preselected destinations based on the one or more received disaster recovery configurations, wherein the disaster recovery configurations include preconfigured actions for the user device to perform local security processing based on cached policies when the cloud-based system is unavailable, the cached policies being dynamically updated based on prior cloud-enforced actions and tenant-specific configurations, and wherein conflicts between customer-defined and global default destination lists are deterministically resolved in favor of the customer-defined lists.

9 . The cloud-based system of claim 8 , wherein the steps further include:

updating a cache based on the actions taken during activation of the disaster recovery mode, wherein the actions include locally allowing or blocking traffic based on a previously cached policy when the cloud-based system is unavailable.

10 . The cloud-based system of claim 8 , wherein the one or more disaster recovery configurations are each associated with one or more specific tenants of a cloud-based system.

11 . The cloud-based system of claim 8 , wherein the one or more disaster recovery configurations include a list of global default destinations preselected by a cloud provider.

12 . The cloud-based system of claim 11 , wherein the one or more disaster recovery configurations additionally include one or more customer defined destination lists.

13 . The cloud-based system of claim 12 , wherein the one or more customer defined destination lists take priority over the list of global default destinations, and wherein conflicting entries between the lists are resolved in favor of the customer defined destination lists.

14 . The cloud-based system of claim 12 , wherein the list of global default destinations and the customer defined destination lists include domains which are instructed to be one of blocked or allowed.

15 . A method comprising steps of:

receiving one or more disaster recovery configurations;

identifying activation of a disaster recovery mode, wherein the disaster recovery mode is triggered based on detection that a cloud-based system is unavailable to perform security processing for network traffic associated with a user device, the detection comprising receipt of or query of a Domain Name System (DNS) record signaling the unavailability; and

controlling traffic flow such that the traffic is any of blocked to all destinations, allowed to all destinations, and allowed to preselected destinations based on the one or more received disaster recovery configurations, wherein the disaster recovery configurations include preconfigured actions for the user device to perform local security processing based on cached policies when the cloud-based system is unavailable, the cached policies being dynamically updated based on prior cloud-enforced actions and tenant-specific configurations, and wherein conflicts between customer-defined and global default destination lists are deterministically resolved in favor of the customer-defined lists.

16 . The method of claim 15 , wherein the steps further include:

updating a cache based on the actions taken during activation of the disaster recovery mode, wherein the actions include locally allowing or blocking traffic based on a previously cached policy when the cloud-based system is unavailable.

17 . The method of claim 15 , wherein the one or more disaster recovery configurations are each associated with one or more specific tenants of a cloud-based system.

18 . The method of claim 15 , wherein the one or more disaster recovery configurations include a list of global default destinations preselected by a cloud provider.

19 . The method of claim 18 , wherein the one or more disaster recovery configurations additionally include one or more customer defined destination lists.

20 . The method of claim 19 , wherein the one or more customer defined destination lists take priority over the list of global default destinations, and wherein conflicting entries between the lists are resolved in favor of the customer defined destination lists.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2023
From: BANSAL, ABHINAV; LING, PAUL YUN; MAHAJAN, VIKAS
To: ZSCALER, INC.
Reel/Frame 063448/0569 →
Priority Claims (1)
IN 202311016582 · Mar 13, 2023 · national
Continuity (3)
Continuation In Part 17154139 · Jan 21, 2021
Continuation In Part 16922353 · Jul 7, 2020
Related Publication 20230262030A1 · Aug 17, 2023
References Cited (63)
US 7693059B2 · Osenbach et al. · 2010 [cited by applicant]
US 8464335B1 · Sinha et al. · 2013 [cited by applicant]
US 8495737B2 · Sinha et al. · 2013 [cited by applicant]
US 8695059B2 · Kopti · 2014 [cited by applicant]
US 8763071B2 · Sinha et al. · 2014 [cited by applicant]
US 8955091B2 · Kailash et al. · 2015 [cited by applicant]
US 9019962B1 · Ghosh · 2015 [cited by applicant]
US 9065800B2 · Devarajan et al. · 2015 [cited by applicant]
US 9350710B2 · Herle et al. · 2016 [cited by applicant]
US 9473537B2 · Sinha et al. · 2016 [cited by applicant]
US 9479357B1 · Fu · 2016 [cited by examiner]
US 9531758B2 · Devarajan et al. · 2016 [cited by applicant]
US 9609460B2 · Sinha · 2017 [cited by applicant]
US 9621574B2 · Desai et al. · 2017 [cited by applicant]
US 9912638B2 · Kailash et al. · 2018 [cited by applicant]
US 9935955B2 · Desai et al. · 2018 [cited by applicant]
US 10142362B2 · Weith et al. · 2018 [cited by applicant]
US 10237286B2 · Sharma et al. · 2019 [cited by applicant]
US 10243997B2 · Desai et al. · 2019 [cited by applicant]
US 10375024B2 · Foxhoven et al. · 2019 [cited by applicant]
US 10419477B2 · Desai et al. · 2019 [cited by applicant]
US 10498605B2 · Weith et al. · 2019 [cited by applicant]
US 10511590B1 · Bosch et al. · 2019 [cited by applicant]
US 10616180B2 · Chanak et al. · 2020 [cited by applicant]
US 10728117B1 · Sharma et al. · 2020 [cited by applicant]
US 10728287B2 · Foxhoven et al. · 2020 [cited by applicant]
US 10749907B2 · Sinha et al. · 2020 [cited by applicant]
US 11526403B1 · Ruslyakov · 2022 [cited by examiner]
US 11962589B2 · Foxhoven · 2024 [cited by examiner]
US 20100027549A1 · Satterlee et al. · 2010 [cited by applicant]
US 20100125903A1 · Devarajan et al. · 2010 [cited by applicant]
US 20100306486A1 · Balasubramanian · 2010 [cited by examiner]
US 20120281706A1 · Agarwal et al. · 2012 [cited by applicant]
US 20130061306A1 · Sinn · 2013 [cited by applicant]
US 20140020062A1 · Tumula et al. · 2014 [cited by applicant]
US 20150135302A1 · Cohen et al. · 2015 [cited by applicant]
US 20150282041A1 · Batchu et al. · 2015 [cited by applicant]
US 20150317194A1 · Sampath · 2015 [cited by examiner]
US 20160142374A1 · Clark · 2016 [cited by applicant]
US 20170091472A1 · Glading · 2017 [cited by examiner]
US 20170279803A1 · Desai et al. · 2017 [cited by applicant]
US 20170286236A1 · Protasov · 2017 [cited by examiner]
US 20170331859A1 · Bansal et al. · 2017 [cited by applicant]
US 20180113807A1 · Foxhoven et al. · 2018 [cited by applicant]
US 20180288062A1 · Goyal et al. · 2018 [cited by applicant]
US 20180343316A1 · Meyer · 2018 [cited by examiner]
US 20180357294A1 · Zhang · 2018 [cited by applicant]
US 20190068617A1 · Coleman · 2019 [cited by examiner]
US 20190141015A1 · Nellen · 2019 [cited by examiner]
US 20190268379A1 · Narayanaswamy et al. · 2019 [cited by applicant]
US 20200274783A1 · Sharma et al. · 2020 [cited by applicant]
US 20200274784A1 · Sharma et al. · 2020 [cited by applicant]
US 20200358669A1 · Sinha et al. · 2020 [cited by applicant]
US 20200402065A1 · Kapur et al. · 2020 [cited by applicant]
US 20210034992A1 · Mukeri · 2021 [cited by examiner]
US 20220103594A1 · Galloway · 2022 [cited by examiner]
US 20220210197A1 · Vaner et al. · 2022 [cited by examiner]
US 20220360562A1 · Hanes · 2022 [cited by examiner]
Network-Independent Support for Using Multiple IP Interface in Applications, IEEE Conference Paper, 2011 Conference on Network and Information Systems Security, Famulari, A, Hecker, A. Abstract Only (Year: 2011). [cited by applicant]
Multipath cloud federation Publication Date: Sep. 1, 2017, Electronic Publication Date: Oct. 18, 2017 Published in: 2017 IEEE 6th International Conference on Cloud Networking (CioudNet) (pp. 1-6), Mael Kimmerlin, Peer H… [cited by applicant]
Tsunami: A parasitic, indestructible botnet on Kad, Author: Memon, Ghulam; Li, Jun; Rejaie, Reza, Abstract Only Publication info: Peer-To-Peer Networking and Applications 7.4: 444-455, Springer Science & Business Media,… [cited by applicant]
A cluster-based countermeasure against blackhole attacks in MANETs, Author: Shi, Fei; Liu, Weijie; Jin, Dongxu; Song, Jooseok, Abstract Only, Publication info: Telecommunication Systems 57.2: 119-136. Springer Science &… [cited by applicant]
Remote access VPNs: Selection and deployment issues, Author: King, Christopher M, Abstract Only Publication info: Business Communications Review 30.6: 52-56. UBM LLC. (Jun. 2000) (Year: 2000). [cited by applicant]