IP Library Granted Patent US 11,265,337
Granted Patent B2
US 11,265,337 · App. 16/402,935 · Granted Mar 1, 2022

Systems and methods for traffic inspection via an embedded browser

Inventors: Alexandr Smelov (Fort Lauderdale, FL); Christopher Fleck (Fort Lauderdale, FL)
Assignee: Citrix Systems, Inc.
H04L63/1425H04L43/06H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,265,337
App. No.
16/402,935
Granted
Mar 1, 2022
Kind
B2
Abstract

Described embodiments provide systems and methods for traffic inspection via embedded browsers. An application inspector module of an embedded browser executable on a client may intercept network traffic for an application. The network traffic may include packets exchanged between the application and the server via a channel. The application inspector module may identify a computing resource usage on the client in providing a user with access to the application via the embedded browser. The application inspector module may generate analytics data based on the intercepted network traffic and the computing resource usage. The application inspector module may maintain a user behavior profile based on the analytics data. The application inspector module may determine that a portion of the network traffic directed to the remote server contains sensitive information. Responsive to the determination, the application inspector module may block or remove the portion of the network traffic.

Claims (28)

1. A method of monitoring a network application, the method comprising:

monitoring, by a client application on a client device, traffic of a first network application hosted on a server and at least one computing resource on the client device, the client application providing the client device with access to a plurality of network applications including the first network application via an embedded browser of the client application;

generating, by the client application, analytics data according to the monitored traffic of the first network application and the monitored at least one computing resource on the client device;

using, by the client application, a user behavior model having a set of weights determined using the analytics data, to identify anomalous activity associated with the first network application; and

restricting, by the client application, in response to identifying the anomalous activity, access to the first network application.

2. The method of claim 1 , further comprising determining, by the client application using the user behavior model, whether to restrict first data in the monitored traffic.

3. The method of claim 2 , further comprising monitoring, by the client application, the first data including one or more operations on the embedded browser.

4. The method of claim 2 , further comprising determining, by the client application, a deviation measure between the first data and expected data generated by the user behavior model to determine whether to restrict the first data, the deviation measure indicating a degree of anomalousness in the first data.

5. The method of claim 1 , wherein monitoring the traffic further comprises monitoring the traffic exchanged via a secure communications channel between the first network application hosted on the server and the client device.

6. The method of claim 1 , wherein monitoring the traffic further comprising monitoring the traffic originating from the client device providing access to the first network application.

7. The method of claim 1 , wherein generating the analytics data further comprises acquiring second analytics data from a telemetry tracker to combine with the analytics data, the telemetry tracker having visibility to the traffic originating from the server hosting the first network application.

8. The method of claim 1 , wherein the analytics data includes at least one of a computing resource performance metric, a network traffic performance metric, or metadata.

9. The method of claim 1 , further comprising training, by the client application, the user behavior model using the analytics data.

10. The method of claim 1 , further comprising determining, by the client application via application of at least one policy, whether to restrict first data in the monitored traffic.

11. A system for monitoring a network application, the system comprising:

an embedded browser of a client application executable on one or more processors of a client device, the embedded browser configured to monitor traffic of a first network application hosted on a server and at least one computing resource on the client device, the client application providing the client device with access to a plurality of network applications including the first network application;

an analytics tracking engine of the client application executable on the one or more processors, the analytics tracking engine configured to generate analytics data according to the monitored traffic of the first network application and the monitored at least one computing resource on the client device; and

a behavior modeler engine of the client application executable on the one or more processors, the behavior modeler engine configured to use a user behavior model having a set of weights determined using the analytics data, to identify anomalous activity associated with the first network application; and

the client device configured to restrict, in response to identifying the anomalous activity, access to the first network application.

12. The system of claim 11 , wherein the client application is further configured to determine, using the user behavior model, whether to restrict first data in the monitored data.

13. The system of claim 12 , wherein the client application is further configured to monitor the first data including one or more operations on the embedded browser.

14. The system of claim 12 , wherein the client application is further configured to determine a deviation measure between the first data and expected data generated by the user behavior model to determine whether to restrict the first data, the deviation measure indicating a degree of anomalousness in the first data.

15. The system of claim 11 , wherein the analytics tracking engine is further configured to monitor the traffic exchanged via a secure communications channel between the first network application hosted on the server and the client device.

16. The system of claim 11 , wherein the analytics tracking engine is further configured to monitor the traffic originating from the client device providing access to the first network application.

17. The system of claim 11 , wherein the analytics tracking engine is further configured to acquire second analytics data from a telemetry tracker to combine with the analytics data, the telemetry tracker having visibility to the traffic originating from the server hosting the first network application.

18. The system of claim 11 , wherein the analytics data includes at least one of a computing resource performance metric, a network traffic performance metric, or metadata.

19. The system of claim 11 , wherein the behavior modeler engine is further configured to train the user behavior model using the analytics data.

20. The system of claim 11 , wherein the client application is further configured to determine, via application of at least one policy, whether to restrict first data in the monitored traffic.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2019
From: SMELOV, ALEXANDR; FLECK, CHRISTOPHER
To: CITRIX SYSTEMS, INC.
Reel/Frame 049186/0218 →
Continuity (2)
Provisional Application 62667211 · May 4, 2018
Related Publication 20190342315A1 · Nov 7, 2019
Cited By (5)
US 12,401,563 US 12,407,730 US 12,413,624 US 12,445,493 US 12,452,306