Distributed cloud-based security systems and methods

US2016269447A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016269447-A1
Application numberUS-201615162840-A
CountryUS
Kind codeA1
Filing dateMay 24, 2016
Priority dateJul 24, 2008
Publication dateSep 15, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A distributed security method is implemented in a processing node of a distributed security system comprising one or more processing nodes and one or more authority nodes, wherein the distributed security system is located external to a network edge of an enterprise and external from one of a computer device and a mobile device associated with a user. The distributed security method includes obtaining security policy data associated with the user and the enterprise from an authority node; monitoring data communications between the user, the enterprise, and the Internet in a processing node; and controlling the data communications between the user, the enterprise, and the Internet based on the monitoring to provide security measures between the user, the enterprise, and the Internet.

First claim

Opening claim text (preview).

What is claimed is: 1 . A distributed security method implemented in a processing node of a distributed security system comprising one or more processing nodes and one or more authority nodes, wherein the distributed security system is located external to a network edge of an enterprise and external from one of a computer device and a mobile device associated with a user, the distributed security method comprising: obtaining security policy data associated with the user and the enterprise from an authority node; monitoring data communications between the user, the enterprise, and the Internet in a processing node; and controlling the data communications between the user, the enterprise, and the Internet based on the monitoring to provide security measures between the user, the enterprise, and the Internet. 2 . The distributed security method of claim 1 , wherein the monitoring comprises: operating one or more data inspection engines on content items in the data communications to determine a decision vector, wherein the controlling is based on the decision vector. 3 . The distributed security method of claim 2 , wherein master security for the data inspection engines is provided by the authority node based on updates received from the one or more processing nodes. 4 . The distributed security method of claim 2 , wherein the one or more data inspection engines comprise a detection processing filter which front ends threat data, wherein the detection processing filter is used first on the content items to reduce processing time thereof. 5 . The distributed security method of claim 1 , further comprising: maintaining a state of the user related to authentication of the user comprising validation of an identity of the user and authorization of the user comprising eligibility of a validate user to complete an action. 6 . The distributed security method of claim 5 , wherein the state is maintained at the processing node, and wherein the authority node and the processing node operate cooperatively to identify fraudulently generated authentication data or authorization data. 7 . The distributed security method of claim 1 , wherein the security threats comprise spyware, malware, viruses, spam, and undesirable content. 8 . A processing node in a distributed security system comprising one or more processing nodes and one or more authority nodes, wherein the distributed security system is located external to a network edge of an enterprise and external from one of a computer device and a mobile device associated with a user, the processing node: one or more processors; and memory storing instructions that, when executed, cause the one or processors to obtain security policy data associated with the user and the enterprise from an authority node; monitor data communications between the user, the enterprise, and the Internet in a processing node; and control the data communications between the user, the enterprise, and the Internet based on monitoring the data communications to provide security measures between the user, the enterprise, and the Internet. 9 . The processing node of claim 8 , wherein the processing node monitors the data communications through operation of one or more data inspection engines on content items in the data communications to determine a decision vector, wherein the data communications are controlled is based on the decision vector. 10 . The processing node of claim 9 , wherein master security for the data inspection engines is provided by the authority node based on updates received from the one or more processing nodes. 11 . The processing node of claim 9 , wherein the one or more data inspection engines comprise a detection processing filter which front ends threat data, wherein the detection processing filter is used first on the content items to reduce processing time thereof. 12 . The processing node of claim 9 , wherein the memory storing instructions that, when executed, further cause the one or processors to maintain a state of the user related to authentication of the user comprising validation of an identity of the user and authorization of the user comprising eligibility of a validate user to complete an action. 13 . The processing node of claim 12 , wherein the state is maintained at the processing node, and wherein the authority node and the processing node operate cooperatively to identify fraudulently generated authentication data or authorization data. 14 . The processing node of claim 9 , wherein the security threats comprise spyware, malware, viruses, spam, and undesirable content. 15 . A distributed security system, comprising: one or more processing nodes and one or more authority nodes, wherein the distributed security system is located external to a network edge of an enterprise and external from one of a computer device and a mobile device associated with a user; where each of the one or more processing nodes comprises one or more processors and memory storing instructions that, when executed, cause the one or processors to obtain security policy data associated with the user and the enterprise from an authority node; monitor data communications between the user, the enterprise, and the Internet in a processing node; and control the data communications between the user, the enterprise, and the Internet based on monitoring the data communications to provide security measures between the user, the enterprise, and the Internet. 16 . The distributed security system of claim 15 , wherein the processing node monitors the data communications through operation of one or more data inspection engines on content items in the data communications to determine a decision vector, wherein the data communications are controlled is based on the decision vector. 17 . The distributed security system of claim 16 , wherein master security for the data inspection engines is provided by the authority node based on updates received from the one or more processing nodes. 18 . The distributed security system of claim 16 , wherein the one or more data inspection engines comprise a detection processing filter which front ends threat data, wherein the detection processing filter is used first on the content items to reduce processing time thereof. 19 . The distributed security system of claim 15 , wherein the memory storing instructions that, when executed, further cause the one or processors to maintain a state of the user related to authentication of the user comprising validation of an identity of the user and authorization of the user comprising eligibility of a validate user to complete an action. 20 . The distributed security system of claim 19 , wherein the state is maintained at the processing node, and wherein the authority node and the processing node operate cooperatively to identify fraudulently generated authentication data or authorization data.

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • Entity profiles · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • H04L9/3213Primary

    using tickets or tokens, e.g. Kerberos (network architectures or network communication protocols for entities authentication using tickets in a packet data network H04L63/0807) · CPC title

  • providing single-sign-on or federations · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016269447A1 cover?
A distributed security method is implemented in a processing node of a distributed security system comprising one or more processing nodes and one or more authority nodes, wherein the distributed security system is located external to a network edge of an enterprise and external from one of a computer device and a mobile device associated with a user. The distributed security method includes ob…
Who is the assignee on this patent?
Zscaler Inc
What technology area does this patent fall under?
Primary CPC classification H04L9/3213. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Sep 15 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).