Dynamic user identification and policy enforcement in cloud-based secure web gateways

US9531758B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9531758-B2
Application numberUS-201514712154-A
CountryUS
Kind codeB2
Filing dateMay 14, 2015
Priority dateMar 18, 2011
Publication dateDec 27, 2016
Grant dateDec 27, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A cloud-based secure Web gateway, a cloud-based secure Web method, and a network deliver a secure Web gateway (SWG) as a cloud-based service to organizations and provide dynamic user identification and policy enforcement therein. As a cloud-based service, the SWG systems and methods provide scalability and capability of accommodating multiple organizations therein with proper isolation therebetween. There are two basic requirements for the cloud-based SWG: (i) Having some means of forwarding traffic from the organization or its users to the SWG nodes, and (ii) Being able to authenticate the organization and users for policy enforcement and access logging. The SWG systems and methods dynamically associate traffic to users regardless of the source (device, location, encryption, application type, etc.), and once traffic is tagged to a user/organization, various polices can be enforced and audit logs of user access can be maintained.

First claim

Opening claim text (preview).

What is claimed is: 1. A cloud-based gateway, comprising: a network interface communicatively coupled to a network; a processor; and memory storing instructions that, when executed, cause the processor to: dynamically associate traffic received on the network interface with users to form a dynamic association, wherein the traffic comprises a combination of authenticated traffic and unknown traffic, wherein the authenticated traffic is associated to an authenticated user and the unknown traffic is associated to an associated user of a destination Internet Protocol (IP) address from the unknown traffic; maintain the dynamic association over time, wherein the dynamic association is maintained over time by updating the dynamic association based on newly received authenticated HTTP traffic, on pre-defined time thresholds for expiring associations, and on detecting collisions of multiple users on the destination IP address; and apply policies to the traffic based on the dynamic association. 2. The cloud-based gateway of claim 1 , wherein an association is pre-configured between an organization and a destination port to identify traffic originating from the organization. 3. The cloud-based gateway of claim 2 , wherein the instructions, when executed, further cause the processor to: perform authentication challenges for known traffic to identify the destination port periodically and to detect fraudulent use. 4. The cloud-based gateway of claim 1 , wherein the authenticated traffic is authenticated Hypertext Transfer Protocol (HTTP) traffic. 5. The cloud-based gateway of claim 1 , wherein the unknown traffic is associated to the associated user based on determining the associated user through authenticated HTTP traffic from a same destination IP address. 6. The cloud-based gateway of claim 1 , wherein the instructions, when executed, further cause the processor to: map the unknown traffic to an organization depending on whether the destination IP address is private or specific to the organization when multiple users are determined on the destination IP address based on seeing multiple users through authenticated HTTP traffic thereon. 7. The cloud-based gateway of claim 1 , wherein the traffic is received via generic routing encapsulation (GRE). 8. The cloud-based gateway of claim 1 , wherein the traffic is received via a virtual private network (VPN). 9. The cloud-based gateway of claim 1 , wherein the traffic is received via an explicit Proxy mode. 10. The cloud-based gateway of claim 1 , wherein the cloud-based gateway is a node in a distributed security system, and wherein the node is configured to receive dynamic associations from other nodes in the distributed security system. 11. A cloud-based gateway method, implemented by a gateway server, comprising: dynamically associating traffic received on a network with users to form a dynamic association, wherein the traffic comprises a combination of authenticated traffic and unknown traffic, wherein the authenticated traffic is associated to an authenticated user and the unknown traffic is associated to an associated user of a destination Internet Protocol (IP) address from the unknown traffic; maintaining the dynamic association over time by updating the dynamic association based on newly received authenticated HTTP traffic, on pre-defined time thresholds for expiring associations, and on detecting collisions of multiple users on the destination IP address; applying policies to the traffic based on the dynamic association. 12. The cloud-based gateway method of claim 11 , further comprising: pre-configuring an association between an organization and a destination port to identify traffic originating from the organization. 13. The cloud-based gateway method of claim 12 , further comprising: performing authentication challenges for known traffic to identify the destination port periodically and to detect fraudulent use. 14. The cloud-based gateway method of claim 11 , wherein the authenticated traffic is authenticated Hypertext Transfer Protocol (HTTP) traffic. 15. The cloud-based gateway method of claim 11 , wherein the unknown traffic is associated to the associated user based on determining the user through authenticated HTTP traffic from a same destination IP address. 16. The cloud-based gateway method of claim 11 , further comprising: mapping the unknown traffic to an organization depending on whether the destination IP address is private or specific to the organization when multiple users are determined on the destination IP address based on seeing multiple users through authenticated HTTP traffic thereon. 17. The cloud-based gateway method of claim 11 , wherein the traffic is received via one of generic routing encapsulation (GRE), a virtual private network (VPN), and an explicit Proxy mode. 18. A network, comprising: a distributed cloud-based security system coupled to the Internet; a plurality of cloud-based gateways within the distributed cloud-based security system; and a plurality of users accessing the Internet through the distributed cloud-based security system; wherein each of the plurality of cloud-based gateways is configured to: dynamically associate traffic received on the network interface with users to form a dynamic association, wherein the traffic comprises a combination of authenticated traffic and unknown traffic, wherein the authenticated traffic is associated to an authenticated user and the unknown traffic is associated to an associated user of a destination Internet Protocol (IP) address from the unknown traffic; maintain the dynamic association over time, wherein the dynamic association is maintained over time by updating the dynamic association based on newly received authenticated HTTP traffic, on pre-defined time thresholds for expiring associations, and on detecting collisions of multiple users on the destination IP address; and apply policies to the traffic based on the dynamic association. 19. The network of claim 18 , wherein the authenticated traffic is authenticated Hypertext Transfer Protocol (HTTP) traffic. 20. The network of claim 18 , wherein the unknown traffic is associated to the associated user based on determining the user through authenticated HTTP traffic from a same destination IP address.

Assignees

Inventors

Classifications

  • G06F21/51Primary

    at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability · CPC title

  • Electricity · mapped topic

  • Physics · mapped topic

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9531758B2 cover?
A cloud-based secure Web gateway, a cloud-based secure Web method, and a network deliver a secure Web gateway (SWG) as a cloud-based service to organizations and provide dynamic user identification and policy enforcement therein. As a cloud-based service, the SWG systems and methods provide scalability and capability of accommodating multiple organizations therein with proper isolation therebet…
Who is the assignee on this patent?
Devarajan Srikanth, Narasimhan Sridhar, Sinha Amit, and 2 more
What technology area does this patent fall under?
Primary CPC classification G06F21/51. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 27 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).