-
公开(公告)号:US20220286854A1
公开(公告)日:2022-09-08
申请号:US17699388
申请日:2022-03-21
Applicant: Zscaler, Inc.
Inventor: Nathan Howe , Kenneth B. Urquhart , Subramanian Srinivasan , Sridhar Kartik Kumar Chatnalli Deshpande , Patrick Foxhoven
Abstract: The present disclosure relates to systems and methods for cloud-based 5G security network architectures intelligent steering, workload isolation, identity, and secure edge steering. Specifically, various approaches are described to integrate cloud-based security services into Multiaccess Edge Compute servers (MECs). That is, existing cloud-based security services are in line between a UE and the Internet. The present disclosure includes integrating the cloud-based security services and associated cloud-based system within service provider's MECs. In this manner, a cloud-based security service can be integrated with a service provider's 5G network or a 5G network privately operated by the customer. For example, nodes in a cloud-based system can be collocated within a service provider's network, to provide security functions to 5G users or connected by peering from the cloud-based security service into the 5G service provider's regional communications centers.
-
公开(公告)号:US11438363B2
公开(公告)日:2022-09-06
申请号:US16839120
申请日:2020-04-03
Applicant: Zscaler, Inc.
Inventor: Nathan Howe
Abstract: Systems and methods include receiving a domain of interest; performing an analysis of the domain to extract namespaces of the domain, hosts associated with the domain, subdomains associated with the domain, namespaces of the subdomains, and addresses including address ranges of any identified namespaces; performing a Common Vulnerabilities and Exposures (CVE) search based on the analysis to identify a CVE list associated with the domain; determining weightings of the namespaces of the domain and the subdomains to provide a name list; obtaining cloud monitoring content associated with the domain; and utilizing the name list, the CVE list, and the cloud monitoring content to determine a risk associated with the domain.
-
公开(公告)号:US20220287151A1
公开(公告)日:2022-09-08
申请号:US17194568
申请日:2021-03-08
Applicant: Zscaler, Inc.
Inventor: Nathan Howe
Abstract: A method, implemented in a cloud-based system, includes, responsive to a client device having a Subscriber Identity Module (SIM) card therein connecting to a mobile network from a mobile network operator, receiving authentication of the client device based on the SIM card; receiving forwarded traffic from the client device; and processing the forwarded traffic according to policy, wherein the policy is determined based on one of a user of the client device and a type of the client device, each being determined based on the SIM card.
-
公开(公告)号:US20220286911A1
公开(公告)日:2022-09-08
申请号:US17491795
申请日:2021-10-01
Applicant: Zscaler, Inc.
Inventor: Nathan Howe , Kenneth B. Urquhart
Abstract: Cloud-based 5G security, implemented in a Multi-Access Edge Compute (MEC) system, includes steps of receiving a request for a workload from User Equipment (UE); determining a type of traffic for the workflow and querying a machine learning engine based on the traffic type; informing the UE of how the workflow should be accessed; and receiving an updated request for the workflow and steering the traffic based on how the workflow should be steered. The steps can include receiving policy updates from a cloud-based system, related to how workloads should be steered.
-
公开(公告)号:US12137082B2
公开(公告)日:2024-11-05
申请号:US17491831
申请日:2021-10-01
Applicant: Zscaler, Inc.
Inventor: Nathan Howe , Kenneth B. Urquhart
Abstract: Cloud-based 5G security, implemented in a Multi-Access Edge Compute (MEC) system, includes steps of receiving a request for a workload from User Equipment (UE) via a Radio Access Network (RAN); determining a path to the workload; creating a tunnel to the workload; and steering the request to the workload via the tunnel that is independent of any underlying mobile network for the RAN. The tunnel can be encrypted and used on a per-application and per-session basis.
-
公开(公告)号:US12010553B2
公开(公告)日:2024-06-11
申请号:US17491795
申请日:2021-10-01
Applicant: Zscaler, Inc.
Inventor: Nathan Howe , Kenneth B. Urquhart
CPC classification number: H04W28/0925 , H04L63/0227 , H04L63/029 , H04L63/1425 , H04W28/12
Abstract: Cloud-based 5G security, implemented in a Multi-Access Edge Compute (MEC) system, includes steps of receiving a request for a workload from User Equipment (UE); determining a type of traffic for the workflow and querying a machine learning engine based on the traffic type; informing the UE of how the workflow should be accessed; and receiving an updated request for the workflow and steering the traffic based on how the workflow should be steered. The steps can include receiving policy updates from a cloud-based system, related to how workloads should be steered.
-
公开(公告)号:US20240129321A1
公开(公告)日:2024-04-18
申请号:US18313446
申请日:2023-05-08
Applicant: Zscaler, Inc.
Inventor: Nathan Howe , Sanjit Ganguli , Gerard Festa
IPC: H04L9/40
CPC classification number: H04L63/126 , H04L63/20
Abstract: Systems and methods for a zero trust architecture are provided. A method, according to one implementation, includes detecting an initial attempt by an entity to connect, access, or communicate with a network resource and blocking the entity from initially connecting, accessing, or communicating with the network resource. The method also includes performing a verification procedure to verify one or more of an identity of the entity and a context of the initial attempt. The method also performs a control procedure to control one or more of malicious content and sensitive data. In addition, the method includes performing an enforcement procedure in response to results of the verification procedure and control procedure to determine how to handle the initial attempt.
-
公开(公告)号:US11596027B2
公开(公告)日:2023-02-28
申请号:US17194568
申请日:2021-03-08
Applicant: Zscaler, Inc.
Inventor: Nathan Howe
Abstract: A method, implemented in a cloud-based system, includes, responsive to a client device having a Subscriber Identity Module (SIM) card therein connecting to a mobile network from a mobile network operator, receiving authentication of the client device based on the SIM card; receiving forwarded traffic from the client device; and processing the forwarded traffic according to policy, wherein the policy is determined based on one of a user of the client device and a type of the client device, each being determined based on the SIM card.
-
公开(公告)号:US20220286860A1
公开(公告)日:2022-09-08
申请号:US17371408
申请日:2021-07-09
Applicant: Zscaler, Inc.
Inventor: Nathan Howe , Kenneth B. Urquhart
Abstract: A Multi-Access Edge Compute (MEC) system includes a plurality of compute resources including one or more processors configured to implement services; wherein the services include any of edge services, routing functions, and hosted services; and wherein the services further include cloud-based security services implemented in the MEC in conjunction with a cloud-based security system that includes a plurality of nodes and offers multi-tenant cloud-based security services, and wherein the cloud-based security services implemented in the MEC are for subscribers of a service provider associated with the MEC.
-
公开(公告)号:US20220286429A1
公开(公告)日:2022-09-08
申请号:US17491831
申请日:2021-10-01
Applicant: Zscaler, Inc.
Inventor: Nathan Howe , Kenneth B. Urquhart
Abstract: Cloud-based 5G security, implemented in a Multi-Access Edge Compute (MEC) system, includes steps of receiving a request for a workload from User Equipment (UE) via a Radio Access Network (RAN); determining a path to the workload; creating a tunnel to the workload; and steering the request to the workload via the tunnel that is independent of any underlying mobile network for the RAN. The tunnel can be encrypted and used on a per-application and per-session basis.
-
-
-
-
-
-
-
-
-