US2023164116A1PendingUtilityA1

Multi-tenant cloud-based firewall systems and methods

Assignee: ZSCALER INCPriority: Nov 17, 2015Filed: Jan 27, 2023Published: May 25, 2023
Est. expiryNov 17, 2035(~9.3 yrs left)· nominal 20-yr term from priority
H04L 63/0218H04L 63/0254H04L 67/10H04L 67/146H04L 67/141H04L 43/028
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Multi-tenant cloud-based firewall systems and methods are described. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls. The firewall systems and methods can protect users at user level control, regardless of location, device, etc., over all ports and protocols (not only ports 80/443) while providing administrators a single unified policy for Internet access and integrated reporting and visibility. The firewall systems and methods can eliminate dedicated hardware at user locations, providing a software-based cloud solution. The firewall systems and methods support application awareness to identify application; user awareness to identify users, groups, and locations regardless of physical address; visibility and policy management providing unified administration, policy management, and reporting; threat protection and compliance to block threats and data leaks in real-time; high performance through an in-line cloud-based, scalable system; etc.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A non-transitory computer-readable storage medium having computer readable code stored thereon for programming a processor, in a node of a cloud-based security system, to perform steps of:
 receiving one or more packets, the one or more packets being received from a network device external to the node;   processing the one or more packets utilizing firewall policies of one or more firewall sessions to determine whether or not to block the one or more packets from transmission over a network;   logging information associated with the one or more firewall sessions; and   producing a report based on the logging of the one or more firewall sessions, the report including a plurality of fields associated with the one or more packets processed by the one or more firewall sessions.   
     
     
         2 . The non-transitory computer-readable storage medium of  claim 1 , wherein the report includes information identifying top destinations traversing the network and top firewall threats detected by the one or more firewall sessions. 
     
     
         3 . The non-transitory computer-readable storage medium of  claim 1 , wherein the logging is configured for one of aggregate logging and full logging. 
     
     
         4 . The non-transitory computer-readable storage medium of  claim 1 , wherein the report is produced as one of a real-time report generated by compressed stats and an analyze report generated by full session log analysis. 
     
     
         5 . The non-transitory computer-readable storage medium of  claim 1 , wherein the steps include producing a plurality of reports, and wherein the plurality of reports are produced for any of a particular user, a particular Internet Protocol (IP) address, or group of IP addresses. 
     
     
         6 . The non-transitory computer-readable storage medium of  claim 1 , wherein the steps further include:
 providing an interactive display of firewall insights, the display including graphs of usage trends through the one or more firewall sessions.   
     
     
         7 . The non-transitory computer-readable storage medium of  claim 1 , wherein the steps further include:
 receiving an update based on detection of zero-day/zero-hour threats based on the report; and   updating the one or more firewall sessions based on the update.   
     
     
         8 . A node in a cloud-based security system, comprising:
 a processor and memory storing instructions that, when executed, cause the processor to:
 receive one or more packets, the one or more packets being received from a network device external to the node; 
 process the one or more packets utilizing firewall policies of one or more firewall sessions to determine whether or not to block the one or more packets from transmission over a network; 
 log information associated with the one or more firewall sessions; and 
 produce a report based on the logging of the one or more firewall sessions, the report including a plurality of fields associated with the one or more packets processed by the one or more firewall sessions. 
   
     
     
         9 . The node of  claim 8 , wherein the report includes information identifying top destinations traversing the network and top firewall threats detected by the one or more firewall sessions. 
     
     
         10 . The node of  claim 8 , wherein the logging is configured for one of aggregate logging and full logging. 
     
     
         11 . The node of  claim 8 , wherein the report is produced as one of a real-time report generated by compressed stats and an analyze report generated by full session log analysis. 
     
     
         12 . The node of  claim 8 , wherein the instructions cause the processor to produce a plurality of reports, and wherein the plurality of reports are produced for any of a particular user, a particular Internet Protocol (IP) address, or group of IP addresses. 
     
     
         13 . The node of  claim 8 , wherein the instructions further cause the processor to:
 provide an interactive display of firewall insights, the display including graphs of usage trends through the one or more firewall sessions.   
     
     
         14 . The node of  claim 8 , wherein the instructions further cause the processor to:
 receive an update based on detection of zero-day/zero-hour threats based on the report; and   update the one or more firewall sessions based on the update.   
     
     
         15 . A method implemented in a node of a cloud-based security system, the method comprising steps of:
 receiving one or more packets, the one or more packets being received from a network device external to the node;   processing the one or more packets utilizing firewall policies of one or more firewall sessions to determine whether or not to block the one or more packets from transmission over a network;   logging information associated with the one or more firewall sessions; and   producing a report based on the logging of the one or more firewall sessions, the report including a plurality of fields associated with the one or more packets processed by the one or more firewall sessions.   
     
     
         16 . The method of  claim 15 , wherein the report includes information identifying top destinations traversing the network and top firewall threats detected by the one or more firewall sessions. 
     
     
         17 . The method of  claim 15 , wherein the logging is configured for one of aggregate logging and full logging. 
     
     
         18 . The method of  claim 15 , wherein the report is produced as one of a real-time report generated by compressed stats and an analyze report generated by full session log analysis. 
     
     
         19 . The method of  claim 15 , wherein the steps include producing a plurality of reports, and wherein the plurality of reports are produced for any of a particular user, a particular Internet Protocol (IP) address, or group of IP addresses. 
     
     
         20 . The method of  claim 15 , wherein the steps further include:
 providing an interactive display of firewall insights, the display including graphs of usage trends through the one or more firewall sessions.

Join the waitlist — get patent alerts

Track US2023164116A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.