Patents Assigned to Netskope, Inc.
-
Publication number: 20260230520Abstract: The disclosed technology keeps up with the deployment of APIs, so that Secure Access Service Edge (SASE) protection is afforded. The technology includes accessing an API repository hosting the OpenAPI specification. The OpenAPI specification describes the API of the service, allowing computers to understand capabilities of the service without looking at source code or documentation of the service, and without inspecting traffic of the service. The technology includes retrieving the OpenAPI specification from the API repository. The technology includes identifying a section of the OpenAPI specification as containing a per-activity attribute that corresponds to a core activity that triggers a protective action. The technology includes extracting, from the section, an attribute that is useful for building a connector with connector rules or application signatures.Type: ApplicationFiled: January 26, 2026Publication date: August 6, 2026Applicant: Netskope, Inc.Inventors: Krishna Narayanaswamy, Venkataswamy Pathapati, Muhammed Shafeek
-
Patent number: 12695765Abstract: A system uses an artificial intelligence (AI) engine to generate a response for end-user devices using services and to provide threat protection in a cloud-based network. The system consists of tenants, tunnels, the AI engine, and an AI reporter. A tenant includes the end-user devices. The tunnels transmit and segregate traffic between the end-user devices and the services. The AI engine intercepts traffic within tunnels, receives a request from a user, and applies functions to manage it. The AI engine monitors the request and generates the response. The AI engine determines patterns based on interactions of the user with services, processes the patterns, generates a baseline of user activity and change settings. The AI engine generates the response based on the settings and sends it to the user to fulfill the request. The AI reporter transmits information corresponding to the request and response across the tenants of the cloud-based network.Type: GrantFiled: December 9, 2024Date of Patent: July 28, 2026Assignee: Netskope, Inc.Inventors: Stevan W. Pierce, Jr., Damian Charles Chung, Robert Wayne Butler, II, Madhura Sridhar
-
Patent number: 12695794Abstract: Systems, devices, and computer-implemented methods are presented for monitoring distinct enterprise systems for violations of security policies. In one embodiment, a network security system collects data from a plurality of monitored systems within an enterprise and generates a unified data model using the data. The unified data model establishes connections between two or more of the monitored systems, and more particularly, between objects within the monitored systems based on matching corresponding parameters. The connections provide the network security system with insight into other data in the monitored systems allowing the network security system to identify violations of security policies by leveraging the connections. The network security system can output alerts and remediate the violations in a given monitored system.Type: GrantFiled: November 10, 2025Date of Patent: July 28, 2026Assignee: Netskope, Inc.Inventors: Eetu Lassi Oskari Korhonen, Sayan Hazra, Hardik Shelat, Kaushik Mukherjee
-
Publication number: 20260213958Abstract: The disclosed technology teaches a method of operating an inspection proxy for encrypted sessions between users in an organization serviced by the inspection proxy and cloud-based services accessed by the users. The method comprises a Hardware Secure Module (HSM) providing, to the inspection proxy comprising an intermediate certificate authority, a signed certificate authority (CA) certificate that browsers, operated by the users in the organization, recognize to be authorized to sign end-entity certificates, by virtue of being chained to a root certificate recognized by the browsers.Type: ApplicationFiled: December 23, 2025Publication date: July 23, 2026Applicant: Netskope, Inc.Inventors: Sridhar B. VENKATAGOWDA, Krishna NARAYANASWAMY, Siming WU
-
Publication number: 20260205407Abstract: A method for providing data exchange using secure tunnel in a multi-tenant cloud native control plane system using machine learning algorithms. The cloud control plane receives a request for data access, provisions network connection to service endpoint using data plane and control plane. The control plane identifies routing information of network traffic from multiple end-user devices to establish the connection. Resiliency of the network is identified based on control plane or data plane failure and maintains the connection. A network policy associated with request for accessing data is determined using machine learning algorithms trained on network patterns. Network patterns includes connections between end-user devices, gateway endpoints, user locations, and/or device addresses. Network policy specifies routing for accessing data and the secure tunnel from multiple tunnels.Type: ApplicationFiled: December 29, 2025Publication date: July 16, 2026Applicant: Netskope, Inc.Inventors: Parag Pritam Thakore, Sunil Mukundan, Anupam Rai
-
Patent number: 12684018Abstract: The technology disclosed relates to a proxy receiving a request to manipulate a data object on an independent object store. The proxy is interposed between a user system from which the request originates and the independent object store. The technology disclosed further relates to the proxy accessing a metadata store that contains object metadata for the data object and retrieving the object metadata. The technology disclosed further relates to the proxy enforcing a policy on the request based on the object metadata. Enforcing the policy further includes enforcing malware detection policies and threat detection policies.Type: GrantFiled: June 3, 2024Date of Patent: July 14, 2026Assignee: Netskope, Inc.Inventors: Krishna Narayanaswamy, Lebin Cheng, Abhay Kulkarni, Ravi Ithal, Chetan Anand, Rajneesh Chopra
-
Patent number: 12676908Abstract: A method and system for switching routes based on conditions in cloud-based multi-tenant systems is disclosed. Routes delivers services to end user devices. The routes are specified for policies. The policies specify residencies for the routes, cloud services, and data storage. An application running on an end user device selects a policy and a cloud service. A route corresponding to the policy, and the cloud service is returned to the application.Type: GrantFiled: July 1, 2024Date of Patent: July 7, 2026Assignee: Netskope, Inc.Inventors: Bryan D. Black, Jacob S. Roersma
-
Patent number: 12659357Abstract: A network security system (NSS) is described that performs context aware GenAI traffic inspection using sliding windows. The NSS receives an interaction between an endpoint and a GenAI model, where data of the interaction arrives at the NSS in serial order. The NSS analyzes the interaction by storing the data in chunks in serial order as the data arrives, selecting a batch of the chunks including a target chunk that fall within a sliding window, evaluating the batch of chunks with a detection module that includes a language processing model such that the chunks in the batch preceding the target chunk provide context awareness for the language processing model, and repeatedly advancing the sliding window from the target chunk to the next chunk in serial order to select the next batch. The NSS applies a security policy to the interaction based on results of analyzing the interaction.Type: GrantFiled: November 5, 2025Date of Patent: June 16, 2026Assignee: Netskope, Inc.Inventor: Siying Yang
-
Patent number: 12647362Abstract: A method and system for reducing triggering of throughput penalties imposed on a group of users by a software-as-a-service (SaaS) server due to Application Programming Interface (API) calls exceeding limits of the SaaS server. The approaches include intercepting requests to the SaaS server from a user group and monitoring a rate of API calls the API calls forwarded to the SaaS server, identifying one or more power users based on a notification threshold value for the user group, and managing the rate of the API calls for the requests submitted by the identified power users of the user group in accordance with an API call throttle limit, thus remediating triggering of the throughput penalty.Type: GrantFiled: August 5, 2024Date of Patent: June 2, 2026Assignee: Netskope, Inc.Inventors: Chandrasekaran Rajagopalan, Brian Miller
-
Publication number: 20260149695Abstract: A controlled content system for providing a controlled and contained environment that is remotely accessible is disclosed. A third-party application on the end user device is modified to allow certain sites and services to be mediated in a mid-link server. The third-party application uses policies to know when to access the mid-link server for the controlled and contained environment. A Hypertext Transfer Protocol (HTTP) stack for connection with remote services is based on the network packet traffic identified by the policies as mediated targets. The HTTP stack is modified, or the HTTP stack is substituted with a mediated HTTP stack. A Hypertext Transfer Protocol Secure (HTTPS) or a Virtual Private Network (VPN) connection is configured to connect to the mid-link server for the mediated targets, and for targets that are not mediated, the HTTP connection is configured between the end user device and the targets without the mid-link server.Type: ApplicationFiled: December 1, 2025Publication date: May 28, 2026Applicant: Netskope, Inc.Inventor: Bradley B. Harvell
-
Patent number: 12641100Abstract: Computer network anomaly detection systems and methods are disclosed. One embodiment includes retrieving one or more learned profiles for a group of networked computing devices included in a computer network from a database. For each pair of computing devices in the group, a pairwise distance matrix may be computed. Each pairwise distance in the pairwise distance matrix is computed based on a statistical data profile associated with each computing device in each pair of computing devices from the group. The statistical data profiles may be included in the learned profiles. Any pairwise distances that are greater than a threshold may be removed from the pairwise distance matrix to generate a reduced pairwise distance matrix. One or more computing devices associated with the remaining pairwise distances in the reduced pairwise distance matrix may be sorted into a cluster of computing devices. An anomaly score may be computed for the cluster.Type: GrantFiled: October 17, 2023Date of Patent: May 26, 2026Assignee: NETSKOPE, INC.Inventors: Srinivas Akella, Shahab Sheikh-Bahaei
-
Patent number: 12632572Abstract: The disclosed technology facilitates User and Entity Behavior Analytics (UEBA) by classifying a file being transferred as encrypted or not. The technology involves monitoring movement of a files by a user over a wide area network, detecting file encryption for the files using a trained classifier, wherein the detecting includes processing by the classifier some or all of the following features extracted from each of the files: a chi-square randomness test; an arithmetic mean test; a serial correlation coefficient test; a Monte Carlo-Pi test; and a Shannon entropy test, counting a number of the encrypted files moved by the user in a predetermined period, comparing a predetermined maximum number of encrypted files allowed in the predetermined period to the count of the encrypted files moved by the user and detecting that the user has moved more encrypted files than the predetermined maximum number, and generating an alert.Type: GrantFiled: February 23, 2024Date of Patent: May 19, 2026Assignee: Netskope, Inc.Inventors: Yi Zhang, Siying Yang, Yihua Liao, Dagmawi Mulugeta, Raymond Joseph Canzanese, Jr., Ari Azarafrooz
-
Patent number: 12615242Abstract: The disclosed technology teaches a method for security monitoring in TLS or other certificate-pinned sessions by a cloud-based network security system. When a security condition is detected in the decrypted packets, alerts are generated for the client device. The method involves injecting a message into the session using keys extracted by the cloud-based resource for encryption. Some implementations utilize an inspection proxy and an endpoint routing client for secure tunneling. A secure web gateway buffers encrypted packets in a new session with a cloud-based resource, detects a connection access request from a certificate-pinned application, requests and receives key extraction, and forwards keys to the security system. The secure web gateway applies the keys to systematically encrypted traffic, decrypts packets, and relays ongoing session traffic between the security system and the client device via the inspection proxy, which applies security policies during the process.Type: GrantFiled: February 8, 2024Date of Patent: April 28, 2026Assignee: Netskope, Inc.Inventors: Oleg Murat Smolsky, Yongjie Yin
-
Patent number: 12613890Abstract: The technology disclosed includes a system to perform multi-label support vector machine (SVM) classification of a document. The system creates document features representing frequencies or semantics of words in the document. Trained SVM classification parameters for a plurality of labels are applied to the document features for the document. The system determines positive and negative distances between SVM hyperplanes for the labels and the feature vector. Labels with positive distance to the feature vector are harvested. When the distribution of negative distances is characterized by a mean and standard deviation, the system further harvests the labels with a negative distance such that the harvested labels include the labels with a negative distance between the mean negative distance and zero and separated from the mean negative distance by a predetermined first number of standard deviations.Type: GrantFiled: January 17, 2025Date of Patent: April 28, 2026Assignee: Netskope, Inc.Inventors: Ravindra K. Balupari, Sandeep Yadav
-
Machine learning powered cloud sandbox for malware detection in portable document format (PDF) files
Patent number: 12596804Abstract: A cloud-based network security system (NSS) is described. The NSS uses a sandbox to safely open and extract information about a PDF file and uses machine learning algorithms to analyze the information to predict whether the PDF file contains malware. Specifically, dynamic information about the PDF file is captured while it is open in the sandbox. Static information is extracted from the PDF file as well. The dynamic and static information is input to an AI or machine learning model trained to provide an output indicating a prediction of whether the PDF file contains malware. A verdict engine uses the output from the AI or machine learning model to classify the document as malicious or clean. Security policies can then be applied based on the classification.Type: GrantFiled: October 4, 2024Date of Patent: April 7, 2026Assignee: Netskope, Inc.Inventors: Xinjun Zhang, Zhenxin Zhan, Ghanashyam Satpathy, Hung-Ming Chen, Dong Guo -
Patent number: 12598216Abstract: The technology disclosed relates to endpoint data loss prevention (DLP). In particular, the technology disclosed relates to enforcing data loss prevention policies at an endpoint without needing to perform content sensitivity scan at the endpoint.Type: GrantFiled: April 10, 2024Date of Patent: April 7, 2026Assignee: Netskope, Inc.Inventors: Krishna Narayanaswamy, Ajay Agrawal
-
Patent number: 12593210Abstract: A dynamic security system to secure cellular devices across a cellular network in a cloud-based environment. The dynamic security system includes a tenant of multiple tenants having multiple cellular devices, a tunnel, a traffic steering module, and a threat management module. The tunnel transmits and identifies traffic associated with different network identifiers. The traffic steering module routes traffic towards gateways and the threat management module analyzes traffic at the tunnel and generates policies and recommendations to remediate a threat. The threat management module intercepts traffic within the tunnel at an application layer of the cloud-based environment, creates policy profiles for tenants, monitors a threat landscape, and relates the threat with the policy profiles. The threat management module further stores tenant profiles, threat information, and policy profiles.Type: GrantFiled: September 20, 2024Date of Patent: March 31, 2026Assignee: Netskope, Inc.Inventors: Kallol Banerjee, Harsh Pandey, Bryan D. Black, Jonathan Bosanac
-
Patent number: 12592959Abstract: The technology disclosed relates to a method, system, and non-transitory computer-readable media that detects malicious communication between a command and control (C2) cloud resource on a cloud application and malware on an infected host, using a network security system. The network security system reroutes the cloud traffic to the network security system. The incoming requests of the cloud traffic are directed to a cloud application in the plurality of cloud applications, and wherein the cloud application has a plurality of resources. The network security system analyzes the incoming requests, determines that the incoming requests are targeted at one or more malicious resources in the plurality of resources.Type: GrantFiled: June 23, 2023Date of Patent: March 31, 2026Assignee: Netskope, Inc.Inventors: Dagmawi Mulugeta, Raymond Joseph Canzanese, Jr., Colin Estep, Siying Yang, Jenko Hwong, Gustavo Palazolo Eiras, Yongxing Wang
-
Publication number: 20260089509Abstract: A dynamic security system to secure cellular devices across a cellular network in a cloud-based environment. The dynamic security system includes a tenant of multiple tenants having multiple cellular devices, a tunnel, a traffic steering module, and a threat management module. The tunnel transmits and identifies traffic associated with different network identifiers. The traffic steering module routes traffic towards gateways and the threat management module analyzes traffic at the tunnel and generates policies and recommendations to remediate a threat. The threat management module intercepts traffic within the tunnel at an application layer of the cloud-based environment, creates policy profiles for tenants, monitors a threat landscape, and relates the threat with the policy profiles. The threat management module further stores tenant profiles, threat information, and policy profiles.Type: ApplicationFiled: September 20, 2024Publication date: March 26, 2026Applicant: Netskope, Inc.Inventors: Kallol Banerjee, Harsh Pandey, Bryan D. Black, Jonathan Bosanac
-
Publication number: 20260080026Abstract: An intermediary server provides secure access to a web page of a web-based service upon request of a web server. The intermediary server includes an operating system that runs a new instance of a web browser engine. The web browser engine creates a temporary folder to isolate the new instance from other instances and deletes the temporary folder upon deletion of the new instance. The web browser engine produces an image of a web page rendered in the new instance and transmits an access web page to a web browser. The access web page is configured to retrieve the image from the web browser engine and display the image in the web browser. User interactions are registered and sent to the new instance in the intermediary server. The user interactions are reproduced within the new instance and the new instance produces images of the web page after the user interactions.Type: ApplicationFiled: September 15, 2025Publication date: March 19, 2026Applicant: Netskope, Inc.Inventors: Mariano Largo Del Amo, Victor Jurado Martinez