Zscaler, Inc.

United States of America

Back to Profile

1-100 of 591 for Zscaler, Inc. Sort by
Query
Aggregations
IP Type
        Patent 567
        Trademark 24
Jurisdiction
        United States 579
        World 11
        Canada 1
Date
New (last 4 weeks) 9
2026 September (MTD) 3
2026 August 8
2026 July 8
2026 June 5
See more
IPC Class
H04L 9/40 - Network security protocols 257
H04L 29/06 - Communication control; Communication processing characterised by a protocol 111
H04L 29/08 - Transmission control procedure, e.g. data link level control procedure 51
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system 41
G06N 20/00 - Machine learning 35
See more
NICE Class
42 - Scientific, technological and industrial services, research and design 23
09 - Scientific and electric apparatus and instruments 6
41 - Education, entertainment, sporting and cultural services 1
Status
Pending 135
Registered / In Force 456
  1     2     3     ...     6        Next Page

1.

Predicting Legitimacy of User Access to Available Enterprise Apps

      
Application Number 19070801
Status Pending
Filing Date 2025-03-05
First Publication Date 2026-09-10
Owner Zscaler, Inc. (USA)
Inventor Hu, Chenhui

Abstract

Systems and methods are provided for predicting the validity or authorization of a user to access applications (apps) in a network. A method, according to one implementation, includes a step of obtaining transaction logs that include a) user features related to a plurality of users of an organization, b) app features related to a plurality of apps used within the organization, and c) user-app interaction information related to requests by users to access apps in addition to responses to the requests to either permit or deny user access. Also, the method includes a step of applying a collaborative filtering technique on the transaction logs to train an Artificial Intelligence (AI) model for predicting whether a new user is legitimately permitted access to one or more of the plurality of apps.

IPC Classes  ?

2.

Zero Trust System Architecture

      
Application Number 19653620
Status Pending
Filing Date 2026-04-21
First Publication Date 2026-09-03
Owner Zscaler, Inc. (USA)
Inventor
  • Howe, Nathan
  • Ganguli, Sanjit
  • Festa, Gerard

Abstract

Systems and methods for zero trust access control are provided. A cloud-based security platform positioned between an entity and a network resource detects a request by the entity to connect to, access, or communicate with the network resource and blocks the request by default pending completion of a plurality of evaluation procedures. A verification procedure evaluates at least an identity of the entity and a context associated with the request. A control procedure evaluates at least one of a risk associated with the entity, presence of malicious content in traffic associated with the request, and presence of sensitive data in the traffic. An enforcement procedure determines, based on outputs of the verification procedure and the control procedure, an action to apply to the request, the action being selected from a plurality of conditional allow actions and a plurality of conditional block actions.

IPC Classes  ?

3.

Cloud Native Threat Detection, Investigation, and Response Systems and Methods

      
Application Number 19066458
Status Pending
Filing Date 2025-02-28
First Publication Date 2026-09-03
Owner Zscaler, Inc. (USA)
Inventor
  • Tiwari, Abhishek
  • Appan, Preetha
  • Singh, Gurpreet

Abstract

Systems and methods for detecting and responding to threats in a cloud native computing environment include steps of collecting, from one or more sensors configured to monitor container hosts, runtime telemetry that includes process activity, system call traces, and network traffic data; ingesting, into a data fabric, the runtime telemetry along with log data from a cloud system positioned to block suspicious traffic; analyzing the ingested runtime telemetry and the log data to identify one or more indicators of compromise (IoCs); correlating an event blocked by the cloud system at the perimeter with the identified IoCs from the runtime telemetry; and initiating, based on the correlation, an automated remediation action in the cloud native computing environment.

IPC Classes  ?

4.

Measuring Network Experience by Performing Adaptive Tracing of a Cloud Path

      
Application Number 19061248
Status Pending
Filing Date 2025-02-24
First Publication Date 2026-08-27
Owner Zscaler, Inc. (USA)
Inventor
  • Kalipatnapu, Satish
  • Malleshaiah, Prasannakumar Jobigenahally
  • Achanta, Anirudh
  • Desai, Vandan
  • Kolachina, Ashok
  • Rodriguez Gonzalez, Francisco Javier
  • Srivastava, Vikas
  • Patel, Amitkumar
  • Budukh, Tejas
  • Panigrahy, Saroj

Abstract

Systems and methods for measuring and assigning network experience scores include collecting end-to-end metric data corresponding to application traffic between one or more clients and one or more servers, the metric data including any of latency, jitter, and packet loss; comparing the metric data with baseline percentile values; assigning one or more scores to one or more segments of a path associated with the application traffic based on the metric data and the baseline percentile values; and aggregating the scores of the one or more segments to produce a single network experience score indicative of overall network performance for the application traffic.

IPC Classes  ?

5.

Multi-Layered Privacy Protection and Tracking Prevention

      
Application Number 19065259
Status Pending
Filing Date 2025-02-27
First Publication Date 2026-08-27
Owner Zscaler, Inc. (USA)
Inventor Kelly, Mitchell

Abstract

Systems and methods for cloud-based multi-layered privacy protection and tracking prevention include routing traffic of a plurality of users associated with a tenant of the cloud-based system through a Secure Web Gateway (SWG) of a cloud-based system; analyzing traffic of a user of the plurality of users for privacy threats; employing one or more defense modules to protect the user from the privacy threats based on the analyzing; and monitoring performance of a destination of the traffic to detect performance degradation due to the one or more defense modules.

IPC Classes  ?

6.

Optimized Cloud-Based Data Loss Prevention (DLP)

      
Application Number 19055016
Status Pending
Filing Date 2025-02-17
First Publication Date 2026-08-20
Owner Zscaler, Inc. (USA)
Inventor
  • Schneider, Michael
  • Szabo, Peter

Abstract

Systems and methods for optimized cloud-based Data Loss Prevention (DLP) include monitoring user traffic associated with one or more tenants of the cloud-based system, the traffic including actions performed in association with a file sharing and storage service; responsive to a user accessing a file within the file sharing and storage service, performing a DLP scan requirement analysis; based on a result of the DLP scan requirement analysis, (i) performing a DLP scan of the file or (ii) bypassing a DLP scan of the file; and performing one or more actions based on policy associated with the user and the file.

IPC Classes  ?

  • G06F 21/60 - Protecting data
  • G06F 21/54 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by adding security routines or objects to programs
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

7.

Hypertext Markup Language (HTML) Sandboxing with Browser Isolation

      
Application Number 19055022
Status Pending
Filing Date 2025-02-17
First Publication Date 2026-08-20
Owner Zscaler, Inc. (USA)
Inventor
  • Rao, Sumukh
  • Jain, Amit
  • Desai, Deepen
  • Nair, Jithin Prajeev
  • Paul, Narinder
  • Sainion, Parnit
  • Polurouthu, Vinay

Abstract

Systems and methods for Hypertext Markup Language (HTML) sandboxing with browser isolation include responsive to a user attempting to access a webpage, sending the webpage to a sandbox for performing an analysis on the webpage; rendering the webpage within a browser isolation session, thereby allowing the user to interact with the webpage while the analysis is being performed; generating a score for the webpage based on the analysis, the score being indicative of the maliciousness of the webpage; and performing one or more actions based on the score associated with the webpage.

IPC Classes  ?

  • G06F 21/53 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by executing in a restricted environment, e.g. sandbox or secure virtual machine
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements

8.

Hybrid Automotive Cybersecurity Monitoring Service

      
Application Number 19058411
Status Pending
Filing Date 2025-02-20
First Publication Date 2026-08-20
Owner Zscaler, Inc. (USA)
Inventor Liu, Yuan-An

Abstract

Systems and methods are provided for enabling hybrid processing of cybersecurity analysis for embedded systems in vehicles, whereby local cybersecurity threats are detected locally on the vehicle itself, while a remote edge server can provide more comprehensive cybersecurity threat analysis. According to one implementation, an embedded system may be installed on or incorporated within a vehicle. The embedded system, for example, includes a wireless transceiver device and an operating system including at least a kernel and a cybersecurity agent. The cybersecurity agent includes minimal resources for contributing base level or lightweight functionality with respect to protection against vehicle cybersecurity attacks. The wireless transceiver device is configured to offload vehicle data to a cloud-based server, the cloud-based server configured for contributing detailed level or heavyweight functionality with respect to protection against the vehicle cybersecurity attacks.

IPC Classes  ?

  • H04W 12/122 - Counter-measures against attacksProtection against rogue devices

9.

Private Access for Third-Party Applications

      
Application Number 19049530
Status Pending
Filing Date 2025-02-10
First Publication Date 2026-08-13
Owner Zscaler, Inc. (USA)
Inventor Aamir, Mohammad

Abstract

Systems and methods for providing private access to third-party applications include responsive to execution of a third-party application on a mobile device, transmitting a pre-login tunnel request to the cloud-based system; responsive to receiving a signed certificate from the cloud-based system, establishing a pre-login tunnel to one or more pre-login endpoints of the third-party application; performing authentication to the third-party application via the pre-login tunnel; and responsive to receiving a second signed certificate from the cloud-based system, establishing a post-login tunnel to one or more post-login endpoints of the third-party application.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system

10.

Automated Network Environment Compliance Control

      
Application Number 19043682
Status Pending
Filing Date 2025-02-03
First Publication Date 2026-08-06
Owner Zscaler, Inc. (USA)
Inventor
  • Inbar, Roi
  • Danino, Shoham

Abstract

Systems and methods for automated network environment compliance control include receiving one or more security findings associated with an organization's network environment; analyzing, by a Large Language Model (LLM) agent, the one or more security findings to identify compliance requirements across a plurality of compliance frameworks; determining one or more compliance controls based on the compliance requirements identified by the LLM agent; validating each of the one or more compliance controls; and generating a compliance report including one or more implementation strategies and risk analyses for each validated compliance control.

IPC Classes  ?

11.

Automated Reasoning and Explanation of Correlated Factors in Digital Experience Monitoring

      
Application Number 19085276
Status Pending
Filing Date 2025-03-20
First Publication Date 2026-08-06
Owner Zscaler, Inc. (USA)
Inventor
  • Malleshaiah, Prasannakumar Jobigenahally
  • Xiong, Hanchen
  • Kolachina, Ashok
  • Achanta, Anirudh
  • Makwana, Jay
  • Coelho, Jr., Claudionor Jose Nunes
  • Guha, Sudipto
  • Jagatheesan, Prakash
  • Chandraiah, Shreyas Madapura
  • Dhanaraj, Darshan
  • Tummala, Srinivas

Abstract

Systems and methods for automated reasoning and explanation of correlated factors in digital experience monitoring include collecting performance data from a plurality of sources, the performance metrics including network metrics, application performance metrics, device metrics, and user behavior metrics; identifying one or more anomalies and correlations between the collected performance data; processing the one or more anomalies and correlations with a Large Language Model (LLM) to generate one or more explanations for the identified anomalies and correlations; and presenting the generated explanations through a user interface.

IPC Classes  ?

  • G06F 11/34 - Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation

12.

Self-Service Network Reconciliation based on User Experience Scoring

      
Application Number 19040761
Status Pending
Filing Date 2025-01-29
First Publication Date 2026-07-30
Owner Zscaler, Inc. (USA)
Inventor
  • Selvarajan, Gopi
  • Tellakula, Sreeni

Abstract

Systems and methods for self-service network reconciliation improve network performance in a cloud-based system by using an SDN controller to dynamically optimize routing paths. The SDN controller receives route information from BGP speakers and gathers user experience metrics—such as latency, jitter, or packet loss—to evaluate whether current routes meet performance or SLA targets. If a route falls short, the controller applies a smart routing algorithm to select an alternative path that better satisfies performance criteria. It then updates BGP attributes accordingly, causing traffic to shift to the improved route and enhancing overall user experience.

IPC Classes  ?

  • H04L 45/02 - Topology update or discovery
  • H04L 45/00 - Routing or path finding of packets in data switching networks

13.

Transparent High Availability Multi-Link Connectivity of Edge Devices

      
Application Number 19024646
Status Pending
Filing Date 2025-01-16
First Publication Date 2026-07-16
Owner Zscaler, Inc. (USA)
Inventor
  • Surendra Babu, Thilak Raj
  • Verma, Ravinder
  • Prabhu, Thekkar Nishanth

Abstract

An edge device, disposed at a branch network and configured to connect the branch network to a wide area network (WAN), the edge device includes circuitry configured to: interconnect with a plurality of local area network (LAN) interfaces in the branch network; form, over the plurality of LAN interfaces, a set of logical tunnels for high-availability (HA) traffic associated with clustering of a plurality of edge devices in the branch network; and distribute the HA traffic the set of logical tunnels to provide redundancy and resilience if one of the plurality of LAN interfaces fails or becomes congested.

IPC Classes  ?

  • H04L 45/00 - Routing or path finding of packets in data switching networks
  • H04L 41/12 - Discovery or management of network topologies
  • H04L 45/302 - Route determination based on requested QoS
  • H04L 47/12 - Avoiding congestionRecovering from congestion
  • H04L 47/70 - Admission controlResource allocation
  • H04L 49/113 - Arrangements for redundant switching, e.g. using parallel planes

14.

Creating a Security-Focused Model Anchored by a Threat Intelligence Table

      
Application Number 19562335
Status Pending
Filing Date 2026-03-10
First Publication Date 2026-07-16
Owner Zscaler, Inc. (USA)
Inventor Hu, Chenhui

Abstract

Systems and methods for enabling cybersecurity inquiries are provided. In one implementation, a method includes a step of receiving cybersecurity threat intelligence data from one or more threat intelligence sources. The method also includes structuring the cybersecurity threat intelligence data into one or more threat intelligence tables each having a plurality of fields describing attributes of network security threats. Also, the method includes sampling rows from each of the one or more threat intelligence tables and programmatically generating, from each corresponding row, a plurality of Q/A/R triples, each Q/A/R triple including a Question element, an Answer element, and a Reasoning element derived from one or more fields. Next, the method includes a step of generating a cybersecurity-focused language model from the one or more threat intelligence tables and the plurality of Q/A/R triples, wherein the cybersecurity-focused language model, when trained, is configured to answer network security inquiries.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities

15.

Cloud-Based Policy Enforcement and Risk Controls Based on Geopolitical, Geographic, Geological, and Idealistic Insights

      
Application Number 19019630
Status Pending
Filing Date 2025-01-14
First Publication Date 2026-07-16
Owner Zscaler, Inc. (USA)
Inventor
  • Howe, Nathan
  • Tucker, James
  • Nadendla, Arvind
  • Cheung, Eric

Abstract

Systems and methods for cloud-based policy enforcement and risk controls based on geopolitical insights include ingesting external data feeds from a plurality of sources, the external data feeds providing information indicative of geopolitical factors; analyzing the ingested data to classify one or more geographic regions, networks, or user populations into risk categories; determining, for each tenant of the cloud-based system, a level of acceptable risk tolerance that defines actions to be taken upon assignment of a particular risk category to a region or user population; and applying, based on the determined risk tolerance and assigned risk category, one or more adaptive cybersecurity controls.

IPC Classes  ?

16.

Cloud observability framework for providing troubleshooting and monitoring for services

      
Application Number 19069767
Status Pending
Filing Date 2025-03-04
First Publication Date 2026-07-09
Owner Zscaler, Inc. (USA)
Inventor
  • Varkali, Ravinder
  • Chappidi, Sunil
  • Chitte, Bhushan
  • Pangeni, Sushil
  • Singh, Jaspreet
  • Chadha, Manpreet
  • Entoliya, Ruchita Dinesh
  • Somasundaram, Ramesh Kumar
  • Chapagain, Kriti
  • Wang, Di
  • Hussain, Noorul
  • Dhere, Rahul
  • R S, Abhishek
  • Gupta, Pramit
  • Singh, Aniket
  • Sai, Adi Sathya
  • Sampathu, Karthik
  • Krishna, Prithvi Manoj
  • G, Renushree
  • Pandey, Nishank
  • R, Haripriya
  • Chan, Clark
  • Jain, Pranjal
  • Kallarackal, Varghese
  • Sanghvi, Kumar

Abstract

Systems and methods for providing monitoring and troubleshooting for services of a cloud-based system include receiving a request from a user, the request being for any of monitoring and troubleshooting one or more services provided by the cloud-based system; submitting a job to one or more observability agents associated with the one or more services of the cloud-based system; receiving a response from the one or more observability agents, the response including metrics associated with the one or more services; and providing the response to the user.

IPC Classes  ?

17.

Lookalike Domain Risk Score Determination

      
Application Number 19560959
Status Pending
Filing Date 2026-03-09
First Publication Date 2026-07-09
Owner Zscaler, Inc. (USA)
Inventor Rubin, Dani

Abstract

A systems and methods for determining a risk score for lookalike domains are disclosed. A plurality of candidate domains are generated from a seed domain using a genetic algorithm that applies deception techniques. Registered candidate domains are analyzed by multiple independent scoring engines that produce an internal deception score, a reputation score, a visual similarity score based on rendered webpage analysis, and a favicon similarity score. The individual scores are dynamically weighted and combined using conditional logic to calculate a final risk score. The weighting adapts based on signal strength, including prioritizing visual cloning indicators or malicious infrastructure signals. Unregistered domains are assigned reduced priority. When the final risk score exceeds a predefined threshold, an alert is generated. The disclosed approach integrates lexical, infrastructure, and content-based signals to reduce false positives and improve detection of sophisticated phishing domains.

IPC Classes  ?

18.

Artificial Intelligence (AI) Agents for Agent Applications

      
Application Number 19068279
Status Pending
Filing Date 2025-03-03
First Publication Date 2026-07-09
Owner Zscaler, Inc. (USA)
Inventor Goyal, Rohit

Abstract

Systems and methods for an AI agent for agent applications including performing inline monitoring of traffic originating from the user device; receiving a query from a user associated with the user device, the query being associated with an issue affecting connectivity of the user device to one or more resources; analyzing the query via an Artificial Intelligence (AI) agent of the agent application; and any of providing one or more remediation steps for resolving the connectivity issue, generating and submitting an Information Technology (IT) support ticket, and autonomously performing one or more actions to resolve the connectivity issue via the AI agent of the agent application.

IPC Classes  ?

  • H04L 41/0654 - Management of faults, events, alarms or notifications using network fault recovery
  • H04L 43/02 - Capturing of monitoring data

19.

Complexity-based Divide-and-Conquer Framework for Copilots

      
Application Number 19001685
Status Pending
Filing Date 2024-12-26
First Publication Date 2026-07-02
Owner Zscaler, Inc. (USA)
Inventor
  • Coelho, Jr., Claudionor Jose Nunes
  • Xiong, Hanchen
  • Malleshaiah, Prasannakumar Jobigenahally
  • Tiwari, Praveen
  • Gonzalez, Javier Rodriguez
  • Shah, Raimi
  • Bollinger, Jacob

Abstract

Systems and methods are provided for customizing flow paths to better handle queries and questions directed to a Large Language Model (LLM) or another automated search model. According to one implementation, a method includes a step of receiving a question from a user device. The method further includes a step of determining a level of complexity of the question. Also, the method includes tailoring a divide-and-conquer plan when the complexity of the question is determined to be higher than a lowest level of complexity. The method then includes a step of executing the divide-and-conquer plan to produce an answer to the question.

IPC Classes  ?

20.

Cloud Service Provider (CSP) Event Capture and Processing System

      
Application Number 19068234
Status Pending
Filing Date 2025-03-03
First Publication Date 2026-06-25
Owner Zscaler, Inc. (USA)
Inventor
  • Subbaraman, Anand
  • Annakula, Ragavendra
  • Kasbi, Kushagra
  • Krishna, Vaibhav Avasarla
  • B, Divya
  • Atal, Durgesh
  • Kondekar, Aadarsh Uday
  • Agarwal, Varuni

Abstract

Systems and methods for a Cloud Service Provider (CSP) event capture and processing system include retrieving a change feed from one or more Cloud Service Providers (CSPs) associated with a customer of the cloud-based system; analyzing the change feeds to identify modifications of one or more resources within network environments associated with the customer, wherein the network environments are provided by the one or more CSPs; updating a data store of the customer with any new or modified resources based on the analyzing; and providing a customer-specific dashboard including analytics for all CSPs associated with the customer of the cloud-based system.

IPC Classes  ?

  • G06Q 10/0631 - Resource planning, allocation, distributing or scheduling for enterprises or organisations

21.

GenAI-Powered Discovery of Evolving Cybersecurity Threat Campaigns

      
Application Number 18972311
Status Pending
Filing Date 2024-12-06
First Publication Date 2026-06-11
Owner Zscaler, Inc. (USA)
Inventor
  • Tiwari, Praveen
  • Thimmisetty, Charanraj
  • Nedorosleva, Sofia
  • Sakhuja, Hardik
  • Guha, Sudipto

Abstract

Systems and methods for executing an evolving threat campaign discovery pipeline are provided. A method, according to one implementation, includes a step of utilizing a harvester stage of an evolving threat campaign discovery pipeline, the harvester stage configured to perform a continuous open web crawling action to obtain initial threat information from external sources. The method also includes a step of utilizing an examiner stage of the evolving threat campaign discovery pipeline, the examiner stage configured to perform automated and human-assisted vetting of the initial threat information to obtain verified threat data. Also, the method includes utilizing a curator stage of the evolving threat campaign discovery pipeline, the curator stage configured to record the verified threat data in a threat campaign database to monitor and maintain knowledge of an evolving threat campaign.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures

22.

Systems and Methods for Extranet Application Support

      
Application Number 18973657
Status Pending
Filing Date 2024-12-09
First Publication Date 2026-06-11
Owner Zscaler, Inc. (USA)
Inventor
  • Pullela, Shyam
  • Nagarajan, Chandra
  • Sathyanarayan, Praveen Yadothare
  • Seshadri, Prakash
  • Menon, Joby

Abstract

Systems and methods for extranet application support within a virtual private access system include receiving a request to access a resource from a user device associated with a customer of the cloud-based system, wherein the resource is located within one or more data centers associated with a partner of the customer; determining an optimal node of a plurality of nodes and an optimal tunnel of a plurality of tunnels for creating a connection between the user device and the resource; and creating a connection between the user device and the resources via the optimal node and the optimal tunnel.

IPC Classes  ?

  • H04L 67/63 - Routing a service request depending on the request content or context
  • H04L 45/12 - Shortest path evaluation

23.

Delegated Tenant Administration in a Cloud-Based System

      
Application Number 19055772
Status Pending
Filing Date 2025-02-18
First Publication Date 2026-06-11
Owner Zscaler, Inc. (USA)
Inventor
  • Palkonda, Vamshi
  • Ramesh, Badam
  • Gupta, Palash
  • Kaur, Gaganpreet
  • Bhatt, Vivek

Abstract

Systems and methods for delegated tenant administration in a cloud-based system include receiving a request to access a resource from a user device, wherein the resource is located in one of a public cloud and an enterprise network, and wherein the user device is associated with a user of a tenant of the cloud-based system; performing a policy lookup for determining policy governing access for the user to the resource, wherein the policy is based on a micro tenant associated with the tenant; providing a connection between the user device and the resource based on the policy and the micro tenant associated with the user.

IPC Classes  ?

24.

Enhancing a Code Base using Dynamic Retrieval-Augmented Generation (RAG) with Run-Time Prompt Enrichment

      
Application Number 19052365
Status Pending
Filing Date 2025-02-13
First Publication Date 2026-06-11
Owner Zscaler, Inc. (USA)
Inventor
  • Shyju, Saurav
  • Venkatesh, Golla Sai

Abstract

Systems and methods for enhancing software code are provided. A method, according to one implementation, includes receiving a code base developed by one or more software developers and receiving a prompt for requesting enhancement to the code base. Also, the method includes a step of using a dynamic Retrieval-Augmented Generation (RAG) component and a Knowledge Base (KB) repository to enrich the prompt. Based on the enriched prompt, the method further includes a step of using a Large Language Model (LLM) code enhancing tool to enhance the code base.

IPC Classes  ?

  • G06F 8/35 - Creation or generation of source code model driven

25.

Agentless Workload Vulnerability Scanning

      
Application Number 19453557
Status Pending
Filing Date 2026-01-20
First Publication Date 2026-05-28
Owner Zscaler, Inc. (USA)
Inventor
  • Rawat, Abhijeet Singh
  • Barik, Abhiram
  • Gadi, Chandar Dayakar Singh
  • C, Krishnakumar

Abstract

Systems and methods provide agentless security assessment for workloads and cloud posture control across multi-cloud environments. Discovery modules are configured with collection intervals to ingest posture control data including assets, identities, configurations, activities, network flows, and build-time artifacts. A multi-cloud configuration inventory maintains current and historical states and produces misconfiguration and identity-activity findings. For workload vulnerability evaluation, an external snapshot manager obtains point-in-time root-disk state without installing an in-workload agent. A file system data processor derives operating system and package metadata, and a detector matches the metadata against a vulnerability feed refreshed on a recurring basis to identify vulnerabilities. Identified vulnerabilities are correlated with misconfiguration and activity findings to generate prioritized risk exposures. Results are stored per workload and presented through graphical user interfaces that display risk levels, timelines, alerts, and guided remediation, enabling continuous, low-overhead security coverage for cloud workloads and configurations.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]

26.

Advanced Large Language Model (LLM)-based query builder

      
Application Number 18950526
Status Pending
Filing Date 2024-11-18
First Publication Date 2026-05-21
Owner Zscaler, Inc. (USA)
Inventor
  • Inbar, Roi
  • Danino, Shoham

Abstract

Systems and methods for an advanced query building system include receiving a natural language query from a user, the query including a request for data from one or more data repositories; generating a Structured Query Language (SQL) query based on the natural language query; converting the SQL query to JSON-Logic; and utilizing the JSON-Logic to perform a query, and providing results of the query to the user.

IPC Classes  ?

27.

Implementing Federal Information Processing Standards (FIPS) Compliance Checks Within the Software Development Process

      
Application Number 19008997
Status Pending
Filing Date 2025-01-03
First Publication Date 2026-05-21
Owner Zscaler, Inc. (USA)
Inventor
  • Gupta, Romeo
  • Terwilliger, Eric
  • Huie, Ken
  • Meenakshisundaram, Vidya

Abstract

Systems and methods for implementing a FIPS compliance check within the software development process include receiving a Software Bill of Materials (SBOM) associated with software in production; performing a vulnerability scan based on the SBOM; extracting a list of dependencies of the software based on the SBOM and generating a list of cryptographic dependencies associated with the software; and generating a FIPS compliance report for the software based on the vulnerability scan and the list of cryptographic dependencies.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06F 8/41 - Compilation
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06Q 10/0875 - Itemisation or classification of parts, supplies or services, e.g. bill of materials

28.

Systems and Methods for Providing Detailed Cloud-Level Network Traffic Visualizations

      
Application Number 19012583
Status Pending
Filing Date 2025-01-07
First Publication Date 2026-05-21
Owner Zscaler, Inc. (USA)
Inventor
  • Malleshaiah, Prasannakumar Jobigenahally
  • Rodriguez Gonzalez, Francisco Javier
  • Chandraiah, Shreyas Madapura
  • Achanta, Anirudh
  • Amratiya, Shyam
  • Yelmar, Akshay
  • Bhosale, Abhaysingh
  • Patel, Hiren
  • Kalipatnapu, Satish
  • Chadha, Manpreet
  • Kolachina, Ashok
  • Tellakula, Sreeni
  • Srivastava, Vikas
  • Desai, Vandan
  • Patel, Amitkumar

Abstract

Systems and methods for providing detailed cloud-level network traffic visualizations include monitoring traffic traversing between any of computing devices, Data Centers (DCs), applications, and Internet Service Providers (ISPs); analyzing the traffic to determine network performance between any of the computing devices, DCs, applications, and ISPs; generating metrics based on the analyzing, the metrics being associated with the network performance of any of the computing devices, DCs, applications, ISPs, and connections therebetween; and providing a visual representation of the metrics, wherein the visual representation includes graphs visualizing any of the computing devices, DCs, applications, and ISPs, and any connections therebetween.

IPC Classes  ?

  • H04L 43/065 - Generation of reports related to network devices
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/0817 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability by checking functioning

29.

Customized Internet Service Provider (ISP) Ranking Dashboard

      
Application Number 19012598
Status Pending
Filing Date 2025-01-07
First Publication Date 2026-05-21
Owner Zscaler, Inc. (USA)
Inventor
  • Chandraiah, Shreyas Madapura
  • Malleshaiah, Prasannakumar Jobigenahally
  • Achanta, Anirudh
  • Rodriguez Gonzalez, Francisco Javier
  • Chadha, Manpreet
  • Singh, Jaspreet
  • Patel, Amitkumar
  • Srivastava, Vikas
  • Desai, Vandan

Abstract

Systems and methods for a customized Internet Service Provider (ISP) ranking dashboard include monitoring network traffic of a plurality of tenants of the cloud-based system, wherein the network traffic includes traffic originating from a plurality of computing devices distributed across various geolocations; analyzing the network traffic to determine network performance associated with a plurality of Internet Service Providers (ISPs); and providing a dashboard, wherein the dashboard includes one or more visualizations displaying the network performance of the plurality of ISPs.

IPC Classes  ?

  • H04L 41/5009 - Determining service level performance parameters or violations of service level contracts, e.g. violations of agreed response time or mean time between failures [MTBF]
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/091 - Measuring contribution of individual network components to actual service level

30.

Automated Log Collection and Analysis to Remediate User Experience Issues

      
Application Number 19053716
Status Pending
Filing Date 2025-02-14
First Publication Date 2026-05-21
Owner Zscaler, Inc. (USA)
Inventor
  • Budukh, Tejas
  • Malleshaiah, Prasanna Jobigenahally
  • Panigrahy, Saroj Kumar
  • Kalipatnapu, Satish
  • Roy, Subhro Jyoti

Abstract

Systems and methods are provided for automatically supporting clients in a help desk framework. In one implementation, a method includes a step of monitoring an enterprise network. In response to detecting one or more adverse conditions of the enterprise network that imply a decline in one or more User Experience (UX) metrics, the method further includes a step of automatically collecting data logs from the enterprise network. Also, the method includes automatically analyzing the data logs. In response to determining that the data logs indicate one or more issues in the enterprise network, the method further includes a step of suggesting actions to remediate the one or more issues.

IPC Classes  ?

  • G06F 11/07 - Responding to the occurrence of a fault, e.g. fault tolerance

31.

Automated Workflow Management and Solution Recommendation in Customer Support Ticketing System

      
Application Number 18953336
Status Pending
Filing Date 2024-11-20
First Publication Date 2026-05-21
Owner Zscaler, Inc. (USA)
Inventor
  • Malleshaiah, Prasannakumar Jobigenahally
  • Achanta, Anirudh
  • Kolachina, Ashok
  • Chadha, Manpreet
  • Kalipatnapu, Satish
  • Kalra, Sanjay
  • Makwana, Jay
  • Chandraiah, Shreyas Madapura
  • Panigrahy, Saroj
  • Singh, Jaspreet

Abstract

Systems and methods for handling customer support tickets are provided. A method, according to one implementation, includes a step of dynamically summarizing ticket content of a new ticket to obtain partial summaries and a final summary of the new ticket, wherein the new ticket is opened in order to resolve an incident in a domain. The method also includes a step of transforming the final summary into a numerical vector. Also, the method includes performing a similarity search to compare the numerical vector with pre-stored vectors in a vector database, wherein the pre-stored vectors are associated with previously resolved incidents in the domain. The method may further include triggering predefined actions based on the similarity search.

IPC Classes  ?

32.

Systems and Methods for Providing Customer-Specific Network Impact Reports

      
Application Number 19012589
Status Pending
Filing Date 2025-01-07
First Publication Date 2026-05-21
Owner Zscaler, Inc. (USA)
Inventor
  • Chandraiah, Shreyas Madapura
  • Malleshaiah, Prasannakumar Jobigenahally
  • Achanta, Anirudh
  • Rodriguez Gonzalez, Francisco Javier
  • Kalipatnapu, Satish
  • Kuperman, Michael
  • Greco, Charles
  • Pergament, Lidor

Abstract

Systems and methods for providing customer-specific network impact reports include monitoring traffic traversing between any of computing devices, Data Centers (DCs), applications, and Internet Service Providers (ISPs) associated with a plurality of customers of the cloud-based system; analyzing the traffic of the plurality of customers to determine network performance and identify issues; and providing a notification to a specific customer, the notification including details about a detected issue and one or more actionable recommendations.

IPC Classes  ?

  • H04L 41/5009 - Determining service level performance parameters or violations of service level contracts, e.g. violations of agreed response time or mean time between failures [MTBF]
  • H04L 43/091 - Measuring contribution of individual network components to actual service level

33.

Systems and Methods for Dynamic Traffic Routing

      
Application Number 19012592
Status Pending
Filing Date 2025-01-07
First Publication Date 2026-05-21
Owner Zscaler, Inc. (USA)
Inventor
  • Achanta, Anirudh
  • Chhabra, Pankaj
  • Saggau-Lyons, Ailin
  • Malleshaiah, Prasannakumar Jobigenahally
  • Chandraiah, Shreyas Madapura
  • Rodriguez Gonzalez, Francisco Javier
  • Singh, Surender
  • Wu, Amber

Abstract

Systems and methods for dynamic traffic routing include monitoring connectivity to a plurality of available Data Centers (DCs) associated with a cloud-based system; generating real-time connectivity information based on the monitoring, the real-time connectivity information including a performance level of the plurality of available DCs; determining a best performing DC from the plurality of available DCs; and switching a connection from a current DC to the best performing DC.

IPC Classes  ?

  • H04L 45/00 - Routing or path finding of packets in data switching networks
  • H04L 43/065 - Generation of reports related to network devices
  • H04L 45/24 - Multipath

34.

System and method to detect lateral movement of ransomware by deploying a security appliance over a shared network to implement a default gateway with point-to-point links between endpoints

      
Application Number 18622678
Grant Number 12634341
Status In Force
Filing Date 2024-03-29
First Publication Date 2026-05-19
Grant Date 2026-05-19
Owner
  • Zscaler, Inc. (USA)
  • AIRGAP Networks Inc. (USA)
Inventor
  • Agrawal, Ritesh R.
  • Adavi, Vinay
  • Mohan, Satish M.

Abstract

A technique to stop lateral movement of ransomware between endpoints in a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication. Message traffic from compromised endpoints is detected. Attributes of ransomware may be detected in the message traffic, as well as attempts to circumvent the security appliance. Compromised devices may be quarantined.

IPC Classes  ?

35.

Unified Identity Platform for Multiple Cloud Services

      
Application Number 19382653
Status Pending
Filing Date 2025-11-07
First Publication Date 2026-05-14
Owner Zscaler, Inc. (USA)
Inventor
  • Attarwala, Murtuza
  • Wang, Alice
  • Udupa, Siva

Abstract

Systems and methods are provided for enhancing identity management across multiple cloud-based security products. A centralized Identity Provider (IdP) platform dynamically integrates with a plurality of external identity providers to obtain and update federation metadata, propagates identity configurations across different security products, and generates identity-specific logs distinct from traffic and audit logs. The platform supports advanced features including cross-platform risk scoring, multi-device identity association policies, certificate-based authentication for Internet of Things (IoT) devices, and identity proxying for cloud applications. The IdP platform further enables consistent authentication behaviors across heterogeneous products, enforces adaptive access policies, and supports high availability through multi-data-center synchronization and caching.

IPC Classes  ?

36.

Intelligent dynamic security profiles for web application firewalls

      
Application Number 18939929
Grant Number 12676832
Status In Force
Filing Date 2024-11-07
First Publication Date 2026-05-07
Grant Date 2026-07-07
Owner Zscaler, Inc. (USA)
Inventor Gomez, Juan C.

Abstract

Systems and methods for intelligent dynamic security profiles for Web Application Firewalls (WAFs) include receiving raw data related to operation of a plurality of Web Application Firewall (WAF) agents, wherein the plurality of WAF agents are distributed across multiple tenants globally over the Internet; normalizing and sanitizing the raw data; analyzing the normalized and sanitized data with a machine learning algorithm to determine prioritization of rules in a given WAF agent based on the raw data and an objective; and providing a security profile to the given WAF agent where the security profile includes a selection of the rules based on the prioritization and the objective.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • H04L 9/40 - Network security protocols

37.

Dynamic Unified Communications as a Service (UCaaS) application probing

      
Application Number 18915608
Status Pending
Filing Date 2024-10-15
First Publication Date 2026-04-16
Owner Zscaler, Inc. (USA)
Inventor
  • Saggau-Lyons, Ailin
  • Voderbet, Sandeep Kamath
  • Singh, Surender Rammehar
  • Balaiah, Chakkaravarthy Periyasamy

Abstract

Systems and methods for dynamic UCaaS application probing include monitoring, via the cloud-based system, one or more users associated with one or more tenants of the cloud-based system; detecting, based on the monitoring, one or more traffic flows that are associated with one or more Unified Communications as a Service (UCaaS) application calls; and sending a probe to one or more endpoints that are associated with the one or more UCaaS application calls. The steps further include collecting user experience data associated with the one or more UCaaS application calls and providing a unified dashboard for viewing the user experience data and troubleshooting any issues.

IPC Classes  ?

  • H04L 47/2483 - Traffic characterised by specific attributes, e.g. priority or QoS involving identification of individual flows
  • H04L 67/50 - Network services

38.

Artificial Intelligence (AI) agent intent classification and taxonomy management

      
Application Number 18939921
Status Pending
Filing Date 2024-11-07
First Publication Date 2026-03-26
Owner Zscaler, Inc. (USA)
Inventor
  • Xiong, Hanchen
  • Bardhan, Manikya
  • Jagatheesan, Prakash
  • Malleshaiah, Prasannakumar Jobigenahally
  • Tiwari, Praveen
  • Shah, Raimi

Abstract

Systems and methods for AI agent intent classification and taxonomy management include operating an Artificial Intelligence (AI) agent system that includes an agent core connected to memory, one or more tools, and a planner; providing the AI agent with a request; performing intent classification based on the request; and generating an answer to the request based on the intent classification. The intent taxonomy management can include, responsive to adding an intent, reviewing the one or more intents for ambiguity; generating one or more test cases for each of the one or more intents; running a regression test with the one or more test cases; checking for failure cases introduced by the one or more new intents; and providing one or more suggestions to edit the one or more new intents.

IPC Classes  ?

39.

Software development platform repository and account discovery

      
Application Number 18892944
Grant Number 12675603
Status In Force
Filing Date 2024-09-23
First Publication Date 2026-03-26
Grant Date 2026-07-07
Owner Zscaler, Inc. (USA)
Inventor
  • Assayag, Jonathan
  • Danino, Shoham

Abstract

Systems and methods for detecting SDP user accounts that are associated with a company include querying a software development platform for account and repository data based on a customer name for each account analyzing associated account and repository data, generating a score for each account of the plurality of accounts based on the analyzing, the score being indicative of an account belonging to the customer, and labeling one or more accounts of the plurality of accounts as belonging to the customer based on the score.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

40.

Zero trust mobile network-as-a-service

      
Application Number 18893419
Status Pending
Filing Date 2024-09-23
First Publication Date 2026-03-26
Owner Zscaler, Inc. (USA)
Inventor
  • Huybregts, Daan
  • Howe, Nathan
  • Urquhart, Ken

Abstract

Systems and methods for a zero trust mobile network-as-a-service include generating one or more virtualized mobile networks for one or more customers of a cloud service; receiving traffic from a Subscriber Identity Module (SIM) enabled device associated with a customer of the cloud service; steering the traffic through a virtualized mobile network based on the customer associated with the SIM enabled device; and applying zero trust policy to the traffic prior to the traffic exiting the virtualized mobile network.

IPC Classes  ?

  • H04W 12/121 - Wireless intrusion detection systems [WIDS]Wireless intrusion prevention systems [WIPS]

41.

Detecting Secrets in Deleted Software Development Platform Repositories

      
Application Number 19253007
Status Pending
Filing Date 2025-06-27
First Publication Date 2026-03-26
Owner Zscaler, Inc. (USA)
Inventor Danino, Shoham

Abstract

Systems and methods for detecting secrets in deleted software development platforms (SDP) are disclosed herein, including querying an SDP for account and repository data, the querying being based on a customer name, identifying previously existing content that is no long present in a current version of the SDP, reconstructing the previously existing content, analyzing the reconstructed content for one or more indicators of sensitive information, and generating a report based on the analysis.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 8/77 - Software metrics

42.

Intelligent network incident management, root cause analysis, and automated remediation

      
Application Number 18826888
Status Pending
Filing Date 2024-09-06
First Publication Date 2026-03-12
Owner Zscaler, Inc. (USA)
Inventor
  • Ramadass, Rosh
  • Mone, Sasamka

Abstract

Systems and methods for intelligent network incident management, Root Cause Analysis (RCA), and automated remediation include receiving metrics, graphs, and historic logs associated with network performance of a tenant of the cloud system; identifying a network issue based on the received metrics, graphs, and historic logs; performing an automated RCA to determine a cause of the network issue; and remediating the identified network issue based on the determined cause. Various embodiments include training specialized Large Language Models (LLMs) for performing the automated incident identification, RCA, and remediation.

IPC Classes  ?

  • H04L 41/0631 - Management of faults, events, alarms or notifications using root cause analysisManagement of faults, events, alarms or notifications using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis

43.

Query system using multiple AI agents for text-to-SQL and text-to-Python

      
Application Number 18829858
Grant Number 12645672
Status In Force
Filing Date 2024-09-10
First Publication Date 2026-03-12
Grant Date 2026-06-02
Owner Zscaler, Inc. (USA)
Inventor
  • Luo, Gaoxiang
  • Zhu, Zixu
  • Pappas, Kevin
  • Drummond-Hay, Charles
  • Raman, Rahavan

Abstract

Systems and methods are provided for enabling search and query functions. A query system having a framework, executed on one or more processors, includes a plurality of Artificial Intelligence (AI) agents working to support one of text-to-Structured Query Language (SQL) or text-to-Python, wherein the plurality of AI agents include a first AI agent prompted to act as a research analyst for performing a task of interpreting a natural language query from a user, wherein the natural language query relates to natural language to the one of text-to-SQL or text-to-Python; a second AI agent prompted to act as a search data engineer for performing a task of executing a search based on the natural language query; and a third AI agent prompted to act as a code developer for performing a task of writing code based on the search, wherein the plurality of AI agents act autonomously yet collaboratively.

IPC Classes  ?

44.

Malicious network beaconing detection

      
Application Number 18925429
Status Pending
Filing Date 2024-10-24
First Publication Date 2026-03-12
Owner Zscaler, Inc. (USA)
Inventor
  • Cong, Zicun
  • Singh, Atinderpal
  • Mahato, Pradeep
  • Lan, Yung-Wen
  • Chauhan, Kruti Sandeep
  • Shacham, Dan
  • Paul, Sandeep
  • Shang, Rex
  • Desai, Deepen
  • Bollinger, Jacob

Abstract

Systems and methods for malicious beaconing detection include extracting one or more beaconing sequences from log data associated with a network; performing feature extraction for the one or more extracted beaconing sequences; and implementing one or more Machine Learning (ML) models for classifying each of the one or more beaconing sequences as any of clean, malicious, suspicious, and unknown. The one or more ML models can be associated with an ensemble model, where a final classification of a beaconing sequence can be based on results of each of the one or more ML models.

IPC Classes  ?

45.

Generating Software Development Life Cycle (SDLC)-based application segments

      
Application Number 18918429
Status Pending
Filing Date 2024-10-17
First Publication Date 2026-03-05
Owner Zscaler, Inc. (USA)
Inventor
  • Hu, Chenhui
  • Omar, Shikhar

Abstract

Systems and methods for generating SDLC-based application segments include defining a set of applications, the set of applications comprising a plurality of applications associated with a tenant of the cloud-based system; generating a plurality of application pairs from the set of applications; analyzing applications within each application pair of the plurality of application pairs for filtering the plurality of application pairs, the analyzing comprising a plurality of similarity checks and identification of environment key words; and generating one or more application segments each comprising one or more applications from the set of applications based on the filtering.

IPC Classes  ?

  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • G06F 8/70 - Software maintenance or management
  • G06F 40/20 - Natural language analysis

46.

Cross-domain Identity Management (SCIM)-based policy generation for application segments

      
Application Number 18918432
Status Pending
Filing Date 2024-10-17
First Publication Date 2026-03-05
Owner Zscaler, Inc. (USA)
Inventor
  • Hu, Chenhui
  • Omar, Shikhar

Abstract

Systems and methods for generating SCIM-based application segment policies include obtaining log data for a plurality of users of an enterprise where the log data relates to usage of a plurality of applications by the plurality of users, wherein the enterprise is one of a plurality of enterprises associated with the cloud-based system; determining one or more app-segments that are groupings of application of the plurality of applications; and generating access policy of the plurality of applications based on System for Cross-domain Identity Management (SCIM) data and the one or more app-segments.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 43/067 - Generation of reports using time frame reporting

47.

Systems and Methods for Application Segmentation Leveraging Configuration Management Database (CMDB) Integration and Real-Time Data Analytics

      
Application Number 19381812
Status Pending
Filing Date 2025-11-06
First Publication Date 2026-03-05
Owner Zscaler, Inc. (USA)
Inventor
  • Shah, Suketu Bharat
  • Bandarupalli, Phani Krishna
  • Ramasamy, Brindha
  • Subramaniyam, Sankarkumar
  • Krishnamaraju, Raghava
  • Hu, Chenhui
  • Bitla, Vivek
  • Tamvada, Megha

Abstract

A cloud-based private access system integrates static CMDB data with real-time access telemetry to automate Zero Trust segmentation. Administrators upload CMDB files (e.g., CSV/JSON) describing applications, FQDNs, IPs, ports, protocols, ownership, and priorities. An analytics management service stages and normalizes the data, retrieves reference domain data from an in-memory cache, and queries a telemetry engine to correlate intended configurations with observed usage. The system detects mismatches, over-permissive wildcard access, and auto-discovers non-listed elements such as subdomains, ports, or protocol combinations. It then generates prioritized recommendations to refine wildcard rules, create explicit allow policies, and merge or split application groups. Administrators review, simulate, and approve updates, enabling phased rollout, rollback, auditing, and continuous policy tuning based on evolving user and application behavior.

IPC Classes  ?

48.

Automatic Detection and Visualization of Application Hosting Sites

      
Application Number 19381831
Status Pending
Filing Date 2025-11-06
First Publication Date 2026-03-05
Owner Zscaler, Inc. (USA)
Inventor
  • Shah, Suketu Bharat
  • Ramasamy, Brindha
  • Tamvada, Megha
  • Menon, Joby
  • Shekar, Aruna
  • Hu, Chenhui
  • Jaber, Omar

Abstract

Disclosed are systems and methods for generating location-aware reports for enterprise application usage. Transactional data is obtained from intermediaries mediating user access via application connectors, and location data is acquired for hosted applications, including hosting platform type (public cloud or private data center), region identifiers, and geo-location attributes. Geo-location is derived via API-integrated metadata and IP-based lookup, with administrator entry for private centers. The analyzed data produces site-level residency determinations and correlates access paths with geographic attributes. Reports include a global, interactive map that geo-tags sites in real time, a bar graph view that sorts application sites and displays endpoint counts, and dynamic insights per site (application listings, user access numbers, total and per-application traffic, and data volume trends), thereby enhancing visibility for compliance and operational oversight.

IPC Classes  ?

  • H04L 67/51 - Discovery or management thereof, e.g. service location protocol [SLP] or web services

49.

Systems and Methods for Providing Efficient Remediations for Cloud Environment Vulnerabilities

      
Application Number 19383378
Status Pending
Filing Date 2025-11-07
First Publication Date 2026-03-05
Owner Zscaler, Inc. (USA)
Inventor
  • Barel, Nir
  • Danino, Shoham

Abstract

Disclosed are systems and methods for continuous exposure management across multiple cloud environments. Posture control data, including configuration, vulnerability, and identity activity information, is continuously collected and aggregated into a unified exposure dataset. A machine-learning correlation model analyzes the dataset to identify combinations of seemingly unrelated low-risk events that collectively form higher-risk exposure conditions. Each exposure condition is assigned a risk score, and potential remediation actions are evaluated using a remediation priority score based on the amount of risk mitigated and the relative remediation effort. Remediation actions are then prioritized to optimize overall risk reduction efficiency. The system continuously updates exposure data and prioritization as new information is received, enabling dynamic and scalable management of cloud security posture and reducing the operational burden of manual prioritization.

IPC Classes  ?

50.

Data Owner Controls in DLP

      
Application Number 19383463
Status Pending
Filing Date 2025-11-07
First Publication Date 2026-03-05
Owner Zscaler, Inc. (USA)
Inventor
  • Deshmukh, Pooja
  • Bayar, Balakrishna
  • Bhallamudi, Arun
  • Devarajan, Srikanth
  • Udupa, Siva

Abstract

Systems and methods are disclosed for data owner control in Data Loss/Leakage Prevention (DLP). A data owner system processes sensitive data from a structured data source, normalizes fields, and generates an index comprising one-way hash representations of tokens. The index, including schema and primary key information, is uploaded via a secure channel to a cloud-based monitoring system. The cloud system distributes the index to enforcement nodes and performs inline monitoring of network traffic. Content is tokenized and normalized, and tokens are compared against the hashed index using index lookup tables and token windows to detect violations. Policies specify actions such as reporting, blocking, quarantining, or allowing authenticated personally identifiable information (PII) of a data owner. Incremental updates are supported through row hash-based deltas without regenerating the entire index. This approach provides efficient, precise, and privacy-preserving DLP while reducing false positives and granting data owners control over use of their own data.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 16/22 - IndexingData structures thereforStorage structures
  • H04L 9/40 - Network security protocols

51.

Distributed Network Application Security Policy Generation and Enforcement for Microsegmentation

      
Application Number 19385716
Status Pending
Filing Date 2025-11-11
First Publication Date 2026-03-05
Owner Zscaler, Inc. (USA)
Inventor
  • O’neil, John H.
  • Smith, Peter
  • Keiser, Jr., Thomas Evan

Abstract

Techniques are disclosed for enforcing application-centric microsegmentation policies in a network using machine learning. A trained machine learning model classifies network communication flows between hosts and applications to generate labeled flows. Based on these classifications, a microsegmentation policy is automatically generated that is independent of underlying network topology and optimized for performance, accuracy, or interpretability. A host in the network receives the microsegmentation policy and applies it locally to flows associated with the host. Enforcement of the policy includes allowing, blocking, quarantining, or redirecting flows according to the labels. The approach enables granular east-west traffic controls, dynamic adaptation to changing flow conditions, and automatic updates based on retrained models. Additional features include hierarchical policy structures, contextual metadata for flow classification, audit logging, and user-facing visualization of microsegments. The disclosed methods improve workload security by providing scalable, data-driven, and automatically generated microsegmentation policies.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • G06F 21/60 - Protecting data
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

52.

Utilizing deep learning for inline Uniform Resource Locator (URL) categorization

      
Application Number 18909037
Status Pending
Filing Date 2024-10-08
First Publication Date 2026-02-26
Owner Zscaler, Inc. (USA)
Inventor
  • Hu, Chenhui
  • Salih, Muhammed
  • Zhang, Miao
  • Nagpal, Kabir
  • Shang, Rex
  • Bollinger, Jacob
  • Kumar, Santhosh

Abstract

Systems and methods for inline Uniform Resource Locator (URL) categorization include training a lightweight machine learning model to score content associated with unknown Uniform Resource Locators (URLs) to determine a category of the plurality of categories for each of the unknown URLs; deploying the trained lightweight machine learning model to a node in a cloud-based system for use in production; and utilizing the trained lightweight machine learning model to monitor traffic inline to categorize unknown URLs.

IPC Classes  ?

  • H04L 47/2441 - Traffic characterised by specific attributes, e.g. priority or QoS relying on flow classification, e.g. using integrated services [IntServ]
  • G06F 16/955 - Retrieval from the web using information identifiers, e.g. uniform resource locators [URL]
  • G06F 16/958 - Organisation or management of web site content, e.g. publishing, maintaining pages or automatic linking

53.

Systems and methods for cloud discovery and orchestration

      
Application Number 18814809
Grant Number 12706957
Status In Force
Filing Date 2024-08-26
First Publication Date 2026-02-26
Grant Date 2026-08-11
Owner Zscaler, Inc. (USA)
Inventor
  • Kovacs, Zoltan
  • Howe, Nathan

Abstract

Systems and methods for cloud discovery and orchestration include retrieving a plurality of out-of-band inputs related to a cloud environment; retrieving a plurality of inline inputs related to the cloud environment; determining one or more correlations between one or more destinations, sources, and networks associated with the cloud environment based on the out-of-band inputs and the inline inputs; and determining one or more relationships between the one or more destinations, sources, and networks based on the correlations.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 9/40 - Network security protocols

54.

ZERO TRUST EXCHANGE

      
Serial Number 99659772
Status Pending
Filing Date 2026-02-19
Owner Zscaler, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Software as a service (SAAS) services featuring software for digital security and experience management services, namely, enforcing, restricting, enhancing and controlling access to private applications and services, hosted applications and services, cloud applications and services, Software-as-a-Service (SaaS) applications and services, Anything-as-a-Service (XaaS) applications, devices and services; platform as a service (PaaS) featuring computer software platforms for providing secure, cloud-delivered access to applications, data, artificial intelligence (ai), and services across distributed networks by enforcing security policies, including in the fields of identity-based access control, secure web gateway, cloud firewall, cloud access security broker (CASB), data loss prevention, threat detection and sandboxing, traffic inspection, and protection of users, workloads, and devices across on-premises, cloud, and hybrid environments; Computer security threat analysis for protecting data; Data security consultancy; Internet security consultancy; Computer network security consultancy; Computer services, namely, on-line scanning, detecting, quarantining and eliminating of viruses, worms, trojans, spyware, adware, malware and unauthorized data and programs on computers and electronic devices; Software as a service (SAAS) services featuring software using artificial intelligence (AI) for detecting, analyzing, and remediating cybersecurity threats, correlating network, application, and user activity to identify anomalous behavior, automating policy enforcement and access decisions based on contextual risk signals, and generating predictive insights to enhance security controls across cloud, on-premises, and hybrid computing environments.

55.

ACT FAST. STAY SECURE.

      
Serial Number 99659381
Status Registered
Filing Date 2026-02-18
Registration Date 2026-09-08
Owner Zscaler, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Software as a service (SAAS) services featuring software for providing a cloud-based security platform for securely connecting users, workloads, and devices to applications and data over any network and for AI-powered threat detection, data loss prevention, and zero trust network access; Research in the field of artificial intelligence; Computer network security consultancy; Computer security consultancy

56.

Utilizing cloud-based data for determining and recommending organization office site locations

      
Application Number 18888402
Status Pending
Filing Date 2024-09-18
First Publication Date 2026-02-12
Owner Zscaler, Inc. (USA)
Inventor
  • Balaiah, Chakkaravarthy Periyasamy
  • Bathla, Abhishek

Abstract

Systems and methods for utilizing cloud-based data for determining and recommending organization office site locations include obtaining data from a cloud-based system associated with employees of an organization, wherein the cloud-based system includes a plurality of organizations with employees each assigned thereto; processing the data associated with the organization to determine a plurality of office site locations of the organization; and displaying the plurality of office site locations of the organization via a User Interface (UI) based on the processing.

IPC Classes  ?

  • G06Q 10/067 - Enterprise or organisation modelling
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network

57.

Similar domain detection using favicon comparison

      
Application Number 18792055
Status Pending
Filing Date 2024-08-01
First Publication Date 2026-02-05
Owner Zscaler, Inc. (USA)
Inventor
  • Barel, Nir
  • Danino, Shoham

Abstract

Systems and methods for favicon comparison-based similar domain detection include receiving a base domain, the base domain being associated with an enterprise; receiving a domain list comprising a plurality of domains; performing a favicon comparison between the base domain and each of the plurality of domains within the domain list; and classifying each of the plurality of domains within the domain list as one of being associated with the enterprise or not being associated with the enterprise based on the favicon comparison.

IPC Classes  ?

58.

Adaptive Per-Packet Transmission Control Protocol (TCP) Traceroute

      
Application Number 19289859
Status Pending
Filing Date 2025-08-04
First Publication Date 2026-01-29
Owner Zscaler, Inc. (USA)
Inventor Chhabra, Pankaj

Abstract

The present disclosure describes systems and methods for performing adaptive network tracing using a hybrid approach. The method involves creating a valid TCP connection with a target destination and sending TCP packets with increasing TTL values to identify network hops. When a TCP handshake fails for specific packets, the system switches to sending TCP SYN packets with increasing TTLs to continue tracing. Hop and packet information are encoded into the IPV6 destination option header or the random bytes portion of a TLS Client Hello message for comprehensive tracking. Responses, including ICMP “Time Exceeded” messages, allow extraction of encoded trace data to identify routers along the path. The hybrid approach ensures robust results by overcoming network limitations, such as firewall restrictions and rate-limiting mechanisms, while maintaining low resource consumption. These systems optimize tracing, particularly in IPV6 and TLS environments, enabling accurate mapping of network routes for diagnostics and analysis.

IPC Classes  ?

  • H04L 43/106 - Active monitoring, e.g. heartbeat, ping or trace-route using time related information in packets, e.g. by adding timestamps
  • H04L 45/00 - Routing or path finding of packets in data switching networks
  • H04L 67/145 - Termination or inactivation of sessions, e.g. event-controlled end of session avoiding end of session, e.g. keep-alive, heartbeats, resumption message or wake-up for inactive or interrupted session
  • H04L 69/163 - In-band adaptation of TCP data exchangeIn-band control procedures
  • H04L 69/22 - Parsing or analysis of headers
  • H04L 69/28 - Timers or timing mechanisms used in protocols

59.

Similar domain detection using similarity check-based ranking

      
Application Number 18756146
Grant Number 12689608
Status In Force
Filing Date 2024-06-27
First Publication Date 2026-01-01
Grant Date 2026-07-21
Owner Zscaler, Inc. (USA)
Inventor
  • Gozlan, Roee
  • Danino, Shoham

Abstract

Systems and methods for similar domain detection include receiving a base domain, the base domain being associated with an enterprise; receiving a domain list comprising a plurality of domains; performing a plurality of similarity checks between the base domain and each of the plurality of domains within the domain list; and generating a directory of domains comprising one or more domains determined to be associated with the enterprise based on the one or more similarity checks.

IPC Classes  ?

  • H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
  • H04L 61/59 - Network arrangements, protocols or services for addressing or naming using proxies for addressing

60.

Client-Rooted Decryption Public Key Infrastructure (PKI) for Secure Cloud-Based Inspection of Encrypted Traffic

      
Application Number 19322142
Status Pending
Filing Date 2025-09-08
First Publication Date 2026-01-01
Owner Zscaler, Inc. (USA)
Inventor
  • Weith, Loren
  • Rosomakho, Yaroslav
  • Chanak, John A.
  • Tarnavsky, Vadim
  • Pergament, Lidor

Abstract

Techniques for implementing a client-rooted decryption Public Key Infrastructure (PKI) to securely inspect encrypted traffic in cloud-based proxy environments are disclosed. A proxy node generates an intermediate Certificate Authority (CA) certificate signing request (CSR) and sends it to a client device equipped with a locally-managed root CA. The client device cross-signs the CSR, creating a client-specific intermediate CA certificate, which it returns to the proxy node. This client-specific intermediate CA certificate is scoped uniquely to the individual client device, significantly reducing the potential blast radius in case of CA key compromise. The proxy node uses the client-specific CA certificate to dynamically generate short-lived, scoped decryption certificates for inspecting encrypted traffic. This architecture provides client-level control of trust boundaries, enhanced traceability, reduced complexity, and improved scalability of encrypted traffic inspection, minimizing the operational risks associated with conventional centralized certificate management.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/40 - Network security protocols

61.

Systems and methods for traffic inspection using payload offsets

      
Application Number 18752239
Grant Number 12641091
Status In Force
Filing Date 2024-06-24
First Publication Date 2025-12-25
Grant Date 2026-05-26
Owner Zscaler, Inc. (USA)
Inventor
  • Gomez, Juan
  • George, Anna
  • Joseph, Jane
  • Varanasi, Kanti
  • Bhatia, Nikhil
  • Kumar, Pankaj

Abstract

Systems and methods for traffic inspection using payload offsets include performing inline monitoring between one or more endpoints and the internet; receiving a payload based on the inline monitoring; and performing traffic inspection of the payload based on one or more inspection offset values, wherein the one or more inspection offset values define one or more points within the payload for inspection to begin.

IPC Classes  ?

62.

Systems and methods for probability-based inline rule inspection

      
Application Number 18752226
Grant Number 12621266
Status In Force
Filing Date 2024-06-24
First Publication Date 2025-12-25
Grant Date 2026-05-05
Owner Zscaler, Inc. (USA)
Inventor
  • Gomez, Juan
  • George, Anna
  • Joseph, Jane
  • Varanasi, Kanti
  • Bhatia, Nikhil
  • Kumar, Pankaj

Abstract

Systems and methods for probability-based inline rule inspection include performing inline monitoring between one or more endpoints and the internet; receiving a payload based on the inline monitoring; and performing traffic inspection of the payload based on one or more rules, wherein each of the one or more rules are inspected based on a probability assigned thereto, and wherein the probability assigned to each of the one or more rules can be a function of an execution time of each of the one or more rules and a historic effectiveness of each of the one or more rules.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 47/20 - Traffic policing

63.

Systems and methods for providing interactive visualizations of traffic characteristics within a network

      
Application Number 18792043
Status Pending
Filing Date 2024-08-01
First Publication Date 2025-12-18
Owner Zscaler, Inc. (USA)
Inventor
  • Joseph, Jane
  • Kumar, Mahesh Krishna
  • Chawla, Mohit
  • Sugumaran, Rajamohan
  • Guha, Sumit
  • Menon, Sunil

Abstract

Systems and methods for providing interactive visualizations of traffic characteristics within a network include determining, for one or more applications associated with a tenant of a cloud-based system, application information associated with each of the one or more applications; providing, via a Graphical User Interface (GUI), an interactive visualization of the application information associated with each of the one or more applications; and responsive to one or more selections being made via the interactive visualization, enabling one or more cloud-based security functions based on the one or more selections.

IPC Classes  ?

  • G06F 3/04847 - Interaction techniques to control parameter settings, e.g. interaction with sliders or dials
  • G06F 3/0482 - Interaction with lists of selectable items, e.g. menus
  • H04L 9/40 - Network security protocols

64.

Digital experience Artificial Intelligence (AI) assistant for end users

      
Application Number 18895954
Status Pending
Filing Date 2024-09-25
First Publication Date 2025-12-11
Owner Zscaler, Inc. (USA)
Inventor
  • Malleshaiah, Prasannakumar Jobigenahally
  • Rodriguez Gonzalez, Francisco Javier
  • Srivastava, Vikas
  • Patel, Amitkumar
  • Kolachina, Ashok
  • Desai, Vandan
  • Budukh, Tejas

Abstract

Systems and methods for an Artificial Intelligence (AI) agent adapted to support end users includes performing monitoring of one or more users via a cloud-based system and logging device metrics based thereon, wherein the device metrics are associated with one or more devices of the one or more users; providing an Artificial Intelligence (AI) agent adapted to troubleshoot issues related to the one or more devices; and responsive to the AI agent being invoked by a user of the one or more users, providing one or more remediation recommendations for one or more issues based on the device metrics.

IPC Classes  ?

  • G06F 11/07 - Responding to the occurrence of a fault, e.g. fault tolerance
  • G06K 19/06 - Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code

65.

Artificial Intelligence (AI) agent evaluation framework

      
Application Number 18884279
Status Pending
Filing Date 2024-09-13
First Publication Date 2025-12-11
Owner Zscaler, Inc. (USA)
Inventor
  • Tiwari, Praveen
  • Thimmisetty, Charanraj
  • Wang, Xuejiao
  • Malleshaiah, Prasannakumar Jobigenahally
  • Sen, Shaunak
  • Xiong, Hanchen

Abstract

Systems and methods for an Artificial Intelligence (AI) agent evaluation framework include operating, in a test environment, an Artificial Intelligence (AI) agent system that includes an agent core connected to memory, one or more tools, and a planner; providing the AI agent with one or more requests; receiving a response to each of the one or more requests; and evaluating performance of the AI agent based on responses to each of the one or more requests. The one or more requests can be LLM-generated variations of a seed request either for testing the AI agent's ability to respond to queries or to test the ability of the AI agent to ignore malicious requests.

IPC Classes  ?

  • G06Q 10/0639 - Performance analysis of employeesPerformance analysis of enterprise or organisation operations

66.

Artificial Intelligence (AI) agent playbook utilization and management

      
Application Number 18889931
Status Pending
Filing Date 2024-09-19
First Publication Date 2025-12-11
Owner Zscaler, Inc. (USA)
Inventor
  • Xiong, Hanchen
  • Malleshaiah, Prasannakumar Jobigenahally
  • Tiwari, Praveen
  • Thimmisetty, Charan
  • Rodriguez Gonzalez, Francisco Javier
  • Shah, Raimi
  • Tummala, Srinivas Rao

Abstract

Systems and methods for Artificial Intelligence (AI) agent playbook utilization and management include receiving a request from a natural language conversational interface where the request relates to user experience associated with one or more users using a network to access services; analyzing the request to determine intent; and processing the request based on the intent, wherein the processing is performed based on a playbook of a plurality of playbooks. The steps include generating one or more playbooks based on a playbook generation lifecycle, wherein the playbook generation lifecycle includes creating a playbook, testing the playbook, reviewing the playbook, and delivering the playbook.

IPC Classes  ?

  • G06F 40/35 - Discourse or dialogue representation

67.

Anomaly Detection via a Detect and Collect Approach

      
Application Number 19227993
Status Pending
Filing Date 2025-06-04
First Publication Date 2025-12-11
Owner Zscaler, Inc. (USA)
Inventor
  • Guha, Sudipto
  • Tiwari, Praveen

Abstract

Systems and methods are disclosed for anomaly detection using a “detect and collect” cybersecurity monitoring approach. Initially, a cybersecurity monitoring system obtains and analyzes a baseline subset of telemetry data from computing resources to detect potential anomalies indicative of cybersecurity threats. Responsive to identifying such anomalies, the system selectively determines additional, contextually relevant telemetry data for targeted collection. This selective data collection significantly reduces telemetry volumes, enhancing efficiency and scalability. An intelligent data fabric and dynamic security knowledge graph are employed to enrich telemetry data in real-time, enabling comprehensive anomaly characterization, risk scoring, and automated security responses. The disclosed techniques support multimodal and multiresolution anomaly detection, adaptive learning, and rapid threat response within diverse distributed computing environments.

IPC Classes  ?

68.

Detection of Phishing Domains via Short Uniform Resource Locator (URL) Redirection Analysis

      
Application Number 19302475
Status Pending
Filing Date 2025-08-18
First Publication Date 2025-12-11
Owner Zscaler, Inc. (USA)
Inventor Danino, Shoham

Abstract

Systems and methods include receiving a customer domain from a user via a user device; parsing a plurality of candidate look-alike domains based on the customer domain; executing at least one detection technique selected from a plurality of short URL detection techniques to determine whether one or more short URLs redirect to one of the plurality of candidate look-alike domains; and in response to determining, by the at least one detection technique, that the one or more short URLs redirect to one of the plurality of candidate look-alike domains, classifying that candidate look-alike domain as a phishing attempt.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • G06F 16/955 - Retrieval from the web using information identifiers, e.g. uniform resource locators [URL]

69.

Context aware Artificial Intelligence (AI) assistant for troubleshooting network issues

      
Application Number 18915586
Status Pending
Filing Date 2024-10-15
First Publication Date 2025-12-04
Owner Zscaler, Inc. (USA)
Inventor
  • Malleshaiah, Prasannakumar Jobigenahally
  • Khechinashvili, Valentin
  • Rodriguez Gonzalez, Francisco Javier
  • Shete, Shriyash
  • Yelmar, Akshay
  • Xiong, Hanchen

Abstract

Systems and methods for a context aware Artificial Intelligence (AI) assistant for troubleshooting network issues includes operating an Artificial Intelligence (AI) agent system that includes an agent core connected to memory, one or more tools, and a planner; receiving a request from a user; and generating, via the AI agent, an answer to the request using a plurality of inputs related to user experience of one or more users associated with a tenant of a cloud-based system.

IPC Classes  ?

70.

Artificial intelligence (AI) agent inputs using user interfaces (UIs)

      
Application Number 18915597
Grant Number 12645714
Status In Force
Filing Date 2024-10-15
First Publication Date 2025-12-04
Grant Date 2026-06-02
Owner Zscaler, Inc. (USA)
Inventor
  • Malleshaiah, Prasannakumar Jobigenahally
  • Khechinashvili, Valentin
  • Rodriguez Gonzalez, Francisco Javier
  • Shete, Shriyash
  • Yelmar, Akshay
  • Xiong, Hanchen

Abstract

Systems and methods for Artificial Intelligence (AI) agent inputs using User Interfaces (UIs) includes operating an Artificial Intelligence (AI) agent system that includes an agent core connected to memory, one or more tools, and a planner; receiving an input from a user, wherein the input includes any of a prompt from the user and a selection from a User Interface (UI); and generating, via the AI agent, an answer based on the input.

IPC Classes  ?

  • G06F 16/00 - Information retrievalDatabase structures thereforFile system structures therefor
  • G06F 3/0483 - Interaction with page-structured environments, e.g. book metaphor
  • G06F 3/04842 - Selection of displayed objects or displayed text elements
  • G06F 16/332 - Query formulation
  • G06F 16/3329 - Natural language query formulation
  • G06F 16/335 - Filtering based on additional data, e.g. user or group profiles
  • G06F 16/338 - Presentation of query results
  • G06F 40/134 - Hyperlinking
  • G06T 11/26 -
  • G06T 11/60 - Editing figures and textCombining figures or text

71.

System and Method thereof for Agentless Monitoring of Third-Party Applications

      
Application Number 19298744
Status Pending
Filing Date 2025-08-13
First Publication Date 2025-12-04
Owner Zscaler, Inc. (USA)
Inventor
  • Gorin, Boris
  • Steingarten, Niv

Abstract

Systems and methods are disclosed for agentless monitoring of third-party applications in a software as a service (SaaS) environment. A monitoring agentless application (MAA) initiates a service instance in a cloud-based computing environment of a SaaS provider and populates the service instance with simulated resources and simulated data that emulate an authentic SaaS environment while excluding sensitive information. Access credentials are provided to a third-party application, enabling the third-party application to operate within the service instance under realistic conditions. The MAA monitors actions performed by the third-party application with respect to the simulated resources to extract behavior data, such as resource access patterns, data collection frequency, configuration changes, or network communications. The behavior data may be analyzed to detect anomalous or malicious activity, thereby enabling behavioral analysis of SaaS applications without installing agents or exposing production environments.

IPC Classes  ?

72.

Generative User Interfaces (UIs) for Artificial Intelligence (AI) agents

      
Application Number 18915591
Status Pending
Filing Date 2024-10-15
First Publication Date 2025-12-04
Owner Zscaler, Inc. (USA)
Inventor
  • Malleshaiah, Prasannakumar Jobigenahally
  • Khechinashvili, Valentin
  • Rodriguez Gonzalez, Francisco Javier
  • Shete, Shriyash
  • Yelmar, Akshay
  • Xiong, Hanchen

Abstract

Systems and methods for generative User Interfaces (UIs) for Artificial Intelligence (AI) agents includes operating an Artificial Intelligence (AI) agent system that includes an agent core connected to memory, one or more tools, and a planner; receiving a request from a user; and generating, via the AI agent, a response including an interactive data visualization based on the request.

IPC Classes  ?

  • G06F 3/0483 - Interaction with page-structured environments, e.g. book metaphor
  • G06F 40/134 - Hyperlinking
  • G06T 11/20 - Drawing from basic elements, e.g. lines or circles
  • G06T 11/60 - Editing figures and textCombining figures or text

73.

Vulnerabilities and Protections in Large Language Models

      
Application Number 18924682
Status Pending
Filing Date 2024-10-23
First Publication Date 2025-12-04
Owner Zscaler, Inc. (USA)
Inventor
  • Hu, Chenhui
  • Liu, Weizhen
  • Zhang, Miao

Abstract

Large Language Model (LLM) security includes monitoring an LLM; detecting an attack on the LLM and defining an attack type of a plurality of attack types based on the monitoring, providing a notification of the attack; and causing a defense to the attack based on the attack type. Advantageously, the security can be configured to be executed between a user outside of the LLM. Further, the security can be configured to defend against multi-turn attacks.

IPC Classes  ?

74.

Dynamic Invocation of Synthetic Probes Based on Real User Monitoring Agents

      
Application Number 19232640
Status Pending
Filing Date 2025-06-09
First Publication Date 2025-11-27
Owner Zscaler, Inc. (USA)
Inventor
  • Chaturvedi, Abhishek
  • Penumudy, Rajasekhar
  • Malleshaiah, Prasanna Jobigenahally
  • Desai, Vandan
  • Kalipatnapu, Satish
  • Chhabra, Pankaj
  • Desai, Purvi
  • Voderbet, Sandeep Kamath

Abstract

Systems and methods for dynamic invocation of synthetic probes based on Real User Monitoring (RUM) agents include monitoring application performance metrics using a Real User Monitoring (RUM) agent embedded within a client application, wherein the RUM agent continuously observes and reports metrics indicative of user experience; detecting performance anomalies by analyzing application and network metrics against baseline performance thresholds established during normal operations; and initiating dynamic synthetic probes in response to the detected anomalies, wherein said synthetic probes are adaptively configured to target relevant destinations, adjust probing frequency, and utilize specific probing methods tailored to the characteristics and severity of the performance anomalies.

IPC Classes  ?

  • G06F 11/07 - Responding to the occurrence of a fault, e.g. fault tolerance

75.

Lookalike Domain Phishing Detection

      
Application Number 19289975
Status Pending
Filing Date 2025-08-04
First Publication Date 2025-11-27
Owner Zscaler, Inc. (USA)
Inventor
  • Rubin, Dani
  • Danino, Shoham

Abstract

The present disclosure enhances domain lookalike detection by integrating a phishing risk assessment score into a multi-layered evaluation framework. The method systematically generates lookalike domains through genetic algorithms. Registered domains undergo advanced phishing analysis, incorporating domain and URL checks, technical infrastructure assessments, content inspections, and reputation-based intelligence to calculate a dynamic phishing score. A comprehensive risk score is then determined by merging phishing likelihood with business attributes, graphical/contextual similarity metrics, and domain registration patterns. Domains are categorized into predefined risk levels including phishing, registered, preventative, company-owned, or watchlist, with specific action recommendations provided for each category. The system generates prioritized alerts for high-risk domains, offering customers actionable intelligence to mitigate threats. By combining phishing-specific indicators with contextual evaluations, this solution improves detection accuracy, reduces false positives, and enables organizations to respond effectively to domain-based threats in real time, addressing evolving cybersecurity challenges.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence

76.

Techniques for generating natural language context in an issue tracking system

      
Application Number 18672444
Grant Number 12675470
Status In Force
Filing Date 2024-05-23
First Publication Date 2025-11-27
Grant Date 2026-07-07
Owner
  • Avalor Technologies Ltd. (Israel)
  • Zscaler, Inc. (USA)
Inventor
  • Tishbi, Kfir Aharon
  • Raz, Raanan

Abstract

Generating a natural language context from a ticket management system includes receiving an unstructured natural language query from a client device; generating a first prompt for a first large language model (LLM) based on: a predefined template and the unstructured natural language query, the first prompt when processed by the first LLM outputs a structured database query; executing the structured database query on a database, the database including a representation of a cloud computing environment; generating a second prompt for a second LLM based on a result of executing the structured database query, the second prompt when processed by the second LLM outputs a natural language response; and sending the natural language response to the client device.

IPC Classes  ?

77.

System and method for utilizing DHCP relay to accomplish quarantining client endpoints in a ransomware protected network

      
Application Number 18346078
Grant Number 12483589
Status In Force
Filing Date 2023-06-30
First Publication Date 2025-11-25
Grant Date 2025-11-25
Owner Zscaler, Inc. (USA)
Inventor
  • Cheh, Raymond Wing Chon
  • Mohan, Satish M.
  • Adavi, Vinay
  • Agrawal, Ritesh R.

Abstract

A technique to stop lateral movement of ransomware between endpoints in a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication by overwriting the DHCP responses. Message traffic from compromised endpoints is detected. Attributes of ransomware may be detected in the message traffic, as well as attempts to circumvent the security appliance. Compromised devices may be quarantined by assigning them the default gateway to a preset blackhole IP address.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 61/5014 - Internet protocol [IP] addresses using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP]

78.

Public to Private Mobile Access

      
Application Number 19289922
Status Pending
Filing Date 2025-08-04
First Publication Date 2025-11-20
Owner Zscaler, Inc. (USA)
Inventor
  • Anghel, Stefan
  • Howe, Nathan
  • Huybregts, Daan
  • Srinivasan, Subramanian

Abstract

This invention provides methods and systems for seamless mobile connectivity between public and private cellular networks. The system dynamically switches user devices between networks based on location, radio signal availability, or preconfigured policies that prioritize private networks when within range. For devices with physical SIM cards, an embedded applet enables switching between operator profiles, while ESIM profiles deploy applets for selecting among multiple identities within a profile. All cellular traffic, whether on public or private networks, is routed through a cloud-based system for centralized security and policy enforcement. Network selection may be influenced by defining the private network as the Home Public Land Mobile Network (HPLMN) or scanning available networks via applet capabilities. The system supports unified subscription, connectivity, and service management via a cloud-based portal, ensuring reliability and security across diverse network environments. This approach enhances mobility, security, and flexibility for enterprise and IoT applications.

IPC Classes  ?

  • H04W 36/14 - Reselecting a network or an air interface
  • H04W 8/18 - Processing of user or subscriber data, e.g. subscribed services, user preferences or user profilesTransfer of user or subscriber data
  • H04W 48/18 - Selecting a network or a communication service
  • H04W 72/56 - Allocation or scheduling criteria for wireless resources based on priority criteria
  • H04W 76/16 - Setup of multiple wireless link connections involving different core network technologies, e.g. a packet-switched [PS] bearer in combination with a circuit-switched [CS] bearer

79.

Zero Trust Policy Engine for Controlling Access to Network Applications

      
Application Number 19275873
Status Pending
Filing Date 2025-07-21
First Publication Date 2025-11-13
Owner Zscaler, Inc. (USA)
Inventor
  • Ganguli, Sanjit
  • Howe, Nathan
  • Ballmer, Daniel

Abstract

Disclosed is a method for implementing a Zero Trust Architecture (ZTA) to secure network resources by eliminating lateral threat movement and minimizing attack surfaces. A zero trust policy engine, positioned inline between user devices and network resources, receives and evaluates access requests by verifying user and device identities along with context information. Based on dynamic risk scores derived from these evaluations, the engine enforces least-privileged, identity-based access policies, selectively granting access exclusively to authorized resources. Connections are terminated and re-established through secure proxy techniques, with continuous inspection of traffic for threats and data loss. Adaptive security measures, including isolation through pixel-streaming and context-aware access adjustments, further enhance protection. This architecture integrates seamlessly with cloud-based security service platforms, supporting workload-to-workload security, external entity integration, and comprehensive compliance reporting through audit trails and dashboards.

IPC Classes  ?

80.

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI)

      
Application Number 18746498
Status Pending
Filing Date 2024-06-18
First Publication Date 2025-11-06
Owner Zscaler, Inc. (USA)
Inventor
  • Pergament, Lidor
  • Udupa, Siva
  • Devarajan, Srikanth
  • Maheshwari, Akshat
  • Kumar, Sujay
  • Nanjundaswamy, Shashidhara M
  • Weith, Loren
  • Kayottu, Sripathy

Abstract

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI) include providing security as a service via a cloud-based system for a plurality of tenants, wherein the cloud-based system includes a plurality of components communicatively coupled and adapted to communicate with one another based on mutual Transport Layer Security (mTLS) authentication; responsive to a new component requiring deployment within the cloud-based system, performing an enrollment process for the new component; and subsequent to the enrollment process, utilizing the new component within the cloud-based system for providing security as a service.

IPC Classes  ?

  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy
  • H04L 9/40 - Network security protocols

81.

Systems and methods for providing cloud integration recommendations based on real-time traffic monitoring

      
Application Number 18651876
Grant Number 12463887
Status In Force
Filing Date 2024-05-01
First Publication Date 2025-11-04
Grant Date 2025-11-04
Owner Zscaler, Inc. (USA)
Inventor
  • Parra, Eduardo Manuel
  • Raikar, Amit
  • Abbott, Paul Dana

Abstract

Systems and methods for providing cloud integration usage recommendations based on real-time traffic monitoring include monitoring traffic traversing a cloud-based system, the traffic originating from one or more endpoints associated with a customer of the cloud-based system; extracting metadata from the monitored traffic; determining one or more software usage recommendations based on the extracted metadata; and presenting the one or more software integration usage recommendations via a portal accessible by one or more users.

IPC Classes  ?

  • G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level

82.

Divide-and-conquer prompt for LLM-based text-to-SQL conversion

      
Application Number 18742119
Grant Number 12705233
Status In Force
Filing Date 2024-06-13
First Publication Date 2025-10-23
Grant Date 2026-08-11
Owner Zscaler, Inc. (USA)
Inventor
  • Mishra, Anjul
  • Purohit, Hriday
  • Xiong, Hanchen
  • Shang, Rex

Abstract

Systems and methods for processing search queries are provided. A method, according to one implementation, includes a step of receiving a query from a user interface, the query including one or more questions or commands pertaining to datasets stored in a relational database. The method also includes a step of generating a prompt having instructions related to how a Large Language Model (LLM) is to handle a complex query having one or more cascading dependencies. Also, the method includes a step of providing the prompt, datasets, and query to an LLM with instructions to convert the query into Structure Query Language (SQL) code.

IPC Classes  ?

83.

Analyzing cloud-based services for compliance with multiple regulations

      
Application Number 18638944
Grant Number 12598217
Status In Force
Filing Date 2024-04-18
First Publication Date 2025-10-23
Grant Date 2026-04-07
Owner Zscaler, Inc. (USA)
Inventor
  • Selvaraj, Kumaraswamy
  • Kuperman, Michael

Abstract

Systems and methods for analyzing compliance of an online service with pre-established regulations or standards are provided herein. In one example, a method includes a step of receiving a request to perform a compliance analysis on a cloud-based service to determine whether the cloud-based service complies with multiple compliance standards applicable to an environment in which the cloud-based service is intended to operate. The method further includes a step of collecting compliance controls associated with each of the multiple compliance standards. Also, the method includes a step of automatically organizing the compliance controls to reduce the number of assessment steps. The method further includes a step of enabling implementation of one or more assessment stages using the reduced number of assessment steps to determine whether the cloud-based service complies with the multiple compliance standards.

IPC Classes  ?

84.

Systems and methods for anomaly detection based on endpoint and network traffic profiles

      
Application Number 18742109
Grant Number 12689643
Status In Force
Filing Date 2024-06-13
First Publication Date 2025-10-23
Grant Date 2026-07-21
Owner Zscaler, Inc. (USA)
Inventor
  • Paul, Sandeep
  • Singh, Atinderpal
  • Cong, Zicun
  • Desai, Deepen

Abstract

Systems and methods for anomaly detection based on endpoint and network traffic profiles include performing inline monitoring of traffic within a network of a plurality of networks via a cloud; identifying anomalous traffic within the traffic based on a network profile, wherein the network profile defines baseline network traffic parameters for the network; determining if one or more other networks of the plurality of networks exhibit traffic similar to the anomalous traffic; and performing an action based on the determining.

IPC Classes  ?

85.

Inline Nested Data Loss Protection (DLP)

      
Application Number 19255260
Status Pending
Filing Date 2025-06-30
First Publication Date 2025-10-23
Owner Zscaler, Inc. (USA)
Inventor
  • Liu, Weizhen
  • Zhang, Miao
  • Yu, Zhen

Abstract

The disclosure presents systems and methods for hierarchical classification of input data across a plurality of categories. A machine learning model processes various data formats, starting with dimensional reduction using tokenization techniques, such as Bert-tiny tokenization, to create model-readable representations. The system predicts super-categories, sub-categories, and granular categories through selective activation of sub-layers tied to identified super-categories, optimizing computational efficiency. Label smoothing during training mitigates overconfidence in predictions, while softmax normalization refines inference outputs. Synthetic data generation using Large Language Models (LLMs) supplements training datasets, and an automated data labeling pipeline efficiently generates hierarchical labels. Modifications to the model, such as stop word removal and file size limitations, further reduce latency. Inference analyzes logits to predict hierarchical paths, providing detailed classifications with clear outputs. The method is adaptable for multimodal formats, ensuring scalable and accurate predictions across diverse data types while minimizing computational costs and improving reliability.

IPC Classes  ?

  • G06F 16/28 - Databases characterised by their database models, e.g. relational or object models
  • G06F 21/60 - Protecting data
  • G06F 40/30 - Semantic analysis

86.

Detecting Phishing Websites Using Perceptual Image Hashing

      
Application Number 19253035
Status Pending
Filing Date 2025-06-27
First Publication Date 2025-10-16
Owner Zscaler, Inc. (USA)
Inventor Danino, Shoham

Abstract

Systems and methods for detecting phishing using image hashing include obtaining a plurality of images from different sources, generating a hash for each image, comparing at least one hash associated with a first image to one or more hashes associated with a second image, calculating a similarity score based on the comparing, and classifying the first image based on the similarity score.

IPC Classes  ?

87.

Cellular Network Performance Monitoring and Optimization

      
Application Number 19238998
Status Pending
Filing Date 2025-06-16
First Publication Date 2025-10-09
Owner Zscaler, Inc. (USA)
Inventor
  • Howe, Nathan
  • Huybregts, Daan
  • Nadendla, Arvind
  • Urquhart, Ken

Abstract

The present invention provides systems and methods for cellular network performance monitoring and optimization, enabling SIM-based devices to dynamically adapt to changing network conditions for improved connectivity. The invention introduces a process that includes determining baseline path performance through detailed probing of network metrics, continuously assessing current path performance via real-time monitoring, and instructing the SIM to switch from its current connected mobile network carrier to an alternate carrier when predefined performance thresholds are not met. Switching instructions are securely delivered Over-The-Air (OTA) to the SIM, ensuring seamless transitions to the most efficient and reliable network path. The system leverages both active and passive application layer observations to optimize latency, throughput, and reliability while supporting diverse applications, including IoT devices, industrial systems, and consumer devices.

IPC Classes  ?

  • H04W 36/30 - Reselection being triggered by specific parameters by measured or perceived connection quality data
  • H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
  • H04W 24/08 - Testing using real traffic
  • H04W 36/12 - Reselecting a serving backbone network switching or routing node

88.

Systems and methods for generating and utilizing lookalike uniform resource locators (URLs)

      
Application Number 18624791
Grant Number 12596761
Status In Force
Filing Date 2024-04-02
First Publication Date 2025-10-02
Grant Date 2026-04-07
Owner Zscaler, Inc. (USA)
Inventor
  • Herszfang, Hila Paz
  • Rubin, Dani
  • Meyuhas, Eden
  • Inbar, Roi
  • Dabit, Samir

Abstract

Systems and methods for generating and utilizing lookalike Uniform Resource Locators (URLs) include receiving an original target domain, the original target domain being associated with an enterprise; generating a plurality of lookalike domains via a genetic algorithm based on the original target domain and a plurality of deception methods; and utilizing the plurality of lookalike domains for performing one or more functions, wherein the one or more functions include providing a report and performing inline URL access filtering.

IPC Classes  ?

  • G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
  • G06F 16/955 - Retrieval from the web using information identifiers, e.g. uniform resource locators [URL]

89.

Systems and methods for generating lookalike Uniform Resource Locators (URLs) based on penalty-based genetic algorithms

      
Application Number 18651949
Grant Number 12689655
Status In Force
Filing Date 2024-05-01
First Publication Date 2025-10-02
Grant Date 2026-07-21
Owner Zscaler, Inc. (USA)
Inventor
  • Herszfang, Hila Paz
  • Rubin, Dani
  • Meyuhas, Eden
  • Inbar, Roi
  • Dabit, Samir

Abstract

Systems and methods for generating and utilizing lookalike Uniform Resource Locators (URLs) include receiving an original target domain; generating a first generation of lookalike domains based on the original target domain and a plurality of deception methods; generating a penalty value for each of a plurality of lookalike domains in the first generation of lookalike domains; generating subsequent generations of lookalike domains and penalty values therefor based on penalty values associated with each of a plurality of lookalike domains in a preceding generation of lookalike domains; and repeating the steps for an N number of generations.

IPC Classes  ?

90.

Multi-Tenant Cloud to Cloud Incident Routing

      
Application Number 19238954
Status Pending
Filing Date 2025-06-16
First Publication Date 2025-10-02
Owner Zscaler, Inc. (USA)
Inventor
  • Bhallamudi, Arun
  • Patel, Chirag
  • Zhang, Frank
  • Tan, James

Abstract

Systems and methods for securely transferring Data Loss Prevention (DLP) incident data from a cloud-based DLP system to a tenant's cloud storage account in a multi-tenant environment include detecting a DLP incident by identifying a policy violation and generating an incident event and an associated request containing metadata and contextual information for the incident; processing the request, the processing comprising validating the tenant's configuration settings for storage access permissions and target storage details and determining routing information for the tenant's cloud storage account; and writing DLP incident data associated with the DLP incident into the tenant's public cloud storage account.

IPC Classes  ?

  • G06F 3/06 - Digital input from, or digital output to, record carriers

91.

Providing Access Continuity via Tenant-Specific Private Clouds

      
Application Number 19238970
Status Pending
Filing Date 2025-06-16
First Publication Date 2025-10-02
Owner Zscaler, Inc. (USA)
Inventor Pergament, Lidor

Abstract

Systems and methods for providing continued access via a tenant-specific private cloud include monitoring an operation state of a cloud-based system to detect disruptions based on predefined conditions; enabling a disaster recovery mode in response to detecting a disruption in the cloud-based system; and responsive to activation of the disaster recovery mode, redirecting traffic associated with a tenant from the cloud-based system to a tenant-specific private cloud, the tenant-specific private cloud being configured to enforce tenant-specific policies and maintain access to internet, Software-as-a-Service (SaaS) applications, and private applications.

IPC Classes  ?

  • H04L 41/0659 - Management of faults, events, alarms or notifications using network fault recovery by isolating or reconfiguring faulty entities
  • H04L 43/10 - Active monitoring, e.g. heartbeat, ping or trace-route
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network

92.

Systems and methods for determining similarity between Uniform Resource Locators (URLs) based on Graphical Similarity Pixel Comparison

      
Application Number 18901192
Status Pending
Filing Date 2024-09-30
First Publication Date 2025-10-02
Owner Zscaler, Inc. (USA)
Inventor
  • Rubin, Dani
  • Danino, Shoham Danino

Abstract

Systems and methods for generating and utilizing lookalike Uniform Resource Locators (URLs) based on a graphical comparison include receiving an original target domain and a lookalike domain, converting the original target domain and lookalike domain into pixelated images, calculating a similarity based on the images of the original target domain and the lookalike domain, and calculating a percentage difference of the images of the original target domain and the lookalike domain.

IPC Classes  ?

  • G06V 10/75 - Organisation of the matching processes, e.g. simultaneous or sequential comparisons of image or video featuresCoarse-fine approaches, e.g. multi-scale approachesImage or video pattern matchingProximity measures in feature spaces using context analysisSelection of dictionaries
  • G06T 3/40 - Scaling of whole images or parts thereof, e.g. expanding or contracting
  • G06V 20/62 - Text, e.g. of license plates, overlay texts or captions on TV images

93.

Determining Uniform Resource Locator (URL) Similarity Via Convolutional Neural Networks (CNN)

      
Application Number 19092159
Status Pending
Filing Date 2025-03-27
First Publication Date 2025-10-02
Owner Zscaler, Inc. (USA)
Inventor
  • Rubin, Dani
  • Danino, Shoham

Abstract

Systems and methods for determining Uniform Resource Locator (URL) similarity via Convolutional Neural Networks (CNN) include receiving an original target domain and a lookalike domain; converting the original target domain and the lookalike domain into pixelated images; calculating a similarity via a trained CNN based on the pixelated images of the original target domain and the lookalike domain; and providing a similarity score based on the similarity.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities

94.

Integrating Deception-Based Attack Intelligence with External Attack Surface Management (EASM) Data

      
Application Number 19239023
Status Pending
Filing Date 2025-06-16
First Publication Date 2025-10-02
Owner Zscaler, Inc. (USA)
Inventor
  • Assayag, Jonathan
  • Danino, Shoham
  • Desai, Deepen

Abstract

The invention provides systems and methods for integrating deception-based attack intelligence with External Attack Surface Management (EASM) vulnerability data to enhance cybersecurity threat detection and mitigation. The method collects deception data, including attack details and Common Vulnerabilities and Exposures (CVE) identifiers, or classifies attacks into Common Weakness Enumeration (CWE) categories using AI when no CVE is present. EASM tools scan external-facing assets to identify CVE-linked vulnerabilities, which are also mapped to CWE categories. A matching procedure correlates deception and EASM data by identifying CVE matches for known vulnerabilities or CWE matches for broader structural weaknesses. Alerts are generated to prioritize patching efforts and proactive defenses, ensuring actionable responses to imminent threats or systemic vulnerabilities. By automating classification, correlation, and alerting, the invention reduces manual effort, accelerates remediation, and offers a scalable solution for modern organizations to adapt to evolving cyber threats.

IPC Classes  ?

95.

Systems and methods for uniquely labeling egress traffic from secure service edge (SSE) platforms

      
Application Number 18613328
Grant Number 12676831
Status In Force
Filing Date 2024-03-22
First Publication Date 2025-09-25
Grant Date 2026-07-07
Owner Zscaler, Inc. (USA)
Inventor Sutherland, Edwin

Abstract

Systems and methods for uniquely labeling egress traffic from Secure Service Edge (SSE) platforms include intercepting traffic at cloud, wherein the traffic is associated with a tenant of one or more tenants of the cloud, and wherein the traffic is destined for an application; labeling the traffic with an egress Internet Protocol (IP) address and a unique hash value; and forwarding the traffic including the egress IP address and the unique hash value to the application. The unique hash value is unique to the tenant and identifiable by the application for determining the tenant of the one or more tenants based thereon.

IPC Classes  ?

96.

Cloud Activity Anomaly Detection

      
Application Number 19228406
Status Pending
Filing Date 2025-06-04
First Publication Date 2025-09-25
Owner Zscaler, Inc. (USA)
Inventor Herszfang, Hila Paz

Abstract

Anomaly detection in cloud-based systems involves predicting identity behavior using historical activity data. Historical activities and their timestamps are analyzed to determine future intervals when activity is expected. Predictions are generated using weighted historical data emphasizing recent activity, and an anomaly score quantifying risk is calculated for each future interval based on deviation from expected behavior. Inline monitoring may detect and alert administrators or trigger automated responses to unexpected identity behavior. The method includes confidence scoring based on historical validation, visualization via graphical user interfaces, and lightweight, scalable computations suitable for monitoring extensive cloud deployments, enhancing both precision and efficiency in detecting suspicious cloud activity.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • G06F 11/07 - Responding to the occurrence of a fault, e.g. fault tolerance
  • G06F 11/30 - Monitoring
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements

97.

Systems and methods for configuration management database (CMDB) based application segmentation

      
Application Number 18645656
Grant Number 12634200
Status In Force
Filing Date 2024-04-25
First Publication Date 2025-09-18
Grant Date 2026-05-19
Owner Zscaler, Inc. (USA)
Inventor
  • Hu, Chenhui
  • Omar, Shikhar
  • Shah, Raimi
  • Bitla, Vivek
  • Jaffrey, Shujaat Ali
  • Shang, Rex

Abstract

Systems and methods for Configuration Management Database (CMDB) based application segmentation include obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users; obtaining Configuration Management Database (CMDB) data of the enterprise, wherein the CMDB data includes information about hardware and software assets of the enterprise; matching application information within the transactional data and the CMDB data; and generating one or more application segments based on the matching.

IPC Classes  ?

  • H04L 41/0893 - Assignment of logical groups to network elements

98.

Systems and methods for generating location-based application segments

      
Application Number 18655726
Grant Number 12670283
Status In Force
Filing Date 2024-05-06
First Publication Date 2025-09-18
Grant Date 2026-06-30
Owner Zscaler, Inc. (USA)
Inventor
  • Hu, Chenhui
  • Nagpal, Kabir

Abstract

Systems and methods for generating location-based application segments include obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users; obtaining location data associated with the plurality of applications; and generating one or more application segments based on the transactional data and the location data. In various embodiments, the location data can be leveraged to alter various application segmentation factor thresholds for adapting the likelihood of applications to be grouped together.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

99.

Systems and methods for a cloud environment configuration Artificial Intelligence (AI) assistant using Large Language Models (LLMs)

      
Application Number 18745434
Status Pending
Filing Date 2024-06-17
First Publication Date 2025-09-18
Owner Zscaler, Inc. (USA)
Inventor
  • Hu, Chenhui
  • Garg, Gaurav
  • Shah, Raimi
  • Nagpal, Kabir
  • Yu, Zhen
  • Omar, Shikhar

Abstract

Systems and methods for a cloud environment configuration Artificial Intelligence (AI) assistant include receiving a query from a user associated with an enterprise in natural language, the query being associated with one or more configurations within a cloud environment of the enterprise; processing the query via one or more Large Language Models (LLMs); and providing a response to the query, wherein the response comprises data associated with the one or more configurations based on the query and a feedback mechanism for obtaining feedback from the user based on the response.

IPC Classes  ?

100.

Memory surge protection for application segmentation models

      
Application Number 18914829
Status Pending
Filing Date 2024-10-14
First Publication Date 2025-09-18
Owner Zscaler, Inc. (USA)
Inventor
  • Hu, Chenhui
  • Solanki, Devesh

Abstract

Systems and methods for memory surge protection for application segmentation models include obtaining log data for a plurality of users of an enterprise where the log data relates to usage of a plurality of applications by the plurality of users and user metadata; determining a memory usage estimation based on the log data; determining i) app-segments that are groupings of application of the plurality of applications and ii) user-groups that are groupings of users of the plurality of users, based on the log data and the memory usage estimation; and providing access policy of the plurality of applications based on the user-groups and the app-segments.

IPC Classes  ?

  • G06F 3/06 - Digital input from, or digital output to, record carriers
  1     2     3     ...     6        Next Page