Systems, methods, and media for file scanning of sources and clients in a zero trust environment

CN119382916BActive Publication Date: 2026-09-04HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410817797.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2023-07-26
Filing Date
2024-06-24
Publication Date
2026-09-04
Estimated Expiration
2044-06-24

AI Technical Summary

Technical Problem

此外,被设计为独立应用的SWG解决方案通常不容易被集成到组织的工作流、日志监控、报告等中

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382916B_ABST
    Figure CN119382916B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to systems and methods for file scanning between a source and a client in a zero trust environment. A system and method for providing file scanning between a client device and a resource over a zero trust network environment (ZTNE) is disclosed. The method includes detecting, in network traffic between the client device and the ZTNE, a request to receive first content from a resource deployed in a private network, wherein the resource is accessible to a user device making the first request over the ZTNE; detecting, in network traffic between the client device and the ZTNE, a second request to send second content from the client device to a public network, wherein the public network is accessible to the user device making the second request over the ZTNE; in response to determining that the second content is permissible, sending the request to the public network; and in response to determining that the second content is not permissible network traffic, blocking the request to the public network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to secure web gateways, and more specifically, to providing secure web gateways through a zero-trust network environment. Background Technology

[0002] Organizations are increasingly allowing users to physically work both inside and outside the organization. When outside, users connect to the organization's internal computer networks, private cloud networks, hybrid networks, etc., to access resources stored there. Typically, users will use their own devices in a Bring Your Own Device (BYOD) setup. All of this creates security vulnerabilities that can expose the organization. For example, a user could download content from the organization's secure network to a device exposed to a public network, potentially compromising sensitive information.

[0003] One preventative solution to limit such exposure is by deploying a secure web gateway (SWG). SWGs are configured to connect user devices to network resources and additionally perform content filtering, content inspection, and security controls on network applications. SWG solutions generate a dedicated network space and connect user devices, as well as web applications that the user devices attempt to access, to this dedicated network space. Therefore, to utilize an SWG solution, network resources must be pre-configured within the network space. Furthermore, SWG solutions, designed as standalone applications, are often not easily integrated into an organization's workflows, log monitoring, reporting, etc.

[0004] Therefore, it would be advantageous to provide a solution that would overcome the aforementioned challenges. Summary of the Invention

[0005] An overview of several exemplary embodiments of this disclosure is provided below. This overview is offered to facilitate the reader in providing a basic understanding of these embodiments and is not intended to limit the scope of this disclosure. This overview is not an extensive summary of all contemplated embodiments and is neither intended to identify key or essential elements of all embodiments nor to depict the scope of any or all aspects. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to the more detailed description that follows. For convenience, the terms "some embodiments" or "certain embodiments" may be used herein to refer to a single embodiment or multiple embodiments of this disclosure.

[0006] A system of one or more computers can be configured to perform specific operations or actions by installing software, firmware, hardware, or combinations thereof on the system, which, in operation, cause the system to perform these actions. One or more computer programs can be configured to perform specific operations or actions by including instructions that, when executed by a data processing device, cause the device to perform these actions.

[0007] In one general aspect, the method may include detecting, in network traffic between a client device and a zero-trust network environment, a first request to receive first content from a resource deployed in a private network, wherein the resource is accessible to the user device making the first request through the zero-trust network environment. The method may also include detecting, in network traffic between the client device and the zero-trust network environment, a second request to send second content from the client device to a public network, wherein the public network is accessible to the user device making the second request through the zero-trust network environment. The method may further include sending a request to the public network in response to determining, based on attributes of the first request and the second content, that the second content is an permitted network traffic. The method may further include blocking the request to the public network in response to determining, based on attributes of the first request and the second content, that the second content is not a permitted network traffic. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, all configured to perform the method actions.

[0008] Implementations may include one or more of the following features. In the method, content is any of the following: text file, document, spreadsheet, presentation, database, comma-separated value (CSV) file, multimedia file, video, and image. The method may include: inspecting first content by a deep packet inspection (DPI) unit; and generating a signature based on the first content. The method may include: inspecting second content by a DPI unit; generating a signature based on the second content; and comparing the signature based on the first content with the signature based on the second content. In the method, determining that the second content is permissible is in response to determining that the first content signature and the second content signature do not match. In the method, determining that the second content is not permissible is in response to determining that the first content signature and the second content signature match. The method may include: generating an activity log by storing each request as an event in an activity log, wherein the event includes a timestamp. The method may include: determining that the second content is not permissible in response to determining that an event representing a first request with a first timestamp occurred within a time period less than a predetermined threshold from an event representing a second request with a second timestamp. In this method, the zero-trust cloud environment includes any one of the following: an access portal server, a secure web gateway, a backend server, and any combination thereof. In this method, the backend server is configured to connect to a connector deployed in a secure network environment. Implementations of the described techniques may include hardware, methods or processes, or tangible computer media.

[0009] In one general aspect, a non-transitory computer-readable medium may include one or more instructions, which, when executed by one or more processors of the device, cause the device to: detect, in network traffic between a client device and a zero-trust network environment, a first request to receive first content from a resource deployed in a private network, wherein the resource is accessible through the zero-trust network environment by the user device making the first request. The medium may also detect, in network traffic between a client device and the zero-trust network environment, a second request to send second content from the client device to a public network, wherein the public network is accessible through the zero-trust network environment by the user device making the second request. The medium may also: in response to determining, based on attributes of the first request and the second content, that the second content is an permitted network traffic, send a request to the public network. The medium may also: in response to determining, based on attributes of the first request and the second content, that the second content is not a permitted network traffic, block the request to the public network. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, all configured to perform method actions.

[0010] In one general aspect, the system may include a processing circuitry system. The system may also include memory containing instructions that, when executed by the processing circuitry system, configure the system to: detect, in network traffic between a client device and a zero-trust network environment, a first request to receive first content from a resource deployed in a private network, wherein the resource is accessible through the zero-trust network environment to the user device making the first request. The system may also detect, in network traffic between a client device and the zero-trust network environment, a second request to send second content from the client device to a public network, wherein the public network is accessible through the zero-trust network environment to the user device making the second request. The system may also: in response to determining, based on attributes of the first request and the second content, that the second content is an permitted network traffic, send a request to the public network. The system may also: in response to determining, based on attributes of the first request and the second content, that the second content is not a permitted network traffic, block the request to the public network. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, all configured to perform the method actions.

[0011] The implementation may include one or more of the following features. In the system, the content is any of the following: text file, document, spreadsheet, presentation, database, comma-separated value (CSV) file, multimedia file, video, and image. In the system, the memory contains additional instructions that, when executed by the processing circuitry system, further configure the system to: inspect the first content by a deep grouping inspection (DPI) unit; and generate a signature based on the first content. In the system, the memory contains additional instructions that, when executed by the processing circuitry system, further configure the system to: inspect the second content by a DPI unit; generate a signature based on the second content; and compare the signature based on the first content with the signature based on the second content. In the system, determining that the second content is permissible is in response to determining that the first content signature and the second content signature do not match. In the system, determining that the second content is not permissible is in response to determining that the first content signature and the second content signature match. In the system, the memory contains additional instructions that, when executed by the processing circuitry system, further configure the system to: generate an activity log by storing each request as an event in an activity log, wherein the events include timestamps. In the system, the memory contains additional instructions that, when executed by the processing circuitry system, also configure the system to: determine that the second content is not permissible in response to determining that an event with a first timestamp representing a first request occurred within a time period less than a predetermined threshold from an event with a second timestamp representing a second request. In the system, the zero-trust cloud environment includes any one of the following: an access portal server, a secure web gateway, a backend server, and any combination thereof. The backend server is configured to connect to a system using a connector deployed in a secure network environment. Implementations of the described techniques may include hardware, methods or processes, or tangible computer media. Attached Figure Description

[0012] The subject matter disclosed herein is specifically pointed out and expressly claimed in the claims at the end of the specification. The foregoing and other objects, features, and advantages of the disclosed embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings.

[0013] Figure 1 This is an example of a network diagram used to describe a user equipment communicating with a zero-trust network in an embodiment.

[0014] Figure 2 This is an example schematic diagram of a client device according to an embodiment.

[0015] Figure 3 This is an example of a schematic diagram used to describe a zero-trust network for an embodiment.

[0016] Figure 4This is an example flowchart of a method for providing a secure web gateway to a client device through a zero-trust network environment, implemented according to an embodiment.

[0017] Figure 5 This is a flowchart of a method for directing network services to resources through a secure web gateway in a zero-trust network, implemented according to an embodiment.

[0018] Figure 6 This is a flowchart of a method for performing file scanning in a zero-trust network environment, implemented according to an embodiment.

[0019] Figure 7 This is an example schematic diagram of a secure web gateway according to an embodiment. Detailed Implementation

[0020] It is important to note that the embodiments disclosed herein are merely examples of many advantageous uses of the inventive teachings herein. Generally, the statements made in the specification of this application do not necessarily limit any of the various claimed embodiments. Furthermore, some statements may apply to some inventive features but not to others. Generally, unless otherwise indicated, a singular element may be plural, and vice versa, without loss of generality. In the drawings, the same numerals refer to the same parts in several views.

[0021] Various disclosed embodiments include methods and systems for providing a secure web gateway (SWG) in a zero-trust network environment. The system configures a user-operated client device to install an agent on the client device. When executed on the client device, the agent configures the client device to generate a virtual network interface (VNI). The agent also configures the client device to communicate with the zero-trust network environment through the VNI. When the client device requests a network resource (which can be of any type), the agent configures the VNI to expose the network resource to the client device as a resource accessible through the VNI's local network. The VNI exposes the client device to a virtual local area network (VLAN), where various external network resources can be represented as if they were local resources within the VLAN. Using this method, all communication from the user device is always delivered through the zero-trust network, allowing the user device to connect to secure networks and authorized public network access. Resources outside the VPN can also be exposed to the user device without requiring a virtual private network (VPN) connection between the user device and the web application.

[0022] Figure 1 This is an example of a network diagram used to describe a user equipment communicating with a zero-trust network in an embodiment. Below is... Figure 2User equipment 110, discussed in more detail below, is communicatively connected to a zero-trust network environment 120. User equipment 110 can be, for example, a personal computer, laptop, tablet, etc. In one embodiment, the zero-trust network (ZTN) environment 120 is implemented as a virtual private cloud (VPC) on a cloud computing environment. The cloud computing environment can be, for example, Amazon® Web Services (AWS), Microsoft® Azure, Google® Cloud Platform (GCP), etc. Figure 3 The ZTN environment 120 example is discussed in more detail below.

[0023] ZTN environment 120 provides connectivity to private network 130 and public network 140. In this example, the user of user equipment 110 and private network 130 belong to the same organization. In other embodiments, the user (i.e., the user account) is otherwise authorized to access private network 130. In one embodiment, private network 130 may be implemented as a VPC on a public cloud (such as AWS) accessible via public network 140. Public network 140 may be, for example, the Internet. Public network 140 is generally accessible to any user, while private network 130 is limited to authorized users (e.g., via zero-trust network environment 120) who provide authenticated credentials.

[0024] In some embodiments, the connector application can be deployed in a private network 130 to facilitate the integration of resources of the private network 130 with backend servers of the zero-trust network environment 120 (such as...). Figure 3 Communication between (as shown). The resources of the private network 130 can be, for example, RDP servers, SSH servers, file servers, object databases, transaction databases, SQL databases, NoSQL databases, web servers, data storage, web applications, etc.

[0025] Figure 2 This is an example schematic diagram of a client device 110 according to an embodiment. The client device 110 includes a processing circuitry system 210 coupled to a memory 220, a storage device 230, and a network interface 240. In one embodiment, the components of the client device may be communicatively connected via a bus 250.

[0026] The processing circuit system 210 can be implemented as one or more hardware logic components and circuits. For example, but not limited to, illustrative types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SOCs), graphics processing units (GPUs), tensor processing units (TPUs), general-purpose microprocessors, microcontrollers, digital signal processors (DSPs), and any other hardware logic component that can perform computation or other manipulations of information.

[0027] The memory 220 may be volatile (e.g., random access memory, etc.), non-volatile (e.g., read-only memory, flash memory, etc.) or a combination thereof.

[0028] In one configuration, software for implementing one or more embodiments disclosed herein may be stored in storage device 230. In another configuration, memory 220 is configured to store such software. Software should be interpreted broadly as representing any type of instruction, whether referred to as software, firmware, middleware, microcode, hardware description language, or others. Instructions may include code (e.g., source code format, binary code format, executable code format, or any other suitable code format). When executed by processing circuitry system 210, the instructions cause processing circuitry system 210 to perform the various processes described herein.

[0029] Storage device 230 may be a magnetic storage device, an optical storage device, etc., and may be implemented as, for example, flash memory or other memory technologies, compact disk-read-only memory (CD-ROM), digital versatile disk (DVD), or any other medium that can be used to store desired information.

[0030] Network interface 240 allows client device 110 to communicate with, for example, a zero-trust network (ZTN) 120. In one embodiment, client device 110 receives proxy software from ZTN 120. The proxy software includes instructions that, when executed by processing circuitry 210 of client device 110, configure client device 110 to implement a virtual network interface (VNI) 242. When executed, the instructions may also configure client device 110 to communicate exclusively via VNI 242. In one embodiment, VNI 242 includes a network namespace-based routing table. In some embodiments, the network namespace is an isolated network namespace. In some embodiments, the proxy software may specifically update the routing table to expose various resources.

[0031] For example, proxy software can update the routing table to indicate that a resource (e.g., a web server) has the IP address 10.0.0.115. In reality, the resource has a local private network (e.g., the one mentioned above). Figure 1 The VNI 242 allows a packet to pass through and be sent to the ZTN 120 for resolution when the client device 110 generates a packet pointing to that address. In one embodiment, the packet can be modified to include the IP address of the ZTN 120, the IP address of the resource (i.e., a different address), etc. For the client device 110, the resource is thus treated as a resource accessible on the local network, when in fact it is only accessible through the ZTN 120. Using this technique, any resource can be mapped through the VNI 242 to be exposed to the client device 110. This technique can be used to expose resources from public and / or private networks. This is advantageous because it provides the client device 110 with additional functionality and access.

[0032] It should be understood that the embodiments described herein are not limited to those described herein. Figure 2 The specific architecture shown is provided, and other architectures may be used equivalently without departing from the scope of the disclosed embodiments.

[0033] Figure 3This is an example of a schematic diagram used to describe a zero-trust network 120 of an embodiment. The zero-trust network (ZTN) 120 includes workloads such as a policy engine 310, a front-end server 320, a back-end server 330, a secure web gateway (SWG) 340, a deep packet inspection (DPI) unit 350, and an identity and access management (IAM) server 360. In one embodiment, the ZTN 120 may be implemented as a VPC on a cloud computing environment such as AWS. In one embodiment, each workload may be implemented on bare metal, as a virtual machine, as a container, as a serverless function, or as any combination thereof.

[0034] User equipment connected to ZTN 120 can be directed to front-end server 320. Front-end server 320 is configured to receive requests from user equipment (such as...) Figure 1 The user equipment 110 receives communications, sends communications to user equipment, and communicates with other components of the ZTN 120, such as the back-end server 330, SWG 340, policy engine 310, and IAM server 360.

[0035] In one embodiment, front-end server 320 is configured to generate a request for credentials for a user account. Credentials may include, for example, a username, password, password key, secret, one-time passcode (OTP), biometric information, etc. In one embodiment, the credentials are supplied to IAM server 360. IAM server 360 can authenticate the credentials. In one embodiment, IAM server 360 may issue a multi-factor authentication (MFA) challenge. The challenge may include a request to receive additional credentials (e.g., by sending a unique PIN, temporary PIN, etc., to a predetermined mobile phone number associated with the user account from which credentials are supplied from the user device).

[0036] In some embodiments, the front-end server 320 is configured to provide proxy software to the user equipment in response to successful authentication of the credentials provided by the user equipment. When executed by the processing unit of the user equipment, the proxy software can configure the user equipment to perform the methods described in more detail herein.

[0037] Backend server 330 is configured to connect to a private network (e.g., via a connector application deployed in a private network). The private network is a network outside the ZTN 120, not a public network. Backend server 330 can be configured to communicate with frontend server 320 to establish communication links between client devices and the frontend server, backend server, and resources in the private network.

[0038] A secure web gateway (SWG) 340 is configured to perform actions on network traffic received from a user device. Actions may include, for example, filtering uniform resource locators (URLs), content inspection, policy enforcement, malware detection, and providing application control for web-based applications (e.g., instant messaging applications). In one embodiment, SWG 340 may be configured to receive incoming network traffic, such as IP packets, from a front-end server 320. Incoming network traffic may be filtered (e.g., based on policies retrieved from a policy engine 310). The policy engine 310 is configured to store policies associated with user accounts, IP addresses, domain directories, etc. In some embodiments, SWG 340 is also configured to initiate inspections of network traffic (e.g., by providing IP packets to a DPI 350). The DPI 350 is configured to inspect network traffic content (e.g., by performing signature matching to detect network attacks, blocking certain protocols, etc.).

[0039] In some embodiments, SWG 340 can (e.g., based on a policy retrieved from policy engine 310) determine when to provide network traffic to DPI 350. This can be beneficial because performing DPI on every packet can lead to network congestion due to bottlenecks on DPI unit 350. SWG 340 can be configured to read only the packet headers and determine whether a packet should be provided to DPI 350 based on the header information and the policy retrieved from policy engine 310.

[0040] Figure 4 This is an example flowchart 400 of a method for providing a secure web gateway to a client device through a zero-trust network environment, implemented according to an embodiment.

[0041] In S410, the software agent is sent to the client device. The software agent includes instructions that, when executed by the processing unit of the client device, configure the client device to perform the steps detailed in the method.

[0042] In S412, a Virtual Network Interface (VNI) is generated. In one embodiment, the VNI includes a routing table based on a network namespace. In some embodiments, the network namespace is an isolated network namespace. Client devices can be assigned names within the namespace, which allows client devices to communicate with other resources that have names in the VNI namespace via the VNI.

[0043] In S414, resources are exposed via VNI. In some embodiments, the routing table can be updated to expose various resources. For example, the routing table can be updated to indicate that a resource (e.g., a web server) is accessible via IP address 10.0.0.115. In practice, the resource has a local private network (e.g., the one mentioned above). Figure 1 The VNI allows a packet to pass through and be sent to a Zero Trust Network (ZTN) for resolution when the client device generates a packet pointing to that address. In one embodiment, the packet can be modified to include the ZTN's IP address, the resource's IP address (i.e., a different address), etc.

[0044] For client devices, the resource is therefore treated as accessible on the local network because the VNI exposes it as if it were on the same local network as the client device, when in reality it is only accessible via the ZTN. This provides the security of a zero-trust network, which, in addition to providing a seamless user experience, enables the implementation of a secure web gateway (SWG). In one embodiment, the resource can be exposed from a private network, from a public network, and from a combination thereof. In some embodiments, a request to expose another resource (i.e., to assign a name to another resource in the VNI's namespace) can be received (e.g., from the client device).

[0045] In S416, a check is performed to determine whether another resource should be exposed to the client device. If so, execution can continue in S414; otherwise, execution can terminate.

[0046] Figure 5 This is a flowchart of a method for directing network services to resources through a secure web gateway in a zero-trust network, implemented according to an embodiment.

[0047] In S510, network traffic is received from the client device. Network traffic may include, for example, IP packets with source, destination, and payload. In one embodiment, the client device is configured to communicate using a Virtual Network Interface (VNI), where resources are exposed to the client device through the VNI. Resources may be deployed in private networks, public networks, and combinations thereof. Resources may be web applications, RDP servers, SSH servers, file servers, object databases, transactional databases, SQL databases, NoSQL databases, web servers, data stores, etc.

[0048] In S520, network traffic is inspected. In one embodiment, inspecting network traffic includes reading the headers of IP packets. For example, the source address, destination address, and packet size may be read. In some embodiments, the payload of the IP packets may be provided to a deep packet inspection (DPI) unit. The DPI unit is configured to read the content of the payload and inspect for, for example, network security threats, illegal content (e.g., pirated software), prohibited content (e.g., confidential information), etc.

[0049] In S530, a check is performed to determine whether the network service is permitted. In one embodiment, permitted services are network services allowed based on policies (e.g., retrieved from a policy engine). For example, the network service being checked may be matched against a policy to determine whether it is permitted. A routing table may be used to determine whether a network service is permitted. In some embodiments, network services may be blocked or partially blocked for predefined time frames (e.g., based on previous network services). For example, if a user equipment is downloading content from a private network and is requesting to upload the content to a public network within a time frame less than a predetermined amount of time (e.g., ten minutes), a policy may determine that such a request should be blocked. If the service is permitted, execution continues in S540. If the network service is not permitted, execution continues in S550.

[0050] In S540, network traffic is sent to the resource. In one embodiment, the address of the resource is determined by reading the header of the IP packet from the network traffic. In some embodiments, the network traffic can be modified to indicate to the resource that the response should be sent to the ZTN instead of the client device.

[0051] In S550, network service is blocked. In one embodiment, a notification can be generated and sent to the user equipment to indicate that a request associated with the network service has been blocked.

[0052] In S560, a check is performed to determine if any additional network traffic has been received. If so, execution continues in S510. If no additional network traffic has been received (e.g., because the connection to the zero-trust network environment was terminated), execution can terminate.

[0053] Figure 6 This is a flowchart of a method for performing file scanning in a zero-trust network environment, implemented according to an embodiment.

[0054] In S610, a request to receive content from the private network is detected. In one embodiment, the request is directed to a resource on the private network. The content can be, for example, a file, a filegroup, etc. Files can be text files, documents, spreadsheets, presentations, databases, comma-separated value (CSV) files, multimedia files, videos, images, etc. Resources can be resources accessible to the client device (e.g., using the method described above) through a VNI configured on the client device.

[0055] In one embodiment, content can be inspected (e.g., via a DPI unit). The DPI unit can generate a signature based on the content, and this signature can be stored in a storage device, such as in a zero-trust network environment.

[0056] In S620, a request to upload content to a public network is detected. In one embodiment, the request is directed to a resource on a public network that is accessible to the client device via a VNI. In some embodiments, a log is generated to record network activity. For example, each request for a resource (e.g., a URL request), upload requests, download requests, etc., can be stored as events in the network activity log. Each event can be stored along with a timestamp to indicate when the event occurred.

[0057] In S630, a check is performed to determine whether the request to upload content is permitted. In one embodiment, (e.g., by the DPI unit) a deep grouping check is performed on the uploaded content to determine whether the uploaded content matches content downloaded from the private network. For example, a signature can be generated from the uploaded content and matched with the stored signature of the content downloaded from the private network. In some embodiments, the check also includes determining when the last access to the private network occurred. If the private network access occurred within a time period less than a predetermined threshold, the request can be blocked (i.e., rejected). If the content upload is permitted, execution continues in S650. If the content upload is not permitted, execution continues in S640.

[0058] In S640, network service is blocked. In one embodiment, a notification can be generated and sent to the user equipment to indicate that the request has been blocked. In some embodiments, the notification may also include a policy, a portion of the policy, an identifier of the policy, etc., upon which the network service is blocked.

[0059] In S650, network services are permitted. Content is sent to the public network for uploading. In some embodiments, a notification can be generated to the administrator of the zero-trust network environment to inform them that a certain policy has been accessed, regardless of the outcome (i.e., whether the network service is blocked).

[0060] Figure 7 This is an example schematic diagram of a secure web gateway 340 according to an embodiment. The secure web gateway (SWG) 340 includes a processing circuitry system 710 coupled to a memory 720, a storage device 730, and a network interface 740. In one embodiment, the components of the SWG 340 may be communicatively connected via a bus 750.

[0061] The processing circuit system 710 can be implemented as one or more hardware logic components and circuits. For example, but not limited to, illustrative types of hardware logic components that can be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), graphics processing units (GPUs), tensor processing units (TPUs), general-purpose microprocessors, microcontrollers, digital signal processors (DSPs), etc., or any other hardware logic component that can perform computation or other manipulation of information.

[0062] The memory 720 may be volatile (e.g., random access memory, etc.), non-volatile (e.g., read-only memory, flash memory, etc.) or a combination thereof.

[0063] In one configuration, software for implementing one or more embodiments disclosed herein may be stored in storage device 730. In another configuration, memory 720 is configured to store such software. Software should be interpreted broadly as representing any type of instruction, whether referred to as software, firmware, middleware, microcode, hardware description language, or others. Instructions may include code (e.g., source code format, binary code format, executable code format, or any other suitable code format). When executed by processing circuitry system 710, the instructions cause processing circuitry system 710 to perform the various processes described herein.

[0064] Storage device 730 may be a magnetic storage device, an optical storage device, etc., and may be implemented as, for example, flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), or any other medium that can be used to store desired information.

[0065] Network interface 740 allows the secure web gateway 340 to communicate with, for example, client devices, front-end servers, back-end servers, DPI units, policy engines, etc.

[0066] It should be understood that the embodiments described herein are not limited to those described herein. Figure 7 The specific architecture shown is provided, and other architectures may be used equivalently without departing from the scope of the disclosed embodiments.

[0067] In addition, front-end servers, back-end servers, DPI units, policy engines, etc., can use similar... Figure 7 The architecture described herein shall be implemented without departing from the scope of the disclosed embodiments.

[0068] The various embodiments disclosed herein can be implemented as hardware, firmware, software, or any combination thereof. Furthermore, the software is preferably implemented as an application tangibly embodied in a program storage unit or computer-readable medium (consisting of components or certain devices and / or combinations of devices). The application can be uploaded to and executed by a machine including any suitable architecture. Preferably, the machine is implemented on a computer platform having hardware such as one or more central processing units (“CPU”), memory, and input / output interfaces. The computer platform may also include an operating system and microinstruction code. The various processes and functions described herein may be part of the microinstruction code, or part of the application, or any combination thereof, which can be executed by the CPU, regardless of whether such a computer or processor is explicitly shown. Furthermore, various other peripheral units may be connected to the computer platform, such as additional data storage units and printing units. Additionally, a non-transitory computer-readable medium is any computer-readable medium other than transient propagation signals.

[0069] All examples and conditional language described herein are for illustrative purposes, intended to help the reader understand the principles of the disclosed embodiments and the concepts contributed by the inventors to the field, and should be construed as not being limited to these specifically described examples and conditions. Furthermore, all statements regarding the principles, aspects, and embodiments of the disclosed embodiments described herein, as well as their specific examples, are intended to cover their structural and functional equivalents. Additionally, it is intended that such equivalents include both currently known equivalents and those developed in the future; that is, any developed element that performs the same function, regardless of its structure.

[0070] It should be understood that any reference to elements in this document using labels such as "first," "second," etc., generally does not restrict the number or order of these elements. Rather, these labels are generally used herein as a convenient way to distinguish two or more elements or instances of elements. Therefore, a reference to the first element and the second element does not imply that only two elements can be used there, or that the first element must somehow precede the second element. Furthermore, unless otherwise stated, a group of elements includes one or more elements.

[0071] As used herein, a list of items following the phrase “at least one of…” means that any of the listed items can be used individually, or any combination of two or more of the listed items can be used. For example, if the system is described as including “at least one of A, B, and C”, then the system can include: A only; B only; C only; 2A; 2B; 2C; 3A; combinations of A and B; combinations of B and C; combinations of A and C; combinations of A, B, and C; combinations of 2A and C; combinations of A, 3B, and 2C; and so on.

Claims

1. A method for providing file scanning between a client device and a resource in a zero-trust network environment, comprising: In network services between a client device and a zero-trust network environment, a first request is detected for receiving first content from a resource deployed in a private network, wherein the resource is accessible to the user device making the first request through the zero-trust network environment. In network services between the client device and the zero-trust network environment, a second request for sending second content from the client device to a public network is detected, wherein the public network is accessible to the user device making the second request through the zero-trust network environment; Based on the attributes of the first request and the second content: In response to determining that the second content is an permitted network service, the second request is sent to the public network; or In response to determining that the second content is not a permitted network service, the second request to send the second content to the public network is blocked.

2. The method of claim 1, wherein the content is any of the following: text file, document, spreadsheet, presentation, database, comma-separated value CSV file, multimedia file, video, and image.

3. The method according to claim 1, further comprising: The first content is inspected by the depth grouping inspection DPI unit; as well as A signature is generated based on the first content.

4. The method according to claim 3, further comprising: The second content is checked by the DPI unit; Generate a signature based on the second content; as well as The signature based on the first content is compared with the signature based on the second content.

5. The method of claim 4, wherein determining that the second content is permissible is in response to determining that the first content signature does not match the second content signature.

6. The method of claim 4, wherein determining that the second content is not permissible is in response to determining that the first content signature matches the second content signature.

7. The method according to claim 1, further comprising: The activity log is generated by storing each request as an event in the activity log, where each event includes a timestamp.

8. The method according to claim 7, further comprising: In response to determining that the event with a first timestamp representing the first request occurred within a time period less than a predetermined threshold from the event with a second timestamp representing the second request, it is determined that the second content is not permissible.

9. The method of claim 1, wherein the zero-trust network environment comprises any one of the following: an access portal server, a secure web gateway, a backend server, and any combination thereof.

10. The method of claim 9, wherein the backend server is configured to connect to a connector deployed in the private network.

11. A non-transitory computer-readable medium comprising instructions for providing file scanning between a client device and a resource over a zero-trust network environment, the instructions being executable by one or more processors of the device to: In network services between a client device and a zero-trust network environment, a first request is detected for receiving first content from a resource deployed in a private network, wherein the resource is accessible to the user device making the first request through the zero-trust network environment. In network services between the client device and the zero-trust network environment, a second request for sending second content from the client device to a public network is detected, wherein the public network is accessible to the user device making the second request through the zero-trust network environment; In response to determining that the second content is an permitted network service based on the attributes of the first request and the second content, the second request is sent to the public network; as well as In response to determining, based on the attributes of the first request and the second content, that the second content is not an permitted network service, the second request for sending the second content to the public network is blocked.

12. A system for providing file scanning between a client device and a resource over a zero-trust network environment, comprising: Processing circuit system; as well as A non-transitory computer-readable medium, the non-transitory computer-readable medium comprising instructions executable by the processing circuitry system, for: In network services between a client device and a zero-trust network environment, a first request is detected for receiving first content from a resource deployed in a private network, wherein the resource is accessible to the user device making the first request through the zero-trust network environment. In network services between the client device and the zero-trust network environment, a second request for sending second content from the client device to a public network is detected, wherein the public network is accessible to the user device making the second request through the zero-trust network environment; In response to determining that the second content is an permitted network service based on the attributes of the first request and the second content, the second request is sent to the public network; as well as In response to determining, based on the attributes of the first request and the second content, that the second content is not an permitted network service, the second request for sending the second content to the public network is blocked.

13. The system of claim 12, wherein the content is any of the following: text files, documents, spreadsheets, presentations, databases, comma-separated value CSV files, multimedia files, videos, and images.

14. The system of claim 12, wherein the memory includes additional instructions that, when executed by the processing circuitry system, further configure the system to: The first content is inspected by the depth grouping inspection DPI unit; and A signature is generated based on the first content.

15. The system of claim 14, wherein the memory includes additional instructions that, when executed by the processing circuitry system, further configure the system to: The second content is checked by the DPI unit; A signature is generated based on the second content; and The signature based on the first content is compared with the signature based on the second content.

16. The system of claim 15, wherein determining that the second content is permissible is in response to determining that the first content signature does not match the second content signature.

17. The system of claim 15, wherein determining that the second content is not permissible is in response to determining that the first content signature matches the second content signature.

18. The system of claim 12, wherein the memory includes additional instructions that, when executed by the processing circuitry system, further configure the system to: The activity log is generated by storing each request as an event in the activity log, where each event includes a timestamp.

19. The system of claim 18, wherein the memory includes additional instructions that, when executed by the processing circuitry system, further configure the system to: In response to determining that the event with a first timestamp representing the first request occurred within a time period less than a predetermined threshold from the event with a second timestamp representing the second request, it is determined that the second content is not permissible.

20. The system of claim 12, wherein the zero-trust network environment comprises any one of the following: an access portal server, a secure web gateway, a backend server, and any combination thereof.

21. The system of claim 20, wherein the backend server is configured to connect to a connector deployed in the private network.

Citation Information

Patent Citations

  • Cloud standby scheduling automatic master station system and realization method

    CN107948100A

  • Hidden channel security defense system for cloud platform data

    CN114301693A