Browser Activity Controls Based on Triggering Event Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased vulnerability of communications networks and digital resources due to the proliferation of personal devices (BYOD) and cloud-based services compounds the difficulty in providing cyber protection against cyberattacks, especially for enterprises with remote workers.

Innovation Solution

A cybersecure system, CyberSafe, is implemented, which includes a data and processing security hub and a secure web browser (SWB) in an isolated environment, monitoring and controlling data ingress and egress, enforcing security policies, and providing real-time risk assessment and anomaly detection to protect enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If personal devices (BYOD) and cloud-based services are proliferated to enable remote work, then accessibility and flexibility are improved, but vulnerability to cyberattacks and difficulty in providing cyber protection worsen

Engineering Contradiction:
Improveaccessibility and flexibilityVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the browsing environment by implementing a secure web browser that operates in an isolated sandbox environment, separating enterprise resource access from the general operating system and personal applications. This segmentation prevents malware from affecting either the OS or enterprise resources while allowing remote workers to use personal devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure web browser as an intermediary layer between the user device and enterprise resources. This intermediary enforces security policies, monitors communications, and controls data ingress/egress, thereby protecting enterprise resources while enabling remote access through personal devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure isolation environments are implemented to protect enterprise resources, then security protection is improved, but system complexity and resource management difficulty worsen

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure web browser implements self-service security mechanisms by automatically enforcing security policies, monitoring its own communications, and managing data ingress/egress control without requiring manual intervention. The browser autonomously protects enterprise resources while maintaining operational simplicity for users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal secure browsing environment that handles multiple security functions simultaneously: isolation from the OS, policy enforcement, communication monitoring, and data control. This multi-functional approach consolidates security mechanisms into a single browser component, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250284811A1Browser activity management with actions based on context of triggering events
Publication Date: 2025.09.11 PALO ALTO NETWORKS INC
  • US20250284811A1 patent drawing
  • US20250284811A1 patent drawing
  • US20250284811A1 patent drawing

AI summary

A method for providing secure access to digital resources, the method comprising: monitoring communications between a website and a user using a web browser comprised in a user equipment (UE) that is useable to access the digital resources; processing the monitored communications to determine: a set (WVF) of website vulnerability features comprising features which as a result of the user connecting to the website render a digital resource of the digital resources with which the user communicates vulnerable to cyber damage; and a set of user browsing behaviour features (BHF) comprising features that characterize the user browsing behaviour and internet use pattern which render the digital resource vulnerable to cyber damage; determining based on the website vulnerability factors and the user profile a security risk indicator (SRI) having a value that provides an estimate of a cyber damage risk to the digital resource resulting from the user connecting to the website and the digital resource; and based on the SRI value determining whether or not to permit the user to access the website.