CASB User Interface Analytics for Data Exposure and Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Cloud Access Security Broker (CASB) systems face challenges in providing comprehensive visibility and control over enterprise data in cloud environments, leading to inefficiencies in scanning and user experience, with a lack of concrete insights into potential security threats and user behavior issues.

Innovation Solution

A Cloud Access Security Broker (CASB) User Interface (UI) system that provides consolidated organization-level insights into sensitive data exposure, analyzing unique data objects, users, and external entities, offering visualizations and drill-down mechanisms for investigating compliance and user behavior issues, with features like summary tiles, incident reporting, and remediation tools.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional CASB systems scan through a large number of files in cloud applications, then security monitoring coverage is improved, but system latency increases and user experience deteriorates

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidsystem latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the monolithic CASB scanning system into multiple distributed worker nodes that process files in parallel. Each worker handles a portion of the scanning workload independently, allowing the system to maintain comprehensive security coverage while reducing latency through concurrent processing across multiple nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional approach by implementing hierarchical scanning levels (full scan, partial scan, and on-demand scan) and organizing files into risk-based categories. This multi-dimensional scanning strategy allows the system to adjust monitoring intensity based on file sensitivity and user behavior patterns, reducing unnecessary latency while maintaining security coverage.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If CASB systems provide comprehensive visibility into cloud usage, then security control is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces intermediary components including policy engines that translate security requirements into actionable rules, and analytics layers that aggregate raw scanning data into meaningful insights. These intermediaries simplify the system architecture by decoupling data collection from analysis and response generation, making the overall system more manageable despite comprehensive monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service features where the CASB system automatically learns from user behavior patterns and adjusts scanning policies without manual intervention. The system autonomously identifies high-risk files and users, dynamically adjusting monitoring intensity, which reduces operational complexity while maintaining comprehensive security visibility.

Inventive Principle:
Principle #25Self-service

3Reliability

If incident-based reports are generated, then security incident detection is improved, but concrete view of top threatening objects is lost

Engineering Contradiction:
Improveincident detectionVSAvoidvisibility of top threatening objects
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements feedback loops where incident data from scanning operations is continuously analyzed and fed back into the risk assessment model. This feedback mechanism identifies patterns and correlations across incidents, enabling the system to surface the top threatening objects and entities by aggregating incident frequency, severity, and contextual information from multiple sources.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces traditional mechanical incident reporting with an intelligent analytics system that uses machine learning algorithms to process and interpret incident data. This substitution transforms raw incident logs into actionable intelligence, automatically identifying and prioritizing the most threatening objects, users, and external entities based on aggregated incident patterns.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12395531B2Cloud access security broker user interface and analytics systems and methods
Publication Date: 2025.08.19 ZSCALER INC
  • US12395531B2 patent drawing
  • US12395531B2 patent drawing
  • US12395531B2 patent drawing

AI summary

Systems and methods include, providing a UI for a tenant to input one or more malware and DLP rules, and trusted user exceptions; responsive to a scan by the CASB system of a plurality of users associated with a tenant in a SaaS application where the scan includes identifying malware in content in the SaaS application and performing DLP in the content in the SaaS application based on the one or more malware and DLP rules and trusted user exceptions, maintaining records associated with a plurality of incidents for the malware and the DLP; and providing the UI for the tenant including an analytics view with a plurality of summary tiles including visualizations of the plurality of incidents for the malware and DLP for the tenant and a table listing any of the plurality of incidents for the malware and the DLP for the tenant.