Cloud-Based Intrusion Prevention System for Mobile Threat Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Intrusion Prevention Systems (IPS) and firewalls are physical devices that struggle to provide threat protection in mobile, cloud-based environments where traditional network perimeters are disappearing.

Innovation Solution

A cloud-based Intrusion Prevention System (IPS) and multi-tenant cloud-based firewall that follow users across various connections, locations, devices, and operating systems, providing always-on threat protection and visibility through a suite of technologies including firewall, sandbox, Cloud Access Security Broker (CASB), and Data Leakage Prevention (DLP).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional physical IPS appliances are deployed in data centers, then they can protect servers sitting in the data center, but they cannot protect users and applications that have left the enterprise network due to mobility and cloud migration

Engineering Contradiction:
Improvethreat protection coverageVSAvoidenvironment adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions the IPS system from a physical, location-bound appliance in the data center to a virtualized cloud-based service that can be accessed from any location and device. This dimensional shift from physical space to network space enables the system to follow users across mobile devices, cloud environments, and remote locations, thereby expanding threat protection coverage beyond the traditional network perimeter.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces a cloud-based intermediary layer that sits between users and threats, providing IPS functionality without requiring physical appliances at user locations. This cloud-based IPS service acts as a mediator that can inspect and block threats regardless of where users are connecting from, solving the problem of protecting mobile and cloud-based applications without physical perimeter devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional IPS systems are deployed as physical appliances, then they provide dedicated security functionality, but they require hardware management and do not scale automatically to meet inspection demands

Engineering Contradiction:
Improvesecurity functionalityVSAvoidhardware management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a cloud-based IPS service that automatically scales its inspection capacity based on demand without requiring manual hardware provisioning or management. The system self-adjusts resources to handle varying traffic loads, automatically updates threat signatures and inspection rules, and manages its own infrastructure, thereby eliminating the need for customers to manage physical hardware while maintaining dedicated security functionality.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If conventional IPS systems inspect all traffic including SSL, then they can detect threats hiding in encrypted traffic, but they face SSL inspection limitations and performance challenges

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidinspection throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent combines multiple security functions including SSL inspection, threat intelligence, and cloud-based analysis into a unified cloud-based IPS platform. By merging these functions in the cloud rather than requiring them to run locally on physical appliances, the system achieves both high SSL inspection accuracy for detecting encrypted threats and maintained throughput performance through distributed cloud processing capacity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250158962A1Cloud-based Intrusion Prevention System, Multi-Tenant Firewall, and Stream Scanner
Publication Date: 2025.05.15 ZSCALER INC
  • US20250158962A1 patent drawing
  • US20250158962A1 patent drawing
  • US20250158962A1 patent drawing

AI summary

A method of providing cloud-based security services includes receiving, at one or more distributed processing nodes in a cloud-based system, network traffic from a plurality of endpoints associated with at least one tenant; applying, by each distributed processing node, at least one cloud-based security inspection function configured to detect threats or enforce policy controls in the received network traffic; determining, via a policy engine whether to block, allow, or further analyze the network traffic based on per-tenant security policies; logging, in a cloud-based logging repository, inspection results, policy decisions, and rule matches for subsequent reporting and analytics; and updating the security inspection function at the distributed processing nodes, in real time, with newly discovered threat signatures and policy changes to provide continuous protection across the cloud-based system.