Cloud Policy Manager for Unified CASB, SWG, and Firewall Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based security systems struggle to enforce unified policies across diverse cloud applications and protocols, including peer-to-peer file sharing, multimedia communication, and web traffic, while ensuring secure data management and threat detection, especially in dynamic and evolving environments.

Innovation Solution

A cloud-based policy enforcement system that unifies packet-based and protocol-based access control, threat detection, and activity contextualization, using a Netskope cloud access security broker (N-CASB) to manage and enforce policies across various cloud services, including peer-to-peer file sharing, multimedia communication, and web traffic, while preventing data loss and detecting internal and external threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cloud-based policy enforcement system unifies multiple security functions (packet-based access control, protocol-based access control, threat detection, activity contextualization), then security coverage and policy enforcement capability are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions (packet-based access control, protocol-based access control, threat detection, activity contextualization) into a single cloud-based policy enforcement system. This merging approach allows unified policy management and consistent security enforcement across diverse cloud applications and protocols, resolving the contradiction by achieving comprehensive security coverage through functional integration rather than separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The policy enforcement system is designed with multi-functionality to handle various cloud applications, protocols (FTP, SMTP, POP3, IMAP, HTTP, HTTPS), and security tasks (access control, threat detection, activity contextualization) through a single unified platform. This universal design enables the system to enforce policies across diverse environments without requiring separate specialized systems for each function or protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the system enforces policies across diverse cloud applications and protocols (FTP, SMTP, POP3, IMAP, HTTP, HTTPS), then policy versatility and security coverage are improved, but device complexity increases

Engineering Contradiction:
Improvepolicy versatilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements protocol-specific policy enforcement capabilities within a single device, allowing it to handle multiple cloud applications and protocols (FTP, SMTP, POP3, IMAP, HTTP, HTTPS) through unified policy templates. This multi-functional design provides policy versatility across diverse protocols without requiring separate enforcement devices for each protocol type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The policy enforcement system dynamically adapts to different protocols and cloud applications by loading and applying protocol-specific policy templates as needed. This dynamic capability allows the system to maintain versatility across diverse environments while managing complexity through on-demand protocol handling rather than permanent multi-protocol support in all operational modes.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the system performs comprehensive threat detection and activity contextualization, then security reliability is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs activity contextualization and threat detection by analyzing and contextualizing user activities before policy enforcement decisions are made. This preliminary action of contextualizing activities (understanding user intent, application context, data sensitivity) enables more accurate threat detection and policy enforcement, improving security reliability while managing processing time through proactive analysis rather than reactive response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250233891A1Computer-based policy manager for cloud-based unified functions
Publication Date: 2025.07.17 NETSKOPE INC
  • US20250233891A1 patent drawing
  • US20250233891A1 patent drawing
  • US20250233891A1 patent drawing

AI summary

A computer-implemented policy application device for a cloud-based security system that manages packet routing through cloud-based unified components of a cloud access security broker (CASB) component, a secure web gateway (SWG) component and firewall components, according to a unified security policy. The CASB processes packets exchanged between users and cloud-based resources. The SWG handles access to web accessible destinations. The firewall components provide traffic inspection and access control. The device includes a router component configured for routing each packet of streams of received packets to the components and configured for selectively forwarding the received packets to the CASB and SWG dependent on a type of stream to which the received packets belong, a restrictive state analyzer configured to be in communication with each of the components and configured for determining if and what action should be performed with respect to the each packet in compliance with the unified security policy.