Unmanaged SaaS Detection Through Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in identifying and managing unmanaged Software-as-a-Service (SaaS) applications due to lack of visibility and control, with existing methods being intrusive, inaccurate, or requiring high maintenance, leading to security risks.

Innovation Solution

A system utilizing machine learning and AI to identify SaaS applications through traffic data analysis, compute confidence scores, and generate prioritized lists to manage unmanaged applications, employing Endpoint Detection and Response systems and generative AI for enrichment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If traditional scanning methods are used to detect SaaS applications, then detection coverage is improved, but intrusiveness and accuracy deteriorate

Engineering Contradiction:
Improvedetection coverageVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary system that sits between network traffic and security analysis. This intermediary collects network traffic data, enriches it with contextual information, and feeds it to machine learning models for analysis. This mediator approach allows comprehensive detection without direct intrusion into user applications or systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical scanning methods with machine learning-based detection. Instead of using conventional scanning tools that directly probe applications, the system uses AI models trained on network traffic patterns to identify SaaS applications. This substitution maintains detection coverage while significantly improving accuracy by reducing false positives.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If procurement monitoring is used to track SaaS applications, then application visibility is improved, but maintenance requirements increase

Engineering Contradiction:
Improveapplication visibilityVSAvoidmaintenance requirements
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically collecting, enriching, and analyzing network traffic data to identify SaaS applications. The machine learning models continuously learn from new data patterns, enabling the system to maintain high visibility without requiring manual configuration or intensive maintenance. The system autonomously updates its detection capabilities as new SaaS applications emerge.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements continuous monitoring of network traffic to detect SaaS applications. The system operates continuously, collecting data from network endpoints, enriching it with contextual information, and analyzing it through machine learning models. This continuous action ensures persistent visibility into SaaS applications without requiring periodic manual intervention or maintenance cycles.

Inventive Principle:
Principle #20Continuity of useful action

3Difficulty of detecting and measuring

If browser extensions with agents are deployed, then detection capability is improved, but deployment complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoiddeployment complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of operation

Solution Approach 1:

The patent creates a universal detection system that functions across multiple network endpoints without requiring application-specific agents. The centralized machine learning platform processes network traffic from various sources (web browsers, mobile devices, cloud endpoints) using a unified approach. This multi-functional system maintains high detection capability while simplifying deployment, as it eliminates the need for separate agent installations on each endpoint.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If web proxies are used for inline monitoring, then control over SaaS applications is improved, but system complexity increases

Engineering Contradiction:
Improvecontrol capabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary analysis platform that processes network traffic data without requiring inline proxy deployment. The system collects traffic data from network endpoints, enriches it with contextual information, and analyzes it through machine learning models. This intermediary approach provides control capability over SaaS applications while avoiding the complexity of deploying and managing inline web proxies across the entire network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250280022A1Method for detecting unmanaged cloud applications
Publication Date: 2025.09.04 FORTINET INC
  • US20250280022A1 patent drawing
  • US20250280022A1 patent drawing
  • US20250280022A1 patent drawing

AI summary

In some implementations, a system and method for detecting and analyzing unmanaged SaaS applications are provided. The method includes identifying at least one SaaS application based on a comparison of a set of SaaS application identifiers and entries in a SaaS application database; verifying, through analysis of user interactions, when the identified at least one SaaS application is unmanaged; and computing, using a trained supervised machine learning model, confidence scores of each unmanaged SaaS application, wherein a confidence score is a measure of certainty of the verification that a SaaS application is unmanaged.