Netskope patent detects malicious C2 cloud traffic, blocks malware
Summary
The USPTO granted Patent US12592959B2 to Netskope, Inc. on March 31, 2026. The patent covers technology for detecting and blocking malicious command and control (C2) cloud traffic by using a network security system that reroutes cloud traffic, analyzes incoming requests, identifies malicious resources, and prevents transmission to those resources while maintaining availability of legitimate resources.
What changed
Patent US12592959B2 (20 claims) was granted to Netskope, Inc. covering a method, system, and non-transitory computer-readable media for detecting malicious communication between C2 cloud resources and malware on infected hosts. The network security system reroutes cloud traffic, analyzes incoming requests targeted at cloud applications, identifies malicious resources, and prevents transmission by making malicious resources unavailable while keeping other resources operational.
This is a patent grant notice with no compliance requirements. Technology companies developing cloud security solutions may review the patent claims for potential licensing considerations or to ensure their products do not infringe on the protected technology. The patent has no regulatory mandates or deadlines.
Source document (simplified)
Detecting malicious command and control cloud traffic
Grant US12592959B2 Kind: B2 Mar 31, 2026
Assignee
Netskope, Inc.
Inventors
Dagmawi Mulugeta, Raymond Joseph Canzanese, Jr., Colin Estep, Siying Yang, Jenko Hwong, Gustavo Palazolo Eiras, Yongxing Wang
Abstract
The technology disclosed relates to a method, system, and non-transitory computer-readable media that detects malicious communication between a command and control (C2) cloud resource on a cloud application and malware on an infected host, using a network security system. The network security system reroutes the cloud traffic to the network security system. The incoming requests of the cloud traffic are directed to a cloud application in the plurality of cloud applications, and wherein the cloud application has a plurality of resources. The network security system analyzes the incoming requests, determines that the incoming requests are targeted at one or more malicious resources in the plurality of resources. Also, the network security system prevents transmission of the incoming requests to the malicious resources, by making the malicious resources unavailable for receiving future incoming requests, while keeping other resources in the plurality of resources available for receiving the future incoming requests.
CPC Classifications
H04L 63/1441 H04L 63/029 H04L 63/0884 H04L 63/18 H04L 63/30 H04L 63/0272 H04L 63/1408 H04L 63/1416 H04L 63/1425 H04L 63/145 H04L 63/168
Filing Date
2023-06-23
Application No.
18340076
Claims
20
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Telecom & Technology alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when ChangeBridge: Patent Grants - Networking (H04L) publishes new changes.