Patents Assigned to Fortinet, Inc.
  • Patent number: 11477214
    Abstract: Systems and methods for performing multi-feed classification of security events to facilitate automated IR orchestration are provided. According to one embodiment a cloud-based security service protecting a private network provides a plurality of data feeds, wherein each data feed of the plurality of data feeds independently classify a given security event and produce a classification result. In response to an event associated with a process of an endpoint device that is part of the private network an endpoint protection platform running on the endpoint device performs an initial classification of the event and transmits the classification result to the cloud-based security service for final classification to facilitate causing, by the cloud-based security service, the endpoint protection platform to perform an automated incident response, by providing an output of an automated response engine of the cloud-based security service to the endpoint protection platform.
    Type: Grant
    Filed: December 10, 2019
    Date of Patent: October 18, 2022
    Assignee: Fortinet, Inc.
    Inventors: Udi Yavo, Roy Katmor, Ido Kelson
  • Patent number: 11475790
    Abstract: Systems and methods are described for providing training to attendees of a network security training session through use of gamification. A virtual environment is created containing a network topology simulating a deployed network of network security devices for which teams of the attendees are to receive training. A 3D game interface is presented on a display of a computer system of an attendee. Based on a leaderboard server's game state, a problem-solving objective for the training session is presented on the display. The virtual environment facilitates interactions by the attendee with the network security devices via real web interfaces of corresponding full-feature virtual network security appliances in connection with attempts by the attendee to complete the objectives. Upon completion of an objective, the leaderboard server's game state is updated. Based on the game state of a group of objectives a second group of problem-solving objectives is presented to the attendee.
    Type: Grant
    Filed: June 28, 2019
    Date of Patent: October 18, 2022
    Assignee: Fortinet, Inc.
    Inventors: Robert A. May, Jordan E. Thompson, Jamie Pate
  • Patent number: 11477240
    Abstract: Systems and methods for remote monitoring of a Security Operations Center (SOC) via a mobile application are provided. According to one embodiment, a management service retrieves information regarding multiple network elements that are associated with an enterprise network and extracts parameters of the monitored network elements from the retrieved information. The management service prioritizes the monitored network elements by determining a severity level associated with security-related issues of the network elements and generates various monitoring views that summarize in real time various categories of potential security-related issues detected by the SOC. Further, the management service assigns a priority to each monitoring view and displays a video on the display device that cycles through monitoring views in accordance with their respective assigned priorities.
    Type: Grant
    Filed: June 26, 2019
    Date of Patent: October 18, 2022
    Assignee: Fortinet, Inc.
    Inventors: Robert A. May, Jordan E. Thompson
  • Patent number: 11470083
    Abstract: Systems and methods for facilitating self-service device integration for a NAC server is provided. According to one embodiment, a database is maintained by a NAC server. The database includes mappings of system object identifiers to corresponding implementation details of associated devices. A system object identifier of a device that is to be modeled within the NAC server based on implementation details of another device is received. A list of candidate devices is retrieved from the database based on the system object identifier. A user of the NAC server is prompted to select a candidate device from the list. Responsive to receipt of the selected candidate device, implementation details of the selected candidate device are mapped against the system object identifier and access to the network device is facilitated based on the implementation details of the selected candidate device by storing the mapping as an entry in the device database.
    Type: Grant
    Filed: June 16, 2020
    Date of Patent: October 11, 2022
    Assignee: Fortinet, Inc.
    Inventors: Jeffrey S. Hilfiker, Eric P. Dupont
  • Patent number: 11464046
    Abstract: Responsive to the number of stations exceeding a first threshold number, the transmitting stations are prioritized relative to the station based on a station type. Responsive to the number of stations exceeding a second threshold number, the transmitting stations are prioritized relative to the station based on a station RSSI value. The station is assigned to the run queue with an ATF token responsive to being prioritized within the first or second thresholds permitting transmission of the data packet for the station. The station is assigned to a wait queue responsive to being prioritized outside of the first or second threshold not permitting transmission of the data packet for the station.
    Type: Grant
    Filed: March 30, 2021
    Date of Patent: October 4, 2022
    Assignee: Fortinet, Inc.
    Inventors: Sekhar Sumanth Gorajala Chandra, Yongcheng Lei
  • Patent number: 11463425
    Abstract: Traffic broadcast to a VLAN is restricted. To do so, a plurality of stations are associated with a BSSID (basic service set identifier). A first VLAN is configured by sending a first group key to each station from the plurality of stations that is a member of the first VLAN, wherein each VLAN is associated with a unique group key. One or more frames addressed to the first VLAN are received. The one or more frames are encrypted with the first group key to prevent stations without the first group key from being able to decrypt the one or more frames. The one or more encrypted VLAN frames are broadcast to the plurality of stations associated with the BSSID.
    Type: Grant
    Filed: October 13, 2017
    Date of Patent: October 4, 2022
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Sung-Wook Han
  • Patent number: 11456231
    Abstract: Various heatsink arrangements, and methods for implementing and using such are discussed.
    Type: Grant
    Filed: January 18, 2021
    Date of Patent: September 27, 2022
    Assignee: Fortinet, Inc.
    Inventors: Shen Sunny Zhong, Qian Yu, Han Hsu
  • Patent number: 11449623
    Abstract: Systems and methods for a machine-learning driven fine-grained file access control approach are provided. According to one embodiment, a server associated with an enterprise network can obtain and store information regarding historical user behavior of users of the enterprise network by observing file access requests initiated by the users. The server receives a file access request initiated by a user, which relates to a file stored within the enterprise network in encrypted form. In response to receipt of the file access request, the server determines a risk score for the user based on multiple factors, including information regarding historical user behavior, the file access request and observed data determined based on the file access request so that based on the risk score, access to the file is permitted by returning a decryption key for the file or denied by withholding the decryption key.
    Type: Grant
    Filed: March 22, 2019
    Date of Patent: September 20, 2022
    Assignee: Fortinet, Inc.
    Inventors: Matthew J. Little, Jamie R. Graves, Carson Leonard
  • Patent number: 11451959
    Abstract: Systems and methods for authenticating client devices accessing a wireless communication network through an access point communicatively coupled with an authentication server are provided. The authentication server receives an authentication request, including a first message integrity code (MIC) of a client-specific pre-shared key, from the access point or a wireless local area network (LAN) controller that manages the access point, to establish an encrypted communication channel between a client and the access point. In response to receipt of the authentication request, the authentication server validates the first MIC by receiving various attributes from the access point or the wireless LAN controller and determining a second MIC based on the client-specific pre-shared key of the client known to the authentication server and the received attributes so that the client-specific pre-shared key is validated to be authentic when the first MIC matches with the second MIC.
    Type: Grant
    Filed: September 30, 2019
    Date of Patent: September 20, 2022
    Assignee: Fortinet, Inc.
    Inventors: Carl M. Windsor, Ruben S. Wilson, Yannick Dubuc
  • Patent number: 11444826
    Abstract: Various approaches for providing network maintenance and health monitoring. In some cases, some approaches include systems, methods, and/or devices for receiving and cataloging network incidents and in providing proposed solutions that may include embedded automated remediations and/or embedded dynamic instructions to mitigate the network incidents.
    Type: Grant
    Filed: April 23, 2021
    Date of Patent: September 13, 2022
    Assignee: Fortinet, Inc.
    Inventors: Jason Abate, Shabbir Karimi
  • Patent number: 11444957
    Abstract: Systems and methods for detection and classification of malware using an AI-based approach are provided. In one embodiment, a T-node maintains a sample library including benign and virus samples. A classification model is generated by training a classifier based on features extracted from the samples. The classification model is distributed to D-nodes for use as a local virus detection model. Responsive to detection of a virus by a D-node, the T-node receives a virus sample from the D-node. When the virus sample is not in the sample library, it is incorporated into the sample library. A feature depository is created/updated by the T-node by extracting features from the samples. Responsive to a retraining event: (i) an improved classification model is created by retraining the classifier based on the feature depository; and (ii) the D-nodes are upgraded by replacing their local virus detection models with the improved classification model.
    Type: Grant
    Filed: July 31, 2018
    Date of Patent: September 13, 2022
    Assignee: Fortinet, Inc.
    Inventor: Lei Zhang
  • Publication number: 20220286483
    Abstract: Systems, methods, and apparatuses enable a machine learning model to determine a risk probability of a URL. A query configurator receives a URL in a query and normalizes the URL. The normalized URL is segmented into a plurality of segments. The plurality of segments is serially provided to the machine learning model trained to provide an indication of risk associated with the URL. The indication of risk associated with the URL can be a probability value based on one or more risk probabilities determined for segment-segment transitions of the URL. A security service compares the probability value of the URL to a threshold value and performs a security action based on a result of comparing the probability value to the threshold value.
    Type: Application
    Filed: May 20, 2022
    Publication date: September 8, 2022
    Applicant: Fortinet, Inc.
    Inventors: Rajiv Sreedhar, Ratinder Paul Singh Ahuja, Manuel Nedbal, Toshal Phene, Jitendra Gaitonde
  • Publication number: 20220286436
    Abstract: Various approaches for providing intermediary threat detection. In some cases, the intermediary threat detection is performed by a communication control port that operatively couples with a portable computing device to protect the portable computing device from network based vulnerabilities and exploits.
    Type: Application
    Filed: March 2, 2021
    Publication date: September 8, 2022
    Applicant: Fortinet, Inc.
    Inventor: Kushal Arvind Shah
  • Publication number: 20220272086
    Abstract: Various approaches for securing networks against access from off network devices. In some cases, embodiments discussed relate to systems and methods for identifying potential threats included in a remote network by a network access device prior to requesting access to a known secure network via the remote network.
    Type: Application
    Filed: February 25, 2021
    Publication date: August 25, 2022
    Applicant: Fortinet, Inc.
    Inventor: Emilio Borbolla Galindo
  • Publication number: 20220269737
    Abstract: Various approaches for identifying possible unsecured devices on a network as set forth. In some cases, approaches discussed relate to systems and methods for identifying possible unsecured devices based upon a host name for each of the discovered devices.
    Type: Application
    Filed: February 25, 2021
    Publication date: August 25, 2022
    Applicant: Fortinet, Inc.
    Inventor: Haitao Li
  • Publication number: 20220272116
    Abstract: Various embodiments are discussed that provide systems and methods for identifying possible unsecured devices on a network. In some cases, embodiments discussed relate to systems and methods for identifying possible unsecured devices; clustering the identified devices with other similar devices, and/or determining default or simplified access processes for a given cluster of the identified devices.
    Type: Application
    Filed: February 25, 2021
    Publication date: August 25, 2022
    Applicant: Fortinet, Inc.
    Inventor: Haitao Li
  • Patent number: 11425158
    Abstract: Systems and methods for a security rating framework that translates compliance requirements to corresponding desired technical configurations to facilitate generation of security ratings for network elements is provided. According to one embodiment, a host network element executes a collection of security checks on at least a first network element. The execution is performed by receiving configuration data of the first network element pertaining to each security check of the collection of security checks in response to a request by the host network element and validating each security check by comparing the received configuration data pertaining to each security check with a pre-defined or configurable network security configuration recommendation to generate a compliance result. Further, the host network element generates a compliance report by aggregating the compliance results obtained by executing each security check of the collection of security checks.
    Type: Grant
    Filed: March 19, 2019
    Date of Patent: August 23, 2022
    Assignee: Fortinet, Inc.
    Inventors: Robert A. May, Tarlok Birdi
  • Publication number: 20220263862
    Abstract: Systems and methods for providing an integrated or Smart NIC-based hardware accelerator for a network security device to facilitate identification and mitigation of DoS attacks is provided. According to one embodiment, a processor of a network security device receives an application layer protocol request from a client, directed to a domain hosted by various servers and protected by the network security device. The application layer protocol request is parsed to extract a domain name and a path string. The hardware acceleration sub-system updates rate-based counters based on the application layer protocol request by performing a longest prefix match on the domain name and the path string. When a rate threshold associated with the rate-based counters is exceeded, a challenge message is created and transmitted to the client, having embedded therein the application layer protocol request; otherwise the application layer protocol request is allowed to pass through the network security device.
    Type: Application
    Filed: May 2, 2022
    Publication date: August 18, 2022
    Applicant: Fortinet, Inc.
    Inventors: Zhi Guo, Peixue Li, Xu Zhou
  • Publication number: 20220261276
    Abstract: Systems and methods for intent-based orchestration of independent automation are described.
    Type: Application
    Filed: February 12, 2021
    Publication date: August 18, 2022
    Applicant: Fortinet, Inc.
    Inventors: Michael C. Starr, John T. Kamenik
  • Publication number: 20220255792
    Abstract: Various approaches for providing network maintenance and health monitoring. In some cases, some approaches include systems, methods, and/or devices embodiments that provide for receiving and cataloging network incidents and in providing proposed solutions to mitigate the network incidents.
    Type: Application
    Filed: February 11, 2021
    Publication date: August 11, 2022
    Applicant: Fortinet, Inc.
    Inventors: Jason Abate, Shabbir Karimi