Patents Assigned to Fortinet, Inc.
-
Patent number: 12688089Abstract: A conditional high availability peering among all members of an all-active NGFW cluster is established. Data paths are monitored via a dynamic routing protocol capable of conditional advertisement, such as BGP, to detect network isolation failures. Peering can be temporarily suspended with the remote NGFWs by withdrawing the local IP address used for high availability peering to the remote NGFWs, responsive to the detected data path failure. Responsive to detecting a cure of the failed data path using said dynamic routing protocol, the high availability peering to remote NGFW nodes is automatically restored by resuming advertisement of the local peering IP address of the NGFW, wherein the high availability peering is reactivated for all remote NGFW nodes.Type: GrantFiled: June 27, 2024Date of Patent: July 21, 2026Assignee: Fortinet, Inc.Inventor: Rusdy Krisman
-
Patent number: 12689640Abstract: Generating queries for an anomaly detection framework using natural language prompts, including: receiving a prompt to a large language model for a query in a query language of an anomaly detection framework; providing the prompt to the large language model; and presenting, based on the prompt, the query received from the large language model.Type: GrantFiled: July 11, 2023Date of Patent: July 21, 2026Assignee: Fortinet, Inc.Inventors: Heidar Ragnarsson, David M. Hazekamp, Theodore M. Reed, Salim Afiune Maya, Ian C. Richardson, Matthew Cadorette, Yijou Chen, Sowmya Karmali
-
Patent number: 12689638Abstract: An illustrative method for operating software agent deployed within a compute environment may include detecting a request for a software agent deployed within a compute environment to collect a new type of workload data not previously collected by the software agent and associated with one or more workloads deployed within the compute environment, directing, based on the request, the software agent to install a module corresponding to the new type of workload data in a kernel of an operating system associated with the one or more workloads, and receiving the new type of workload data collected by the software agent using the module in a dataset that uses a same schema as another type of workload data previously collected by the software agent.Type: GrantFiled: November 22, 2022Date of Patent: July 21, 2026Assignee: Fortinet, Inc.Inventors: Anil K. Nanduri, Alex Ramachandran Nirmala, Chirag P. Pandya, Yijou Chen
-
Patent number: 12683869Abstract: An adaptive TTL model is generated from connection events, based on varying flight delay times for connecting the device manager to a plurality of managed devices. During a connection event for any of the plurality of managed devices, a TTL value is automatically chosen for the connection event from the adaptive TTL model.Type: GrantFiled: March 27, 2023Date of Patent: July 14, 2026Assignee: Fortinet, Inc.Inventors: Venugopal SethuRamasamy, Shashikiran G. Shirole
-
Patent number: 12684020Abstract: Approaches policy set feature guided node level partitioning for policy search tree optimization are disclosed. A set of policy bins is generated by creating equal-width bins on a given dimension. An original policy set is scanned to determine a number of policies falling into each policy bin in the set of policy bins. An original policy set characteristic is measured based on the number of policies falling into each policy bin. Parameters that represent relationships between the policy set and another policy set are determined based on a number of policies falling into each policy bin and the policy set characteristic. A new policy set is generated based on the parameters. A new policy search tree is generated based on a new policy set. The new policy search tree provides improved build cost or improved search cost as compared a search tree based on the original policy set.Type: GrantFiled: December 2, 2024Date of Patent: July 14, 2026Assignee: Fortinet, Inc.Inventors: Shushan Wen, Tianrui Wei, Kevin Juncheng Xu
-
Patent number: 12683977Abstract: Various embodiments provide systems and methods for providing security in a ZTNA system.Type: GrantFiled: August 28, 2024Date of Patent: July 14, 2026Assignee: Fortinet, Inc.Inventor: Robert A. May
-
Patent number: 12683934Abstract: Approaches to providing endpoint client authentication and application access control in a zero-trust network access (ZTNA) environment are described. A secure session is generated with a secure web proxy based on a request from a browser, wherein the request corresponds to a user and requests access to a server. A secure tunnel is established between the secure web proxy and the browser. A web proxy address corresponding to the user is generated. The user is identified based on a handshake procedure with the secure web proxy. A temporary passcode is generated for the user to be used for access to the server. The temporary passcode is sent to an email address associated with the user. The server is caused to authenticate the user utilizing the temporary passcode to allow the user access to the server if the temporary passcode is approved.Type: GrantFiled: October 31, 2024Date of Patent: July 14, 2026Assignee: Fortinet, Inc.Inventors: Feng Han, Ying Li Wang, Wenping Luo, Yidong Wei
-
Patent number: 12676874Abstract: An illustrative method for querying multiple datasets may include accessing a plurality of datasets including data associated with monitoring one or more compute environments and ingested at varying time intervals, receiving a query request for information that depends on the data included in multiple datasets of the plurality of datasets, querying, based on the query request, the multiple datasets, prioritizing, based on the varying time intervals, information that depends on the data included in the multiple datasets and presenting, based on the prioritizing, a query result representative of the information that depends on the data included in the multiple datasets.Type: GrantFiled: December 14, 2023Date of Patent: July 7, 2026Assignee: Fortinet, Inc.Inventors: Ulfar Erlingsson, Helgi K. Sigurbjarnarson, Ross T. Bunker, Yijou Chen
-
Patent number: 12676772Abstract: Zero-trust network access (ZTNA) with user datagram protocol (UDP) message forwarding is disclosed. A forwarding rule is determined based on a destination address associated with a received data traffic packet formatted according to a first protocol (e.g., UDP). A bi-directional tunnel is created to forward the traffic based on the determined forwarding rule. A request is generated over a stream having a corresponding stream identifier within the bi-directional tunnel to establish a connection with a proxy device. The traffic packet payload formatted according to the first protocol is wrapped with at least the stream identifier. The wrapped data traffic packet is forwarded to a client device based on the determined forwarding rule to a destination device corresponding to the stream identifier.Type: GrantFiled: April 30, 2024Date of Patent: July 7, 2026Assignee: FORTINET, INC.Inventors: Weining Wu, Junhao Yin
-
Patent number: 12676863Abstract: Security posture tags are calculated from security posture updates about data files gathered from a plurality of security posture agents executing on a plurality of network devices. A request for access including a name of a data file is received. A security posture tag associated with the data file receive. One or more zero trust data access (ZTDA) network policies associated with data file itself is applied as corresponding to the request and/or the data of the security posture tag are applied. Access to the data file of the request is then provided, subject to application of the one or more ZTDA network policies identified as corresponding to the request.Type: GrantFiled: September 30, 2024Date of Patent: July 7, 2026Assignee: Fortinet, Inc.Inventor: Julian H. Benavides
-
Publication number: 20260187544Abstract: Data sets are analyzed with EDA for determining feasible data for training. Monitoring of stations can be passive by snooping data packets, and can be active by direct communication with an operating system. A conference application currently running on a specific station is detected from data packets associated with the specific station. A set of channel experiences and a set of conference application experiences are predicted using the experience prediction model. A sliding window can define a time period for predictions and weighting can define relativity between different inputs. The experience prediction module has been trained with validated channel statistics collected at network sensors dispersed at different locations on the enterprise network.Type: ApplicationFiled: December 27, 2024Publication date: July 2, 2026Applicant: Fortinet, Inc.Inventors: Siva Yogendra Jupudi, Zahoor Ahmed Kazi, Srikaran Shanmukha, Sudhanshu Shandilya, Raveendra Joshi, Sudheer Nagurla, Joel Kingston
-
Publication number: 20260189974Abstract: At a conversion sub-module of a 5G subsystem, the 5G data packets are converted from a 5G cellular data packet format to an Ethernet/Wi-Fi data packet format (and vice versa for upstream traffic). The converted data packets are transmitted from the 5G subsystem to a host system over a GMII channel, as a virtualized Ethernet interface, to an Ethernet packet hardware acceleration engine, to the Ethernet packet hardware acceleration engine. The 5G subsystem is connected to the host system as a USB device. The converted 5G cellular data packets are processed as Ethernet or Wi-Fi data packets through the Ethernet/Wi-Fit packet hardware acceleration engine. The Ethernet packet hardware acceleration engine bypasses a central processing unit. Then the converted data packet is transmitted downstream over Ethernet or Wi-Fi to a destination. Upstream traffic is received.Type: ApplicationFiled: December 27, 2024Publication date: July 2, 2026Applicant: Fortinet, Inc.Inventors: Kun Yu, Yan Li, Qiangmin Zhao
-
Patent number: 12670094Abstract: A system is disclosed. The system includes at least one physical memory device to store a cache table and report generation logic and cache management logic and one or more processors coupled with the at least one physical memory device to execute the cache management logic to perform cache operations on the cache table based on content types associated with each of a plurality of entries in the cache table, wherein each entry includes a tag, a type identifier (ID) and a payload.Type: GrantFiled: May 20, 2024Date of Patent: June 30, 2026Assignee: FORTINET, INC.Inventor: Shushan Wen
-
Patent number: 12671684Abstract: Systems, devices, and methods are discussed for proactively addressing low quality access credentials in a network environment.Type: GrantFiled: December 2, 2021Date of Patent: June 30, 2026Assignee: FORTINET, INC.Inventor: Pedro Miguel Paixao
-
Publication number: 20260180951Abstract: A group of Real Servers, hosting web applications, are scanned to identify vulnerabilities. A next generation firewall of a gateway device located upstream, can virtually patch downstream Real Servers, according to the identified vulnerabilities associated with the Real Servers to prevent exploits. Virtual patching includes configuration of an Intrusion Prevention System (IPS) signatures. Subsequent data traffic is scanned for the identified vulnerabilities of Real Servers at the next generation firewall of the gateway. Pre-scanned data traffic is received for distribution to the Real Servers, in lieu of an operating system update or patch.Type: ApplicationFiled: December 24, 2024Publication date: June 25, 2026Applicant: Fortinet, Inc.Inventor: Oscar Alberto Cifuentes Cortes
-
Publication number: 20260170399Abstract: A machine learning (ML) model architect identifies a problem space for a ML model. The ML model architect then selects a cell architecture skeleton. The ML model architecture defines a set of operations for the cell architecture skeleton. An overparameterized model may be built based at least in part on the cell architecture skeleton and the set of operations for the problem space. The overparameterized model may be reduced to generate a reduced model. The reduced model may be trained using a training dataset to produce a trained, reduced model. Suboptimal operations may be pruned from the trained reduced model to produce a pruned reduced model. Reverse reduction processing may then be performed on the pruned reduced model to generate an optimal cell architecture model for the identified problem space.Type: ApplicationFiled: December 13, 2024Publication date: June 18, 2026Applicant: Fortinet, Inc.Inventor: Sameer Khanna
-
Patent number: 12659333Abstract: Data to be used to generate a capture-the-flag competition for an anomaly detection framework is received from a customer. One or more flags are identified in the data, the one or more flags representing anomalies in the data. A user interface is provided for the capture-the-flag competition including challenges to identify the one or more flags in the data.Type: GrantFiled: April 15, 2024Date of Patent: June 16, 2026Assignee: Fortinet, Inc.Inventors: Galen Emery, Dan Daggett, II, Drew A. Khorasani, Gregory M. Sloan, Craig J. Beyer, Jr., Yijou Chen
-
Patent number: 12659327Abstract: An illustrative method includes monitoring activities within a compute environment and generating a logical graph model using at least a portion of the monitored activities. The logical graph model includes a set of nodes representative of one or more identities, applications, and resources in the compute environment and a set of edges representative of connections between nodes interconnected by the edges. An operation associated with security of the compute environment is performed using the generated logical graph model.Type: GrantFiled: July 11, 2023Date of Patent: June 16, 2026Assignee: Fortinet, Inc.Inventors: Xiaofei Guo, Theodore M. Reed, Kenneth Beasley, Yijou Chen, Sowmya A. Karmali
-
Patent number: 12659325Abstract: An illustrative method includes accessing, by a data platform, workload data associated with one or more workloads deployed within a compute environment and associated with an entity; generating, by the data platform and based on an analysis of the workload data, a rule specific to the entity and associated with an operation of the one or more workloads; and performing, by the data platform, an operation with respect to implementation of the rule within the compute environment.Type: GrantFiled: November 17, 2022Date of Patent: June 16, 2026Assignee: Fortinet, Inc.Inventors: George B. Spofford, Ulfar Erlingsson, Yijou Chen
-
Patent number: 12659326Abstract: An illustrative method for performing an agentless workload assessment may include using an unprivileged agentless workload scanning configuration to generate a replication dataset of a workload associated with a project within a Google Cloud Platform (GCP) environment and perform an analysis of the replication dataset without offloading the replication dataset from the GCP environment. A data platform may perform, based on the analysis, an operation with respect to the workload.Type: GrantFiled: March 30, 2023Date of Patent: June 16, 2026Assignee: Fortinet, Inc.Inventors: Jacob A. Kilby, Theodore M. Reed, Ammar G. Ekbote, Whitney L. Smith, Yijou Chen