Patents Assigned to Fortinet, Inc.
  • Patent number: 12688089
    Abstract: A conditional high availability peering among all members of an all-active NGFW cluster is established. Data paths are monitored via a dynamic routing protocol capable of conditional advertisement, such as BGP, to detect network isolation failures. Peering can be temporarily suspended with the remote NGFWs by withdrawing the local IP address used for high availability peering to the remote NGFWs, responsive to the detected data path failure. Responsive to detecting a cure of the failed data path using said dynamic routing protocol, the high availability peering to remote NGFW nodes is automatically restored by resuming advertisement of the local peering IP address of the NGFW, wherein the high availability peering is reactivated for all remote NGFW nodes.
    Type: Grant
    Filed: June 27, 2024
    Date of Patent: July 21, 2026
    Assignee: Fortinet, Inc.
    Inventor: Rusdy Krisman
  • Patent number: 12689640
    Abstract: Generating queries for an anomaly detection framework using natural language prompts, including: receiving a prompt to a large language model for a query in a query language of an anomaly detection framework; providing the prompt to the large language model; and presenting, based on the prompt, the query received from the large language model.
    Type: Grant
    Filed: July 11, 2023
    Date of Patent: July 21, 2026
    Assignee: Fortinet, Inc.
    Inventors: Heidar Ragnarsson, David M. Hazekamp, Theodore M. Reed, Salim Afiune Maya, Ian C. Richardson, Matthew Cadorette, Yijou Chen, Sowmya Karmali
  • Patent number: 12689638
    Abstract: An illustrative method for operating software agent deployed within a compute environment may include detecting a request for a software agent deployed within a compute environment to collect a new type of workload data not previously collected by the software agent and associated with one or more workloads deployed within the compute environment, directing, based on the request, the software agent to install a module corresponding to the new type of workload data in a kernel of an operating system associated with the one or more workloads, and receiving the new type of workload data collected by the software agent using the module in a dataset that uses a same schema as another type of workload data previously collected by the software agent.
    Type: Grant
    Filed: November 22, 2022
    Date of Patent: July 21, 2026
    Assignee: Fortinet, Inc.
    Inventors: Anil K. Nanduri, Alex Ramachandran Nirmala, Chirag P. Pandya, Yijou Chen
  • Patent number: 12683869
    Abstract: An adaptive TTL model is generated from connection events, based on varying flight delay times for connecting the device manager to a plurality of managed devices. During a connection event for any of the plurality of managed devices, a TTL value is automatically chosen for the connection event from the adaptive TTL model.
    Type: Grant
    Filed: March 27, 2023
    Date of Patent: July 14, 2026
    Assignee: Fortinet, Inc.
    Inventors: Venugopal SethuRamasamy, Shashikiran G. Shirole
  • Patent number: 12684020
    Abstract: Approaches policy set feature guided node level partitioning for policy search tree optimization are disclosed. A set of policy bins is generated by creating equal-width bins on a given dimension. An original policy set is scanned to determine a number of policies falling into each policy bin in the set of policy bins. An original policy set characteristic is measured based on the number of policies falling into each policy bin. Parameters that represent relationships between the policy set and another policy set are determined based on a number of policies falling into each policy bin and the policy set characteristic. A new policy set is generated based on the parameters. A new policy search tree is generated based on a new policy set. The new policy search tree provides improved build cost or improved search cost as compared a search tree based on the original policy set.
    Type: Grant
    Filed: December 2, 2024
    Date of Patent: July 14, 2026
    Assignee: Fortinet, Inc.
    Inventors: Shushan Wen, Tianrui Wei, Kevin Juncheng Xu
  • Patent number: 12683977
    Abstract: Various embodiments provide systems and methods for providing security in a ZTNA system.
    Type: Grant
    Filed: August 28, 2024
    Date of Patent: July 14, 2026
    Assignee: Fortinet, Inc.
    Inventor: Robert A. May
  • Patent number: 12683934
    Abstract: Approaches to providing endpoint client authentication and application access control in a zero-trust network access (ZTNA) environment are described. A secure session is generated with a secure web proxy based on a request from a browser, wherein the request corresponds to a user and requests access to a server. A secure tunnel is established between the secure web proxy and the browser. A web proxy address corresponding to the user is generated. The user is identified based on a handshake procedure with the secure web proxy. A temporary passcode is generated for the user to be used for access to the server. The temporary passcode is sent to an email address associated with the user. The server is caused to authenticate the user utilizing the temporary passcode to allow the user access to the server if the temporary passcode is approved.
    Type: Grant
    Filed: October 31, 2024
    Date of Patent: July 14, 2026
    Assignee: Fortinet, Inc.
    Inventors: Feng Han, Ying Li Wang, Wenping Luo, Yidong Wei
  • Patent number: 12676874
    Abstract: An illustrative method for querying multiple datasets may include accessing a plurality of datasets including data associated with monitoring one or more compute environments and ingested at varying time intervals, receiving a query request for information that depends on the data included in multiple datasets of the plurality of datasets, querying, based on the query request, the multiple datasets, prioritizing, based on the varying time intervals, information that depends on the data included in the multiple datasets and presenting, based on the prioritizing, a query result representative of the information that depends on the data included in the multiple datasets.
    Type: Grant
    Filed: December 14, 2023
    Date of Patent: July 7, 2026
    Assignee: Fortinet, Inc.
    Inventors: Ulfar Erlingsson, Helgi K. Sigurbjarnarson, Ross T. Bunker, Yijou Chen
  • Patent number: 12676772
    Abstract: Zero-trust network access (ZTNA) with user datagram protocol (UDP) message forwarding is disclosed. A forwarding rule is determined based on a destination address associated with a received data traffic packet formatted according to a first protocol (e.g., UDP). A bi-directional tunnel is created to forward the traffic based on the determined forwarding rule. A request is generated over a stream having a corresponding stream identifier within the bi-directional tunnel to establish a connection with a proxy device. The traffic packet payload formatted according to the first protocol is wrapped with at least the stream identifier. The wrapped data traffic packet is forwarded to a client device based on the determined forwarding rule to a destination device corresponding to the stream identifier.
    Type: Grant
    Filed: April 30, 2024
    Date of Patent: July 7, 2026
    Assignee: FORTINET, INC.
    Inventors: Weining Wu, Junhao Yin
  • Patent number: 12676863
    Abstract: Security posture tags are calculated from security posture updates about data files gathered from a plurality of security posture agents executing on a plurality of network devices. A request for access including a name of a data file is received. A security posture tag associated with the data file receive. One or more zero trust data access (ZTDA) network policies associated with data file itself is applied as corresponding to the request and/or the data of the security posture tag are applied. Access to the data file of the request is then provided, subject to application of the one or more ZTDA network policies identified as corresponding to the request.
    Type: Grant
    Filed: September 30, 2024
    Date of Patent: July 7, 2026
    Assignee: Fortinet, Inc.
    Inventor: Julian H. Benavides
  • Publication number: 20260187544
    Abstract: Data sets are analyzed with EDA for determining feasible data for training. Monitoring of stations can be passive by snooping data packets, and can be active by direct communication with an operating system. A conference application currently running on a specific station is detected from data packets associated with the specific station. A set of channel experiences and a set of conference application experiences are predicted using the experience prediction model. A sliding window can define a time period for predictions and weighting can define relativity between different inputs. The experience prediction module has been trained with validated channel statistics collected at network sensors dispersed at different locations on the enterprise network.
    Type: Application
    Filed: December 27, 2024
    Publication date: July 2, 2026
    Applicant: Fortinet, Inc.
    Inventors: Siva Yogendra Jupudi, Zahoor Ahmed Kazi, Srikaran Shanmukha, Sudhanshu Shandilya, Raveendra Joshi, Sudheer Nagurla, Joel Kingston
  • Publication number: 20260189974
    Abstract: At a conversion sub-module of a 5G subsystem, the 5G data packets are converted from a 5G cellular data packet format to an Ethernet/Wi-Fi data packet format (and vice versa for upstream traffic). The converted data packets are transmitted from the 5G subsystem to a host system over a GMII channel, as a virtualized Ethernet interface, to an Ethernet packet hardware acceleration engine, to the Ethernet packet hardware acceleration engine. The 5G subsystem is connected to the host system as a USB device. The converted 5G cellular data packets are processed as Ethernet or Wi-Fi data packets through the Ethernet/Wi-Fit packet hardware acceleration engine. The Ethernet packet hardware acceleration engine bypasses a central processing unit. Then the converted data packet is transmitted downstream over Ethernet or Wi-Fi to a destination. Upstream traffic is received.
    Type: Application
    Filed: December 27, 2024
    Publication date: July 2, 2026
    Applicant: Fortinet, Inc.
    Inventors: Kun Yu, Yan Li, Qiangmin Zhao
  • Patent number: 12670094
    Abstract: A system is disclosed. The system includes at least one physical memory device to store a cache table and report generation logic and cache management logic and one or more processors coupled with the at least one physical memory device to execute the cache management logic to perform cache operations on the cache table based on content types associated with each of a plurality of entries in the cache table, wherein each entry includes a tag, a type identifier (ID) and a payload.
    Type: Grant
    Filed: May 20, 2024
    Date of Patent: June 30, 2026
    Assignee: FORTINET, INC.
    Inventor: Shushan Wen
  • Patent number: 12671684
    Abstract: Systems, devices, and methods are discussed for proactively addressing low quality access credentials in a network environment.
    Type: Grant
    Filed: December 2, 2021
    Date of Patent: June 30, 2026
    Assignee: FORTINET, INC.
    Inventor: Pedro Miguel Paixao
  • Publication number: 20260180951
    Abstract: A group of Real Servers, hosting web applications, are scanned to identify vulnerabilities. A next generation firewall of a gateway device located upstream, can virtually patch downstream Real Servers, according to the identified vulnerabilities associated with the Real Servers to prevent exploits. Virtual patching includes configuration of an Intrusion Prevention System (IPS) signatures. Subsequent data traffic is scanned for the identified vulnerabilities of Real Servers at the next generation firewall of the gateway. Pre-scanned data traffic is received for distribution to the Real Servers, in lieu of an operating system update or patch.
    Type: Application
    Filed: December 24, 2024
    Publication date: June 25, 2026
    Applicant: Fortinet, Inc.
    Inventor: Oscar Alberto Cifuentes Cortes
  • Publication number: 20260170399
    Abstract: A machine learning (ML) model architect identifies a problem space for a ML model. The ML model architect then selects a cell architecture skeleton. The ML model architecture defines a set of operations for the cell architecture skeleton. An overparameterized model may be built based at least in part on the cell architecture skeleton and the set of operations for the problem space. The overparameterized model may be reduced to generate a reduced model. The reduced model may be trained using a training dataset to produce a trained, reduced model. Suboptimal operations may be pruned from the trained reduced model to produce a pruned reduced model. Reverse reduction processing may then be performed on the pruned reduced model to generate an optimal cell architecture model for the identified problem space.
    Type: Application
    Filed: December 13, 2024
    Publication date: June 18, 2026
    Applicant: Fortinet, Inc.
    Inventor: Sameer Khanna
  • Patent number: 12659333
    Abstract: Data to be used to generate a capture-the-flag competition for an anomaly detection framework is received from a customer. One or more flags are identified in the data, the one or more flags representing anomalies in the data. A user interface is provided for the capture-the-flag competition including challenges to identify the one or more flags in the data.
    Type: Grant
    Filed: April 15, 2024
    Date of Patent: June 16, 2026
    Assignee: Fortinet, Inc.
    Inventors: Galen Emery, Dan Daggett, II, Drew A. Khorasani, Gregory M. Sloan, Craig J. Beyer, Jr., Yijou Chen
  • Patent number: 12659327
    Abstract: An illustrative method includes monitoring activities within a compute environment and generating a logical graph model using at least a portion of the monitored activities. The logical graph model includes a set of nodes representative of one or more identities, applications, and resources in the compute environment and a set of edges representative of connections between nodes interconnected by the edges. An operation associated with security of the compute environment is performed using the generated logical graph model.
    Type: Grant
    Filed: July 11, 2023
    Date of Patent: June 16, 2026
    Assignee: Fortinet, Inc.
    Inventors: Xiaofei Guo, Theodore M. Reed, Kenneth Beasley, Yijou Chen, Sowmya A. Karmali
  • Patent number: 12659325
    Abstract: An illustrative method includes accessing, by a data platform, workload data associated with one or more workloads deployed within a compute environment and associated with an entity; generating, by the data platform and based on an analysis of the workload data, a rule specific to the entity and associated with an operation of the one or more workloads; and performing, by the data platform, an operation with respect to implementation of the rule within the compute environment.
    Type: Grant
    Filed: November 17, 2022
    Date of Patent: June 16, 2026
    Assignee: Fortinet, Inc.
    Inventors: George B. Spofford, Ulfar Erlingsson, Yijou Chen
  • Patent number: 12659326
    Abstract: An illustrative method for performing an agentless workload assessment may include using an unprivileged agentless workload scanning configuration to generate a replication dataset of a workload associated with a project within a Google Cloud Platform (GCP) environment and perform an analysis of the replication dataset without offloading the replication dataset from the GCP environment. A data platform may perform, based on the analysis, an operation with respect to the workload.
    Type: Grant
    Filed: March 30, 2023
    Date of Patent: June 16, 2026
    Assignee: Fortinet, Inc.
    Inventors: Jacob A. Kilby, Theodore M. Reed, Ammar G. Ekbote, Whitney L. Smith, Yijou Chen