Patents Assigned to Fortinet, Inc.
  • Patent number: 12706879
    Abstract: Packet traffic flow control includes receiving a packet, by a first virtual machine network security appliance (VMNSA), and determining whether the packet is to be processed by a first path or a second path; in response to determining that the packet is to be processed by the first path, processing the packet by a first traffic flow controller (TFC) of the VMNSA, forwarding the packet by the first TFC to a first transmitter, and sending the packet by the first transmitter; and in response to determining that the packet is to be processed by the second path, processing the packet by the first TFC, forwarding the packet by the first TFC to a second TFC of the VMNSA, processing the packet by the second TFC, forwarding the packet by the second TFC to a second transmitter, and sending the packet by the second transmitter.
    Type: Grant
    Filed: September 4, 2024
    Date of Patent: August 11, 2026
    Assignee: FORTINET, INC.
    Inventor: Liwu Liu
  • Patent number: 12706931
    Abstract: Identifying threats in event data, including: receiving, via an event streaming platform, a plurality of records of event data; filtering the plurality of records of event data to generate a filtered plurality of records; determining that one or more of the filtered plurality of records corresponds to one or more entries in one or more threat assessment resources; and generating an alert based on the one or more filtered plurality of records.
    Type: Grant
    Filed: August 10, 2022
    Date of Patent: August 11, 2026
    Assignee: FORTINET, INC.
    Inventors: Úlfar Erlingsson, Yijou Chen
  • Patent number: 12706933
    Abstract: Automatically classifying user activity for cohort analysis, including: gathering first information describing data upload activity of a user; gathering second information describing data upload activity for one or more cohorts of the user; and determining, based on the first information and the second information, a risk evaluation for the user.
    Type: Grant
    Filed: October 18, 2023
    Date of Patent: August 11, 2026
    Assignee: FORTINET, INC.
    Inventors: Trevor A. Welsh, Harish Kumar Bharat Singh, Weifei Zeng, Yijou Chen
  • Patent number: 12705288
    Abstract: An unknown web page is received for categorization, for example, from a web filtering service in a web browser or a firewall. Semantic embeddings are generated by enriching the unknown web page with semantic meaning in order to determine an unknown web page vector. Proximity of the unknown web page semantic embeddings to the known web categories is calculated by comparing the average vector against the unknown web page vector. A category label for a web site category for the new web page is output based on the calculated proximity. Once known, web filtering and other network policies can be applied to the web page.
    Type: Grant
    Filed: June 29, 2024
    Date of Patent: August 11, 2026
    Assignee: Fortinet, Inc.
    Inventors: Powell Patrick Cheng Tan, Kai Xu, Ye Ma
  • Patent number: 12707332
    Abstract: An SD-WAN route is selected based on the TOS parameters matching real-time SD-WAN link quality requirement by matching jitter, latency and/or packet loss requirements of TOS parameters to highest ranking links over a route. The TOS parameters for a specific application can be parsed from data traffic and matched to optimal SD-WAN routes. The data traffic of the first data packet and subsequent data packets of the first session is output to the selected SD-WAN link.
    Type: Grant
    Filed: December 31, 2023
    Date of Patent: August 11, 2026
    Assignee: Fortinet, Inc.
    Inventors: Wang Xi, Shangwei Duan
  • Patent number: 12706833
    Abstract: A processor has hardware acceleration enabled during passive link quality measurement. The processor comprises a forwarding engine to passively gather link quality details from existing network sessions concerning a plurality of links. The link quality details comprise latency, jitter and packet loss. An SD-WAN path selection module identifies a link from the plurality of links for data packets of a current session using the link quality details. A transmission module sends data packets of the current session over the selected link.
    Type: Grant
    Filed: September 30, 2023
    Date of Patent: August 11, 2026
    Assignee: Fortinet, Inc.
    Inventors: Juan Ruiz Sanchez, Jorge Garcia Alvarez
  • Patent number: 12706980
    Abstract: Systems, methods, and products for data ingestion into top-level shards that include a self-contained infrastructure for detecting anomalies in a cloud-computing environment, including an intake database for receiving input data from the cloud-computing environment, an anomaly detection module, an output database storing results of the processing of the anomaly detection module, and an alert generation module for generating event alerts based on the anomaly detection, including: associating a domain-independent top-level shard with a customer identifier; receiving data corresponding to the customer identifier; and storing the received data in the top-level shard.
    Type: Grant
    Filed: June 29, 2022
    Date of Patent: August 11, 2026
    Assignee: FORTINET, INC.
    Inventors: James H. Turner, Úlfar Erlingsson, Yijou Chen
  • Patent number: 12706932
    Abstract: An illustrative method for operating software agent deployed within a compute environment may include directing the software agent to collect and transmit, to a data platform, a first type of workload data associated with one or more workloads deployed within the compute environment, detecting, while the software agent is operating to collect and transmit the first type of workload data, a request for the software agent to collect a second type of workload data associated with the one or more workloads, and directing, based on the request and without modifying executable code of the software agent, the software agent to collect and transmit, to the data platform, the second type of workload data.
    Type: Grant
    Filed: September 30, 2022
    Date of Patent: August 11, 2026
    Assignee: FORTINET, INC.
    Inventors: Anil K. Nanduri, Xiaofei Guo, Ross T. Bunker, Alex Ramachandran Nirmala, Matti A. Vanninen, Chirag P. Pandya, Yijou Chen
  • Patent number: 12706968
    Abstract: Approaches to use of ephemeral workloads to monitor compute environments are described.
    Type: Grant
    Filed: December 18, 2024
    Date of Patent: August 11, 2026
    Assignee: FORTINET, INC.
    Inventors: Neil Chao, Chonghan Chen, Craig E. Skinfill, Dmytro Ilchenko, Anand Natarajan, Meghan Kast, Derek G. Murray, Rui Zhang, Yijou Chen
  • Publication number: 20260228350
    Abstract: A system is disclosed. The system includes at least one physical memory device and one or more processors coupled with the at least one physical memory device to receive an interface status at a first network device from a second network device in a high availability (HA) cluster via a first HA interface, identify first sessions at the first network device that are owned by the second network device and update ownership of each session in the first sessions from the second network device to a third network device in the cluster, wherein the second network device comprises a secondary HA peer and the third network device comprises a primary HA peer.
    Type: Application
    Filed: January 31, 2025
    Publication date: August 6, 2026
    Applicant: Fortinet, Inc.
    Inventors: Levana He, Yong Wang, Frank Pan
  • Patent number: 12701161
    Abstract: A source node from the cluster of nodes, responsive to receiving the file sharing command from other applications on the same node (e.g., on a virtual machine in the cluster of nodes), copies the shared file to a source workspace directory and compress, and then copy the compressed file to the file sync database. The command comprises a configuration template with file retrieval information. A target node from the cluster of nodes, listens for commands from other nodes in the cluster of nodes. Responsive to receiving the file sharing command, the compressed file is copied from the file sync database to a target workspace directory and decompress, and then copy the shared file to node.
    Type: Grant
    Filed: December 27, 2024
    Date of Patent: August 4, 2026
    Assignee: Fortinet, Inc.
    Inventors: Chaturbhuj Singh, Niraj Nandane, Pooja Singh
  • Patent number: 12695768
    Abstract: Monitoring a software development pipeline, including: retrieving, from one or more components in the software development pipeline, information associated with a software application; identifying, based on the information associated with the software application, an anomaly associated with the software application; and performing one or more remedial actions based on the anomaly.
    Type: Grant
    Filed: June 13, 2022
    Date of Patent: July 28, 2026
    Assignee: FORTINET, INC.
    Inventors: Salim Afiune Maya, David M. Hazekamp, Úlfar Erlingsson, Yijou Chen
  • Patent number: 12688089
    Abstract: A conditional high availability peering among all members of an all-active NGFW cluster is established. Data paths are monitored via a dynamic routing protocol capable of conditional advertisement, such as BGP, to detect network isolation failures. Peering can be temporarily suspended with the remote NGFWs by withdrawing the local IP address used for high availability peering to the remote NGFWs, responsive to the detected data path failure. Responsive to detecting a cure of the failed data path using said dynamic routing protocol, the high availability peering to remote NGFW nodes is automatically restored by resuming advertisement of the local peering IP address of the NGFW, wherein the high availability peering is reactivated for all remote NGFW nodes.
    Type: Grant
    Filed: June 27, 2024
    Date of Patent: July 21, 2026
    Assignee: Fortinet, Inc.
    Inventor: Rusdy Krisman
  • Patent number: 12689640
    Abstract: Generating queries for an anomaly detection framework using natural language prompts, including: receiving a prompt to a large language model for a query in a query language of an anomaly detection framework; providing the prompt to the large language model; and presenting, based on the prompt, the query received from the large language model.
    Type: Grant
    Filed: July 11, 2023
    Date of Patent: July 21, 2026
    Assignee: Fortinet, Inc.
    Inventors: Heidar Ragnarsson, David M. Hazekamp, Theodore M. Reed, Salim Afiune Maya, Ian C. Richardson, Matthew Cadorette, Yijou Chen, Sowmya Karmali
  • Patent number: 12689638
    Abstract: An illustrative method for operating software agent deployed within a compute environment may include detecting a request for a software agent deployed within a compute environment to collect a new type of workload data not previously collected by the software agent and associated with one or more workloads deployed within the compute environment, directing, based on the request, the software agent to install a module corresponding to the new type of workload data in a kernel of an operating system associated with the one or more workloads, and receiving the new type of workload data collected by the software agent using the module in a dataset that uses a same schema as another type of workload data previously collected by the software agent.
    Type: Grant
    Filed: November 22, 2022
    Date of Patent: July 21, 2026
    Assignee: Fortinet, Inc.
    Inventors: Anil K. Nanduri, Alex Ramachandran Nirmala, Chirag P. Pandya, Yijou Chen
  • Patent number: 12683869
    Abstract: An adaptive TTL model is generated from connection events, based on varying flight delay times for connecting the device manager to a plurality of managed devices. During a connection event for any of the plurality of managed devices, a TTL value is automatically chosen for the connection event from the adaptive TTL model.
    Type: Grant
    Filed: March 27, 2023
    Date of Patent: July 14, 2026
    Assignee: Fortinet, Inc.
    Inventors: Venugopal SethuRamasamy, Shashikiran G. Shirole
  • Patent number: 12684020
    Abstract: Approaches policy set feature guided node level partitioning for policy search tree optimization are disclosed. A set of policy bins is generated by creating equal-width bins on a given dimension. An original policy set is scanned to determine a number of policies falling into each policy bin in the set of policy bins. An original policy set characteristic is measured based on the number of policies falling into each policy bin. Parameters that represent relationships between the policy set and another policy set are determined based on a number of policies falling into each policy bin and the policy set characteristic. A new policy set is generated based on the parameters. A new policy search tree is generated based on a new policy set. The new policy search tree provides improved build cost or improved search cost as compared a search tree based on the original policy set.
    Type: Grant
    Filed: December 2, 2024
    Date of Patent: July 14, 2026
    Assignee: Fortinet, Inc.
    Inventors: Shushan Wen, Tianrui Wei, Kevin Juncheng Xu
  • Patent number: 12683977
    Abstract: Various embodiments provide systems and methods for providing security in a ZTNA system.
    Type: Grant
    Filed: August 28, 2024
    Date of Patent: July 14, 2026
    Assignee: Fortinet, Inc.
    Inventor: Robert A. May
  • Patent number: 12683934
    Abstract: Approaches to providing endpoint client authentication and application access control in a zero-trust network access (ZTNA) environment are described. A secure session is generated with a secure web proxy based on a request from a browser, wherein the request corresponds to a user and requests access to a server. A secure tunnel is established between the secure web proxy and the browser. A web proxy address corresponding to the user is generated. The user is identified based on a handshake procedure with the secure web proxy. A temporary passcode is generated for the user to be used for access to the server. The temporary passcode is sent to an email address associated with the user. The server is caused to authenticate the user utilizing the temporary passcode to allow the user access to the server if the temporary passcode is approved.
    Type: Grant
    Filed: October 31, 2024
    Date of Patent: July 14, 2026
    Assignee: Fortinet, Inc.
    Inventors: Feng Han, Ying Li Wang, Wenping Luo, Yidong Wei
  • Patent number: 12676874
    Abstract: An illustrative method for querying multiple datasets may include accessing a plurality of datasets including data associated with monitoring one or more compute environments and ingested at varying time intervals, receiving a query request for information that depends on the data included in multiple datasets of the plurality of datasets, querying, based on the query request, the multiple datasets, prioritizing, based on the varying time intervals, information that depends on the data included in the multiple datasets and presenting, based on the prioritizing, a query result representative of the information that depends on the data included in the multiple datasets.
    Type: Grant
    Filed: December 14, 2023
    Date of Patent: July 7, 2026
    Assignee: Fortinet, Inc.
    Inventors: Ulfar Erlingsson, Helgi K. Sigurbjarnarson, Ross T. Bunker, Yijou Chen