Patents Assigned to Fortinet, Inc.
-
Publication number: 20260261601Abstract: A computer-implemented method includes establishing sessions in a first network appliance initially having a primary role for processing network traffic having data packets, upon sessions being established in the first network appliance, offloading of relevant session information for a simultaneous synchronizing process of the relevant session information to a second network appliance initially having a secondary role, and concurrent with the synchronization process, offloading the relevant session information to one or more network processing resources of the second network appliance to ensure that offloaded sessions of the one or more network processing resources are ready to be used on the second network appliance if a Failover process is initiated from the first network appliance to the second network appliance.Type: ApplicationFiled: February 28, 2025Publication date: September 3, 2026Applicant: Fortinet, Inc.Inventors: Bojia Qiu, Frank Pan, Guoyi Yan, Yong Wang
-
Patent number: 12726495Abstract: Machine learning-enabled clustering of entities in a monitored deployment, including: receiving a graph structure describing activity within a cloud deployment; generating, for each node of a plurality of nodes of the graph structure, a corresponding vector embedding by providing each node to a trained model configured to generate the corresponding vector embedding; and generating a clustered embedding space by applying a clustering algorithm to the corresponding vector embedding for each node of the plurality of nodes.Type: GrantFiled: January 2, 2024Date of Patent: September 1, 2026Assignee: FORTINET, INC.Inventors: Pamela Bhattacharya, Andrew D. Twigg, Yijou Chen
-
Patent number: 12726400Abstract: Approaches to using a backup heartbeat interface to detect and mitigate high availability (HA) split-brain conditions are described. Heartbeat packets from the primary appliance received via a regular heartbeat interface of the backup appliance and monitored the backup appliance to determine whether the connection with the primary appliance via the regular heartbeat interface is stable. A backup heartbeat interface on the backup appliance is enabled in response to a determination that the primary appliance is not operating properly resulting from analyzing at least a status of the heartbeat packets from the primary appliance. A backup heartbeat packet is transmitted from the backup appliance to at least the regular heartbeat interface of the primary appliance in response to a determination that the primary appliance is not operating properly. Services are provided with the backup appliance to replace services previously provided by the primary appliance.Type: GrantFiled: August 30, 2024Date of Patent: September 1, 2026Assignee: FORTINET, INC.Inventors: Jinshan Gu, Yong Wang, Frank Pan
-
Patent number: 12719896Abstract: Adding guardrails to generative artificial intelligence (AI)-created workflows, including: receiving, via a natural language interface for a security framework monitoring a cloud deployment, a natural language input; providing the natural language input to a generative artificial intelligence (AI) model; receiving, from the generative AI model, a response to the natural language input, wherein the response comprises data encoding a user interface (UI) widget comprising natural language description of one or more actions determined by the generative AI model based on the natural language input and a selectable element that, when selected by a user, causes the one or more actions to be performed by an entity other than the generative AI model; and presenting the UI widget via the natural language interface.Type: GrantFiled: January 12, 2024Date of Patent: August 25, 2026Assignee: FORTINET, INC.Inventors: Njall Skarphedinsson, Úlfar Erlingsson, Theodore M. Reed, Joshua Vertes, Pamela Bhattacharya, Yijou Chen
-
Patent number: 12719935Abstract: Various embodiments provide embodiments provide systems and methods for performing edge processing using selectively suspended network security processing. In one example, a non-edge device (e.g., a network security appliance) receives a first network traffic representing a first part of a network session from an edge device (e.g., a network router). The non-edge device applies at least one security process to the first network traffic to yield a security result. Based at least in part on the security result, (i) the non-edge device forward, the first network traffic to a destination and (ii) communicates an indication (e.g., a grant of suspended security review) to the edge device that the edge device is not required to transmit a second part of the network traffic session to the non-edge device for application of the at least one security process.Type: GrantFiled: June 9, 2023Date of Patent: August 25, 2026Assignee: FORTINET, INC.Inventors: Joseph R. Mihelich, Michael Xie, Jordan Thompson, Sandip Borle, Sandeep Krishnamurthy
-
Patent number: 12720575Abstract: Stations are monitored that join and leave a multicast group associated with one or more switches over a wired channel and one or more access points over a wireless channel. At least one of latency or packet loss over a threshold are detected for a specific VLAN group. Multicast traffic is segregated in response to the detection, at the one or more switches, by reassigning stations that are not associated with multicast traffic to a new VLAN group, and by at the one or more access points, reassigning stations that are associated with multicast traffic with the low bandwidth frequency and reassigning stations that are not associated with multicast traffic with the high bandwidth frequency.Type: GrantFiled: December 31, 2023Date of Patent: August 25, 2026Assignee: Fortinet, Inc.Inventors: Ruchir Mishra, Ankur Jain
-
Patent number: 12712897Abstract: Providing data warehouse functionality on a local infrastructure, including: ingesting event data into a plurality of batches; applying, to ingested event data in the plurality of files, one or more transformations based on one or more queries applied to other event data stored in database tables of a data warehouse implemented in a data warehouse platform; and storing transformed event data as a plurality of files in storage independent of the data warehouse platform.Type: GrantFiled: September 23, 2022Date of Patent: August 18, 2026Assignee: FORTINET, INC.Inventors: Úlfar Erlingsson, Derek G. Murray, Yijou Chen
-
Patent number: 12713333Abstract: A Wi-Fi controller receives notification of a probe request of a station that was received from each at least two of the at least two of the two or more Wi-Fi 7 access points of a multiple access point coordination group. The probe requests are each sourced from the station while within the at least partially overlapped radio signal coverage area. The Wi-Fi controller selects one of the at least two of the two or more access points to respond to the probe request with a probe response with a single probe response to the station, in response to the multiple probe requests, by notifying the selected access point to send the single probe response including an RNR (reduced neighbor report) data providing connection information for the at least two access points. The other of the at least two Wi-Fi 7 access points refrain from sending additional probe responses to the station.Type: GrantFiled: September 27, 2023Date of Patent: August 18, 2026Assignee: Fortinet, Inc.Inventor: Vijayakumar Vellaichamy
-
Patent number: 12712911Abstract: Responsive to domain name server (DNS) flood conditions being detected, a fully qualified domain name (FQDN) of each DNS query is checked against a table of legitimate FQDNs, and DNS queries having FQDNs that are verified as legitimate queries to pass to the DNS server are allowed, and DNS queries having FQDNs not verified as legitimate queries from passing to the DNS server are blocked.Type: GrantFiled: September 23, 2024Date of Patent: August 18, 2026Assignee: Fortinet, Inc.Inventors: Haibin Cao, Stephen Robinson, Yongping Yi, Yuying Han
-
Patent number: 12712913Abstract: In one embodiment, a similarity index is calculated from characteristics of a suspected phishing web page to a database of known phishing web pages. The characteristics derive from both HTML tags of the suspected phishing web page and a screenshot of the suspected phishing web page. With machine learning using the similarity index as an input, a probability is estimated that the suspected web page comprises a known phishing web page from the database of known phishing web pages. A known phishing web page is selected from one or more candidates known phishing web pages, based on having a highest probability.Type: GrantFiled: March 24, 2023Date of Patent: August 18, 2026Assignee: Fortinet, Inc.Inventors: Haitao Li, Lisheng Ryan Sun
-
Patent number: 12712660Abstract: A Wi-Fi controller identifies a rogue access point from AP scan reports and a rogue station from station scan reports. A connection between the rogue station and the rogue access point is disrupted by notifying a nearby, trusted access point to transmit a spoofed Basic Service Set (BSS) Transition Management Request (BTM-REQ frame) Action frame. In response, the trusted access point generates the frame spoofed with a Preference field value for a rogue BSSID set to a lowest value under a Subelement: BSS Transition Candidate Preference field, and also spoofed having a Preference field value for a trusted BSSID set to a highest value, and further spoofed with the Disassociation Imminent field value is set to 1 indicative of upcoming disconnection.Type: GrantFiled: December 15, 2023Date of Patent: August 18, 2026Assignee: Fortinet, Inc.Inventors: Ankur Jain, Ruchir Mishra
-
Patent number: 12706879Abstract: Packet traffic flow control includes receiving a packet, by a first virtual machine network security appliance (VMNSA), and determining whether the packet is to be processed by a first path or a second path; in response to determining that the packet is to be processed by the first path, processing the packet by a first traffic flow controller (TFC) of the VMNSA, forwarding the packet by the first TFC to a first transmitter, and sending the packet by the first transmitter; and in response to determining that the packet is to be processed by the second path, processing the packet by the first TFC, forwarding the packet by the first TFC to a second TFC of the VMNSA, processing the packet by the second TFC, forwarding the packet by the second TFC to a second transmitter, and sending the packet by the second transmitter.Type: GrantFiled: September 4, 2024Date of Patent: August 11, 2026Assignee: FORTINET, INC.Inventor: Liwu Liu
-
Patent number: 12706931Abstract: Identifying threats in event data, including: receiving, via an event streaming platform, a plurality of records of event data; filtering the plurality of records of event data to generate a filtered plurality of records; determining that one or more of the filtered plurality of records corresponds to one or more entries in one or more threat assessment resources; and generating an alert based on the one or more filtered plurality of records.Type: GrantFiled: August 10, 2022Date of Patent: August 11, 2026Assignee: FORTINET, INC.Inventors: Úlfar Erlingsson, Yijou Chen
-
Patent number: 12706933Abstract: Automatically classifying user activity for cohort analysis, including: gathering first information describing data upload activity of a user; gathering second information describing data upload activity for one or more cohorts of the user; and determining, based on the first information and the second information, a risk evaluation for the user.Type: GrantFiled: October 18, 2023Date of Patent: August 11, 2026Assignee: FORTINET, INC.Inventors: Trevor A. Welsh, Harish Kumar Bharat Singh, Weifei Zeng, Yijou Chen
-
Patent number: 12705288Abstract: An unknown web page is received for categorization, for example, from a web filtering service in a web browser or a firewall. Semantic embeddings are generated by enriching the unknown web page with semantic meaning in order to determine an unknown web page vector. Proximity of the unknown web page semantic embeddings to the known web categories is calculated by comparing the average vector against the unknown web page vector. A category label for a web site category for the new web page is output based on the calculated proximity. Once known, web filtering and other network policies can be applied to the web page.Type: GrantFiled: June 29, 2024Date of Patent: August 11, 2026Assignee: Fortinet, Inc.Inventors: Powell Patrick Cheng Tan, Kai Xu, Ye Ma
-
Patent number: 12707332Abstract: An SD-WAN route is selected based on the TOS parameters matching real-time SD-WAN link quality requirement by matching jitter, latency and/or packet loss requirements of TOS parameters to highest ranking links over a route. The TOS parameters for a specific application can be parsed from data traffic and matched to optimal SD-WAN routes. The data traffic of the first data packet and subsequent data packets of the first session is output to the selected SD-WAN link.Type: GrantFiled: December 31, 2023Date of Patent: August 11, 2026Assignee: Fortinet, Inc.Inventors: Wang Xi, Shangwei Duan
-
Patent number: 12706833Abstract: A processor has hardware acceleration enabled during passive link quality measurement. The processor comprises a forwarding engine to passively gather link quality details from existing network sessions concerning a plurality of links. The link quality details comprise latency, jitter and packet loss. An SD-WAN path selection module identifies a link from the plurality of links for data packets of a current session using the link quality details. A transmission module sends data packets of the current session over the selected link.Type: GrantFiled: September 30, 2023Date of Patent: August 11, 2026Assignee: Fortinet, Inc.Inventors: Juan Ruiz Sanchez, Jorge Garcia Alvarez
-
Patent number: 12706980Abstract: Systems, methods, and products for data ingestion into top-level shards that include a self-contained infrastructure for detecting anomalies in a cloud-computing environment, including an intake database for receiving input data from the cloud-computing environment, an anomaly detection module, an output database storing results of the processing of the anomaly detection module, and an alert generation module for generating event alerts based on the anomaly detection, including: associating a domain-independent top-level shard with a customer identifier; receiving data corresponding to the customer identifier; and storing the received data in the top-level shard.Type: GrantFiled: June 29, 2022Date of Patent: August 11, 2026Assignee: FORTINET, INC.Inventors: James H. Turner, Úlfar Erlingsson, Yijou Chen
-
Patent number: 12706932Abstract: An illustrative method for operating software agent deployed within a compute environment may include directing the software agent to collect and transmit, to a data platform, a first type of workload data associated with one or more workloads deployed within the compute environment, detecting, while the software agent is operating to collect and transmit the first type of workload data, a request for the software agent to collect a second type of workload data associated with the one or more workloads, and directing, based on the request and without modifying executable code of the software agent, the software agent to collect and transmit, to the data platform, the second type of workload data.Type: GrantFiled: September 30, 2022Date of Patent: August 11, 2026Assignee: FORTINET, INC.Inventors: Anil K. Nanduri, Xiaofei Guo, Ross T. Bunker, Alex Ramachandran Nirmala, Matti A. Vanninen, Chirag P. Pandya, Yijou Chen
-
Patent number: 12706968Abstract: Approaches to use of ephemeral workloads to monitor compute environments are described.Type: GrantFiled: December 18, 2024Date of Patent: August 11, 2026Assignee: FORTINET, INC.Inventors: Neil Chao, Chonghan Chen, Craig E. Skinfill, Dmytro Ilchenko, Anand Natarajan, Meghan Kast, Derek G. Murray, Rui Zhang, Yijou Chen