Patents by Inventor Anupam Bharali
Anupam Bharali has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20210328799Abstract: The technology presented herein enables a new network element to be authenticated to other network elements automatically. In a particular embodiment, a method provides determining a current time relative to a first time. The first time is known to the new network element and a provisioning network element. The method further provides generating first beacon data using seed data stored on the new network element and the current time and generating keying data using the first beacon data and identification information associated with the new network element. The method also provides identifying a first one-time pad (OTP) from the keying data and using the first OTP to encrypt an authentication request for transfer from the new network element to the provisioning network element.Type: ApplicationFiled: July 2, 2021Publication date: October 21, 2021Inventors: Tushar J. Patel, Anupam Bharali, Stan Lee
-
Patent number: 11088838Abstract: The technology presented herein enables a new network element to be authenticated to other network elements automatically. In a particular embodiment, a method provides determining a current time relative to a first time. The first time is known to the new network element and a provisioning network element. The method further provides generating first beacon data using seed data stored on the new network element and the current time and generating keying data using the first beacon data and identification information associated with the new network element. The method also provides identifying a first one-time pad (OTP) from the keying data and using the first OTP to encrypt an authentication request for transfer from the new network element to the provisioning network element.Type: GrantFiled: May 11, 2018Date of Patent: August 10, 2021Assignee: PALO ALTO NETWORKS, INC.Inventors: Tushar J. Patel, Anupam Bharali, Stan Lee
-
Patent number: 10838830Abstract: A distributed log collector and report generation architecture is disclosed. In some embodiments, a received query to generate a log report is forwarded to each of a plurality of log collector clusters, and responses to the query received from each of at least a subset of the plurality of log collector clusters are aggregated to generate the log report.Type: GrantFiled: June 30, 2015Date of Patent: November 17, 2020Assignee: Palo Alto Networks, Inc.Inventors: Srinath Gutti, Anupam Bharali
-
Publication number: 20190349198Abstract: The technology presented herein enables a new network element to be authenticated to other network elements automatically. In a particular embodiment, a method provides determining a current time relative to a first time. The first time is known to the new network element and a provisioning network element. The method further provides generating first beacon data using seed data stored on the new network element and the current time and generating keying data using the first beacon data and identification information associated with the new network element. The method also provides identifying a first one-time pad (OTP) from the keying data and using the first OTP to encrypt an authentication request for transfer from the new network element to the provisioning network element.Type: ApplicationFiled: May 11, 2018Publication date: November 14, 2019Inventors: Tushar J. Patel, Anupam Bharali, Stan Lee
-
Patent number: 10404750Abstract: Using one or more externally defined objects to at least in part define a security policy is disclosed. In some embodiments, an external object list is obtained from an external list server, and a security policy comprising one or more rules based at least in part on one or more externally defined objects comprising the external object list and based at least in part on one or more locally defined objects is defined. The security policy is enforced with respect to one or more devices and periodically updated as the external object list is updated.Type: GrantFiled: January 23, 2017Date of Patent: September 3, 2019Assignee: Palo Alto Networks, Inc.Inventor: Anupam Bharali
-
Publication number: 20170195369Abstract: Using one or more externally defined objects to at least in part define a security policy is disclosed. In some embodiments, an external object list is obtained from an external list server, and a security policy comprising one or more rules based at least in part on one or more externally defined objects comprising the external object list and based at least in part on one or more locally defined objects is defined. The security policy is enforced with respect to one or more devices and periodically updated as the external object list is updated.Type: ApplicationFiled: January 23, 2017Publication date: July 6, 2017Inventor: Anupam Bharali
-
Patent number: 9602539Abstract: Using one or more externally defined objects to at least in part define a security policy is disclosed. In some embodiments, an external object list is obtained from an external list server, and a security policy comprising one or more rules based at least in part on one or more externally defined objects comprising the external object list and based at least in part on one or more locally defined objects is defined. The security policy is enforced with respect to one or more devices and periodically updated as the external object list is updated.Type: GrantFiled: September 28, 2012Date of Patent: March 21, 2017Assignee: Palo Alto Networks, Inc.Inventor: Anupam Bharali
-
Patent number: 9503424Abstract: Dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions is provided. In some embodiments, dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions includes receiving a network policy that includes a domain name (e.g., the network policy can include a network security rule that is based on the domain name); and periodically updating Internet Protocol (IP) address information associated with the domain name by performing a Domain Name Server (DNS) query.Type: GrantFiled: July 23, 2015Date of Patent: November 22, 2016Assignee: Palo Alto Networks, Inc.Inventors: Anupam Bharali, Ajay Ghatge, Ravi Ithal
-
Patent number: 9503480Abstract: Deploying policy configuration across multiple security devices through hierarchical configuration templates is disclosed. In some embodiments, deploying policy configuration across multiple security devices through hierarchical configuration templates for configuring a plurality of security devices includes receiving at a first security device a hierarchy of templates from a central management server, in which the hierarchy of templates includes configuration information for a group of security devices, and in which the first security device is included in the group of security devices; and reconciling on the first security device's configuration information included in the hierarchy of templates and device specific configuration based on local configuration information, in which the first security device performs an object level reconciliation to maintain device configuration consistency.Type: GrantFiled: March 31, 2015Date of Patent: November 22, 2016Assignee: Palo Alto Networks, Inc.Inventors: Anupam Bharali, Kunal Kundu, Zhi Ning Wang
-
Patent number: 9491047Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for managing network devices. A central management system stores shared configuration objects in a central configuration database. A network device stores shared configuration objects and device-specific configuration objects in a local configuration database. The local configuration database's shared configuration objects correspond to shared configuration objects in the central configuration database. The network device can be configured locally or using the central management system.Type: GrantFiled: February 5, 2013Date of Patent: November 8, 2016Assignee: Palo Alto Networks, Inc.Inventors: Nir Zuk, Ravi Ithal, Anupam Bharali
-
Publication number: 20160014082Abstract: Dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions is provided. In some embodiments, dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions includes receiving a network policy that includes a domain name (e.g., the network policy can include a network security rule that is based on the domain name); and periodically updating Internet Protocol (IP) address information associated with the domain name by performing a Domain Name Server (DNS) query.Type: ApplicationFiled: July 23, 2015Publication date: January 14, 2016Inventors: Anupam Bharali, Ajay Ghatge, Ravi Ithal
-
Publication number: 20150281285Abstract: Deploying policy configuration across multiple security devices through hierarchical configuration templates is disclosed. In some embodiments, deploying policy configuration across multiple security devices through hierarchical configuration templates for configuring a plurality of security devices includes receiving at a first security device a hierarchy of templates from a central management server, in which the hierarchy of templates includes configuration information for a group of security devices, and in which the first security device is included in the group of security devices; and reconciling on the first security device's configuration information included in the hierarchy of templates and device specific configuration based on local configuration information, in which the first security device performs an object level reconciliation to maintain device configuration consistency.Type: ApplicationFiled: March 31, 2015Publication date: October 1, 2015Inventors: Anupam Bharali, Kunal Kundu, Zhi Ning Wang
-
Patent number: 9124627Abstract: Dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions is provided. In some embodiments, dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions includes receiving a network policy that includes a domain name (e.g., the network policy can include a network security rule that is based on the domain name); and periodically updating Internet Protocol (IP) address information associated with the domain name by performing a Domain Name Server (DNS) query.Type: GrantFiled: November 22, 2013Date of Patent: September 1, 2015Assignee: Palo Alto Networks, Inc.Inventors: Anupam Bharali, Ajay Ghatge, Ravi Ithal
-
Patent number: 9104745Abstract: A distributed log collector and report generation architecture is disclosed. In some embodiments, a received query to generate a log report is forwarded to each of a plurality of log collector clusters, and responses to the query received from each of at least a subset of the plurality of log collector clusters are aggregated to generate the log report.Type: GrantFiled: September 28, 2012Date of Patent: August 11, 2015Assignee: Palo Alto Networks, Inc.Inventors: Srinath Gutti, Anupam Bharali
-
Patent number: 9027077Abstract: Deploying policy configuration across multiple security devices through hierarchical configuration templates is disclosed. In some embodiments, deploying policy configuration across multiple security devices through hierarchical configuration templates for configuring a plurality of security devices includes receiving at a first security device a hierarchy of templates from a central management server, in which the hierarchy of templates includes configuration information for a group of security devices, and in which the first security device is included in the group of security devices; and reconciling on the first security device's configuration information included in the hierarchy of templates and device specific configuration based on local configuration information, in which the first security device performs an object level reconciliation to maintain device configuration consistency.Type: GrantFiled: April 30, 2012Date of Patent: May 5, 2015Assignee: Palo Alto Networks, Inc.Inventors: Anupam Bharali, Kunal Kundu, Zhi Ning Wang
-
Patent number: 8938777Abstract: Using geographical information in policy enforcement is disclosed. A request for a resource is received from a device. A policy to be applied to the request is determined based at least in part on geographical information associated with an IP address. The policy is enforced. The IP address may be either a source IP address or a destination IP address.Type: GrantFiled: September 23, 2013Date of Patent: January 20, 2015Assignee: Palo Alto Networks, Inc.Inventors: Anupam Bharali, Ravi Ithal, Yueh-Zen Chen
-
Patent number: 8913523Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for configuring network devices. A central management system stores shared configuration objects in a central configuration database. A network device stores shared configuration objects and device-specific configuration objects in a local configuration database. The local configuration database's shared configuration objects correspond to shared configuration objects in the central configuration database. The central management system determines the network device has received a request to update a shared configuration object, where the request did not originate from the central management system, and updates the central configuration database.Type: GrantFiled: March 29, 2013Date of Patent: December 16, 2014Assignee: Palo Alto Networks, Inc.Inventors: Nir Zuk, Anupam Bharali
-
Publication number: 20140150051Abstract: Dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions is provided. In some embodiments, dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions includes receiving a network policy that includes a domain name (e.g., the network policy can include a network security rule that is based on the domain name); and periodically updating Internet Protocol (IP) address information associated with the domain name by performing a Domain Name Server (DNS) query.Type: ApplicationFiled: November 22, 2013Publication date: May 29, 2014Applicant: Palo Alto Networks, Inc.Inventors: Anupam Bharali, Ajay Ghatge, Ravi Ithal
-
Patent number: 8621556Abstract: Dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions is provided. In some embodiments, dynamic resolution of Fully Qualified Domain Name (FQDN) address objects in policy definitions includes receiving a network policy that includes a domain name (e.g., the network policy can include a network security rule that is based on the domain name); and periodically updating Internet Protocol (IP) address information associated with the domain name by performing a Domain Name Server (DNS) query.Type: GrantFiled: May 25, 2011Date of Patent: December 31, 2013Assignee: Palo Alto Networks, Inc.Inventors: Anupam Bharali, Ajay Ghatge, Ravi Ithal
-
Publication number: 20130318198Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for configuring network devices. A central management system stores shared configuration objects in a central configuration database. A network device stores shared configuration objects and device-specific configuration objects in a local configuration database. The local configuration database's shared configuration objects correspond to shared configuration objects in the central configuration database. The central management system determines the network device has received a request to update a shared configuration object, where the request did not originate from the central management system, and updates the central configuration database.Type: ApplicationFiled: March 29, 2013Publication date: November 28, 2013Applicant: Palo Alto Networks, Inc.Inventors: Nir Zuk, Anupam Bharali