Patents by Inventor Michael C. Starr
Michael C. Starr has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20240103911Abstract: Systems and methods for intent-based orchestration of independent automations are provided. Examples described herein alleviate the complexities and technical challenges associated with deploying, provisioning, configuring, and managing configurable endpoints, including network devices, network security systems, cloud-based security services (e.g., provided by or representing a Secure Access Service Edge (SASE) platform), and other infrastructure, on behalf of numerous customers (or tenants). For example, customer intent may be automatically translated into concrete jobs and tasks that operate to make changes to one or more of the configurable endpoints so as to insulate the user from being required to know which configurable endpoint(s) need(s) to change, which vendor supports a given configurable endpoint, and/or vendor specific issues involved in changing the configurable endpoints.Type: ApplicationFiled: November 30, 2023Publication date: March 28, 2024Applicant: Fortinet, Inc.Inventors: Michael C. Starr, John T. Kamenik
-
Patent number: 11928499Abstract: Systems and methods for intent-based orchestration of independent automation are described.Type: GrantFiled: February 12, 2021Date of Patent: March 12, 2024Assignee: Fortinet, Inc.Inventors: Michael C. Starr, John T. Kamenik
-
Patent number: 11870814Abstract: Systems and methods for a unified, cloud-managed platform for controlling enterprise network security are provided. According to one embodiment, a network of an enterprise is protected by a cloud-managed platform. An underlying architecture of the cloud-managed platform is abstracted by providing a portal through which modifications to security policies are expressed as business requirements of the enterprise. The security policies are automatically enforced regardless of location or endpoint. A policy digest, including information regarding the modifications and formatted according to a predefined format, generated and locally queued by the portal is retrieved.Type: GrantFiled: December 2, 2021Date of Patent: January 9, 2024Assignee: Fortinet, Inc.Inventors: Anurag Jain, Kenneth Ammon, Thomas Cross, Michael C. Starr
-
Publication number: 20230156014Abstract: Systems and methods for adjusting the behavior of an endpoint security agent based on a network location are provided. According to an embodiment, an agent of an endpoint device identifies whether a security service of a cloud-based security service is not reachable or is unresponsive. The security service is associated with a particular security function implemented by the agent. When the security service is not reachable or is unresponsive, the agent further determines whether the endpoint device is within a trusted network of multiple trusted networks that have been previously registered with the cloud-based security service by querying a trusted network determination service associated with the cloud-based security service. When the determination is affirmative, the particular security feature is configured for operating inside a trusted network. When the determination is negative, the particular security feature is configured for operating outside a trusted network.Type: ApplicationFiled: January 17, 2023Publication date: May 18, 2023Applicant: Fortinet, Inc.Inventors: Gregory L. Galloway, Karl D. Melcher, Michael C. Starr, Scott M. Davis
-
Patent number: 11601438Abstract: Systems and methods for adjusting the behavior of an endpoint security agent based on a network location are provided. According to an embodiment, an agent of an endpoint device identifies whether a security service of a cloud-based security service is not reachable or is unresponsive. The security service is associated with a particular security function implemented by the agent. When the security service is not reachable or is unresponsive, the agent further determines whether the endpoint device is within a trusted network of multiple trusted networks that have been previously registered with the cloud-based security service by querying a trusted network determination service associated with the cloud-based security service. When the determination is affirmative, the particular security feature is configured for operating inside a trusted network. When the determination is negative, the particular security feature is configured for operating outside a trusted network.Type: GrantFiled: September 25, 2020Date of Patent: March 7, 2023Assignee: Fortinet, Inc.Inventors: Gregory L. Galloway, Karl D. Melcher, Michael C. Starr, Scott M. Davis
-
Publication number: 20230064373Abstract: A system includes a security and vulnerability analysis processor, one or more endpoint devices in communication with the security and vulnerability analysis processor through a communication network, and a vulnerability data ingestion processor configured to obtain, from one or more data sources, security data associated with the one or more endpoint devices. The security and vulnerability analysis processor includes a machine learning model configured to generate predictions about the risk impact of conducting vulnerability remediations to a particular endpoint device of the one or more endpoint devices. The machine learning model is trained using a training set comprising the security data associated with the one or more endpoint devices.Type: ApplicationFiled: September 2, 2022Publication date: March 2, 2023Inventor: Michael C. Starr
-
Publication number: 20220261276Abstract: Systems and methods for intent-based orchestration of independent automation are described.Type: ApplicationFiled: February 12, 2021Publication date: August 18, 2022Applicant: Fortinet, Inc.Inventors: Michael C. Starr, John T. Kamenik
-
Patent number: 11327898Abstract: Systems and methods for a unified, cloud-managed platform for controlling enterprise network security are provided. According to one embodiment, a network of an enterprise is protected by a cloud-managed platform. An underlying architecture of the cloud-managed platform is abstracted by providing a portal through which modifications to security policies are expressed as business requirements of the enterprise. The security policies are automatically enforced regardless of location or endpoint. A policy digest, including information regarding the modifications and formatted according to a predefined format, generated and locally queued by the portal is retrieved.Type: GrantFiled: September 23, 2020Date of Patent: May 10, 2022Assignee: Fortinet, Inc.Inventors: Anurag Jain, Kenneth Ammon, Thomas Cross, Michael C. Starr
-
Publication number: 20220103523Abstract: Systems and methods for establishing a secure connection between an endpoint agent and a cloud-based security service are provided. According to one embodiment, a DNS request is issued by an agent running on an endpoint device to a secure Internet connection service of a cloud-based security service that includes multiple pools of geographically distributed VPN servers. A DNS response to the DNS request is received containing an IP address of a particular VPN server within a pool of the multiple pools. The pool is selected by the secure Internet connection service based on a geographic location of the endpoint device inferred by a source IP address of the DNS request. The particular VPN server is selected from multiple VPN servers in the pool based on its status. A secure Internet connection is established between the agent and the particular VPN server via a particular logical port.Type: ApplicationFiled: September 30, 2020Publication date: March 31, 2022Applicant: Fortinet, Inc.Inventors: Michael C. Starr, Gregory L. Galloway
-
Publication number: 20220103594Abstract: Systems and methods for adjusting the behavior of an endpoint security agent based on a network location are provided. According to an embodiment, an agent of an endpoint device detects whether the endpoint has moved to a new network by monitoring for changes to an IP address associated with the endpoint. When the detecting is affirmative, the agent further determines whether a trusted network determination service associated with a cloud-based security service is reachable. When the determining is affirmative, the agent further identifies whether the new network is among a set of trusted networks that have been previously registered with the cloud-based security service by querying the trusted network determination service. When the identifying is affirmative, a particular security feature on the endpoint is configured for operation within a trusted network and when the identifying is negative, the particular security feature is configured for operation outside of a trusted networks.Type: ApplicationFiled: September 25, 2020Publication date: March 31, 2022Applicant: Fortinet, Inc.Inventors: Gregory L. Galloway, Karl D. Melcher, Michael C. Starr, Scott M. Davis
-
Publication number: 20220103569Abstract: Systems and methods for adjusting the behavior of an endpoint security agent based on a network location are provided. According to an embodiment, an agent of an endpoint device identifies whether a security service of a cloud-based security service is not reachable or is unresponsive. The security service is associated with a particular security function implemented by the agent. When the security service is not reachable or is unresponsive, the agent further determines whether the endpoint device is within a trusted network of multiple trusted networks that have been previously registered with the cloud-based security service by querying a trusted network determination service associated with the cloud-based security service. When the determination is affirmative, the particular security feature is configured for operating inside a trusted network. When the determination is negative, the particular security feature is configured for operating outside a trusted network.Type: ApplicationFiled: September 25, 2020Publication date: March 31, 2022Applicant: Fortinet, Inc.Inventors: Gregory L. Galloway, Karl D. Melcher, Michael C. Starr, Scott M. Davis
-
Publication number: 20220091994Abstract: Systems and methods for a unified, cloud-managed platform for controlling enterprise network security are provided. According to one embodiment, a network of an enterprise is protected by a cloud-managed platform. An underlying architecture of the cloud-managed platform is abstracted by providing a portal through which modifications to security policies are expressed as business requirements of the enterprise. The security policies are automatically enforced regardless of location or endpoint. A policy digest, including information regarding the modifications and formatted according to a predefined format, generated and locally queued by the portal is retrieved.Type: ApplicationFiled: December 2, 2021Publication date: March 24, 2022Applicant: Fortinet, Inc.Inventors: Anurag Jain, Kenneth Ammon, Thomas Cross, Michael C. Starr
-
Publication number: 20210004333Abstract: Systems and methods for a unified, cloud-managed platform for controlling enterprise network security are provided. According to one embodiment, a network of an enterprise is protected by a cloud-managed platform. An underlying architecture of the cloud-managed platform is abstracted by providing a portal through which modifications to security policies are expressed as business requirements of the enterprise. The security policies are automatically enforced regardless of location or endpoint. A policy digest, including information regarding the modifications and formatted according to a predefined format, generated and locally queued by the portal is retrieved.Type: ApplicationFiled: September 23, 2020Publication date: January 7, 2021Applicant: Fortinet, Inc.Inventors: Anurag Jain, Kenneth Ammon, Thomas Cross, Michael C. Starr
-
Patent number: 10826941Abstract: A method for protecting an enterprise network includes, at a system that is remote from the enterprise network: controlling communications to and from the enterprise network according to a set of security policies; controlling endpoint to endpoint connections within the enterprise network according to the set of security policies; receiving a request for modifications to the set of policies; automatically generating a policy digest formatted according to a predefined format, the policy digest comprising the modifications, and storing the policy digest in the memory; retrieving the policy digest from the memory; generating one or more calls to one or more system components that control the communications to and from the enterprise network and the endpoint to endpoint connections based on the policy digest; and modifying control of the communications and the endpoint to endpoint connections based on the one or more calls.Type: GrantFiled: June 29, 2018Date of Patent: November 3, 2020Assignee: Fortinet, Inc.Inventors: Anurag Jain, Kenneth Ammon, Thomas Cross, Michael C. Starr