Patents by Inventor Nir Zuk

Nir Zuk has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8769664
    Abstract: Methods, systems, and apparatus, including computer program products, featuring receiving at a first security device a packet. The first security device determines that the packet is associated with a flow assigned to a distinct second security device. The first security device sends the packet to the second security device. After the second security device performs security processing using the packet, the first security device receives from the second security device a message regarding the packet. The first security device transmits the packet.
    Type: Grant
    Filed: January 30, 2009
    Date of Patent: July 1, 2014
    Assignee: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Wilson Xu, Yuming Mao
  • Patent number: 8726016
    Abstract: Methods, computer program products and apparatus for processing data packets are described. Methods include receiving the data packet, examining the data packet, determining a single flow record associated with the packet and extracting flow instructions for two or more devices from the single flow record.
    Type: Grant
    Filed: September 14, 2012
    Date of Patent: May 13, 2014
    Assignee: Juniper Networks, Inc.
    Inventor: Nir Zuk
  • Publication number: 20140119376
    Abstract: Methods and apparatus for processing data packets in a computer network are described. One general method includes receiving a data packet; examining the data packet to classify the data packet including classifying the data packet as a L2 or L3 packet and including determining at least one zone associated with the packet; processing the packet in accordance with one or more policies associated with the zone; determining forwarding information associated with the data packet; and if one or more policies permit, forwarding the data packet toward an intended destination using the forwarding information.
    Type: Application
    Filed: October 24, 2013
    Publication date: May 1, 2014
    Applicant: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Yuming Mao, Haoying Xu, Arnit Green
  • Publication number: 20140115379
    Abstract: Methods and apparatuses for inspecting packets are provided. A primary security system may be configured for processing packets. The primary security system may be operable to maintain flow information for a group of devices to facilitate processing of the packets. A secondary security system may be designated for processing packets upon a failover event. Flow records may be shared from the primary security system with the secondary security system.
    Type: Application
    Filed: December 30, 2013
    Publication date: April 24, 2014
    Applicant: Juniper Networks, Inc.
    Inventors: Nir ZUK, Yuming Mao, Kowsik Guruswamy
  • Publication number: 20140115688
    Abstract: Systems and methods for detecting and preventing network security breaches are described. The systems and methods present a gateway-based packet-forwarding network security solution to not only detect security breaches but also prevent them by directly dropping suspicious packets and connections. The systems and methods employ multiple techniques to detect and prevent network security breaches, including stateful signature detection, traffic signature detection, and protocol anomaly detection.
    Type: Application
    Filed: December 30, 2013
    Publication date: April 24, 2014
    Applicant: Juniper Networks, Inc.
    Inventors: Nir ZUK, Kowsik Guruswamy
  • Patent number: 8677447
    Abstract: Techniques for identifying user names and enforcing policies are disclosed. An external user account associated with an external application request is identified. A policy is applied based on the identified external user account. One example policy is that access to the external application (via the external user account) should be blocked.
    Type: Grant
    Filed: May 25, 2011
    Date of Patent: March 18, 2014
    Assignee: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Song Wang
  • Publication number: 20140075539
    Abstract: Methods and apparatuses are described for inspecting data packets in a computer network. One or more data packets through the network have associated header data and content. One method includes receiving a data packet, examining the data packet to classify the data packet including classifying the data packet using information included in the header and content, determining flow instructions for processing the packet based on both the header information and the content and processing of the packet using the flow instructions.
    Type: Application
    Filed: September 4, 2013
    Publication date: March 13, 2014
    Applicant: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Song Wang, Siu-Wang Leung, Fengmin Gong
  • Patent number: 8635695
    Abstract: Systems and methods for detecting and preventing network security breaches are described. The systems and methods present a gateway-based packet-forwarding network security solution to not only detect security breaches but also prevent them by directly dropping suspicious packets and connections. The systems and methods employ multiple techniques to detect and prevent network security breaches, including stateful signature detection, traffic signature detection, and protocol anomaly detection.
    Type: Grant
    Filed: September 14, 2012
    Date of Patent: January 21, 2014
    Assignee: Juniper Networks, Inc.
    Inventors: Nir Zuk, Kowsik Guruswamy
  • Patent number: 8631113
    Abstract: Methods and apparatuses for inspecting packets are provided. A primary security system may be configured for processing packets. The primary security system may be operable to maintain flow information for a group of devices to facilitate processing of the packets. A secondary security system may be designated for processing packets upon a failover event. Flow records may be shared from the primary security system with the secondary security system.
    Type: Grant
    Filed: September 14, 2012
    Date of Patent: January 14, 2014
    Assignee: Juniper Networks, Inc.
    Inventors: Nir Zuk, Yu Ming Mao, Kowsik Guruswamy
  • Publication number: 20130318198
    Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for configuring network devices. A central management system stores shared configuration objects in a central configuration database. A network device stores shared configuration objects and device-specific configuration objects in a local configuration database. The local configuration database's shared configuration objects correspond to shared configuration objects in the central configuration database. The central management system determines the network device has received a request to update a shared configuration object, where the request did not originate from the central management system, and updates the central configuration database.
    Type: Application
    Filed: March 29, 2013
    Publication date: November 28, 2013
    Applicant: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Anupam Bharali
  • Patent number: 8594085
    Abstract: Methods and apparatus for processing data packets in a computer network are described. One general method includes receiving a data packet; examining the data packet to classify the data packet including classifying the data packet as a L2 or L3 packet and including determining at least one zone associated with the packet; processing the packet in accordance with one or more policies associated with the zone; determining forwarding information associated with the data packet; and if one or more policies permit, forwarding the data packet toward an intended destination using the forwarding information.
    Type: Grant
    Filed: April 11, 2007
    Date of Patent: November 26, 2013
    Assignee: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Yuming Mao, Haoying Xu, Arnit Green
  • Publication number: 20130298222
    Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for processing a first plurality of packets using one or more processors and maintaining one or more flow records associated with the first plurality of packets, and processing a second plurality of packets without maintaining flow records associated with the second plurality of packets and allowing the second plurality of packets to pass to one or more destinations.
    Type: Application
    Filed: April 17, 2013
    Publication date: November 7, 2013
    Applicant: Palo Alto Networks, Inc.
    Inventor: Nir Zuk
  • Patent number: 8565093
    Abstract: Methods and apparatuses are described for inspecting data packets in a computer network. One or more data packets through the network have associated header data and content. One method includes receiving a data packet, examining the data packet to classify the data packet including classifying the data packet using information included in the header and content, determining flow instructions for processing the packet based on both the header information and the content and processing of the packet using the flow instructions.
    Type: Grant
    Filed: July 28, 2011
    Date of Patent: October 22, 2013
    Assignee: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Song Wang, Siu-Wang Leung, Fengmin Gong
  • Patent number: 8443434
    Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for processing a first plurality of packets using one or more processors and maintaining one or more flow records associated with the first plurality of packets, and processing a second plurality of packets without maintaining flow records associated with the second plurality of packets and allowing the second plurality of packets to pass to one or more destinations.
    Type: Grant
    Filed: August 9, 2010
    Date of Patent: May 14, 2013
    Assignee: Palo Alto Networks, Inc.
    Inventor: Nir Zuk
  • Patent number: 8438252
    Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for managing network devices. A central management system stores shared configuration objects in a central configuration database. A network device stores shared configuration objects and device-specific configuration objects in a local configuration database. The local configuration database's shared configuration objects correspond to shared configuration objects in the central configuration database. The network device can be configured locally or using the central management system.
    Type: Grant
    Filed: December 22, 2011
    Date of Patent: May 7, 2013
    Assignee: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Ravi Ithal, Anupam Bharali
  • Patent number: 8432832
    Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for configuring network devices. A central management system stores shared configuration objects in a central configuration database. A network device stores shared configuration objects and device-specific configuration objects in a local configuration database. The local configuration database's shared configuration objects correspond to shared configuration objects in the central configuration database. The central management system determines the network device has received a request to update a shared configuration object, where the request did not originate from the central management system, and updates the central configuration database.
    Type: Grant
    Filed: August 30, 2012
    Date of Patent: April 30, 2013
    Assignee: Palo Alto Networks, Inc.
    Inventors: Nir Zuk, Anupam Bharali
  • Publication number: 20130074184
    Abstract: Packet processing is provided in a multiple processor system including a first processor to processing a packet and to create a tag associated with the packet. The tag includes information about the processing of the packet. A second processor receives the packet subsequent to the first processor and processes the packet using the tag information.
    Type: Application
    Filed: September 14, 2012
    Publication date: March 21, 2013
    Applicant: JUNIPER NETWORKS, INC.
    Inventors: Nir Zuk, Yu Ming Mao
  • Publication number: 20130067268
    Abstract: Methods and apparatuses for inspecting packets are provided. A primary security system may be configured for processing packets. The primary security system may be operable to maintain flow information for a group of devices to facilitate processing of the packets. A secondary security system may be designated for processing packets upon a failover event. Flow records may be shared from the primary security system with the secondary security system.
    Type: Application
    Filed: September 14, 2012
    Publication date: March 14, 2013
    Applicant: JUNIPER NETWORKS, INC.
    Inventors: Nir ZUK, Yu Ming Mao, Kowsik Guruswamy
  • Publication number: 20130067575
    Abstract: Computer program products and methods of inspecting a log of security records in a computer network are provided. The method includes retrieving a log record, processing the log record including deriving a key to a table, determining a data value from information in the log record and adding the data value to a list of data values associated with the key if the data value is unique. One or more entries of the table are evaluated based on predetermined criteria to detect attempted security breaches.
    Type: Application
    Filed: September 14, 2012
    Publication date: March 14, 2013
    Applicant: JUNIPER NETWORKS, INC.
    Inventor: Nir ZUK
  • Publication number: 20130067561
    Abstract: Methods, computer program products and apparatus for processing data packets are described. Methods include receiving the data packet, examining the data packet, determining a single flow record associated with the packet and extracting flow instructions for two or more devices from the single flow record.
    Type: Application
    Filed: September 14, 2012
    Publication date: March 14, 2013
    Applicant: Juniper Networks, Inc.
    Inventor: Nir ZUK