IP Library Granted Patent US 10,708,306
Granted Patent B2
US 10,708,306 · App. 15/624,440 · Granted Jul 7, 2020

Mobile user identity and/or SIM-based IoT identity and application identity based security enforcement in service provider networks

Inventors: Sachin Verma (San Jose, CA); Leonid Burakovsky (Pleasanton, CA); Jesse C. Shu (Palo Alto, CA); Lei Chang (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/20H04L63/029H04L63/0236H04L63/0263H04L63/1408H04L63/1433H04W12/00409
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,708,306
App. No.
15/624,440
Granted
Jul 7, 2020
Kind
B2
Abstract

Techniques for mobile user identity and/or SIM-based IoT identity and application identity based security enforcement in service provider networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for mobile user identity and/or SIM-based IOT identity and application identity based security enforcement in service provider networks includes monitoring network traffic on a service provider network at a security platform to identify a subscriber identity for a new session; determining an application identifier for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the subscriber identity and the application identifier.

Claims (66)

1. A system, comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

monitor, in real-time, network traffic on a service provider network at a security platform to identify a subscriber identity for a new session, comprising to:

identify, within the network traffic, a create session request message or a create PDP context request message to create the new session;

identify, within the network traffic, a Radio Access Technology (RAT) type;

extract the subscriber identity from the create session request message or the create PDP context request message, the subscriber identity including International Mobile Subscriber Identity (IMSI); and

extract location from the create session request message or the create PDP context request message, the location including three or more of the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), and LAC (Location Area Identifier);

determine an application identifier for user traffic associated with the new session at the security platform, comprising to:

monitor, via deep packet inspection, tunneled user traffic after the new session has been created to obtain the application identifier, wherein the application identifier relates to web browsing using Hypertext Transfer Protocol (HTTP), a Domain Name System (DNS) request, a file transfer using File Transfer Protocol (FTP), Telnet, Dynamic Host Configuration Protocol (DHCP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Trivial File Transfer Protocol (TFTP), or any combination thereof, and wherein the tunneled user traffic includes GPRS Tunneling Protocol User Plane (GTP-U) traffic;

determine a security policy to apply at the security platform to the new session based on the subscriber identity, the RAT type, the location, and the application identifier, wherein the security policy includes allowing or passing the new session, blocking or dropping the new session, or restricting access of the new session; and

perform threat detection and threat prevention based on the subscriber identity, the RAT type, and the application identifier.

2. The system recited in claim 1 , wherein the security platform is configured with a plurality of security policies based on the subscriber identity and the application identifier.

3. The system recited in claim 1 , wherein the processor is configured to:

perform security policy enforcement based on the subscriber identity and the application identifier.

4. The system recited in claim 1 , wherein the processor is configured to:

perform Uniform Resource Link (URL) filtering based on the subscriber identity and the application identifier.

5. The system recited in claim 1 , wherein the security platform is configured with a plurality of security policies based on the subscriber identity and the application identifier.

6. The system recited in claim 1 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a control protocol and user data traffic in a mobile core network for a 3G and/or 4G network.

7. The system recited in claim 1 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a GPRS Tunneling Protocol (GTP) in a mobile core network for a 3G and/or 4G network.

8. The system recited in claim 1 , wherein the processor is configured to:

block the new session from accessing a resource based on the security policy.

9. The system recited in claim 1 , wherein the location includes four or more of the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), or LAC (Location Area Identifier).

10. The system recited in claim 1 , wherein the location includes the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), and LAC (Location Area Identifier).

11. A method, comprising:

monitoring, in real-time, network traffic on a service provider network at a security platform to identify a subscriber identity for a new session, comprising:

identifying, within the network traffic, a create session request message or a create PDP context request message to create the new session;

identifying, within the network traffic, a Radio Access Technology (RAT) type;

extracting the subscriber identity from the create session request message or the create PDP context request message, the subscriber identity including International Mobile Subscriber Identity (IMSI); and

extracting location from the create session request message or the create PDP context request message, the location including three or more of the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), and LAC (Location Area Identifier);

determining an application identifier for user traffic associated with the new session at the security platform, comprising:

monitoring, via deep packet inspection, tunneled user traffic after the new session has been created to obtain the application identifier, wherein the application identifier relates to web browsing using HyperText Transfer Protocol (HTTP), a Domain Name System (DNS) request, a file transfer using File Transfer Protocol (FTP), Telnet, Dynamic Host Configuration Protocol (DHCP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Trivial File Transfer Protocol (TFTP), or any combination thereof, and wherein the tunneled user traffic includes GPRS Tunneling Protocol User Plane (GTP-U) traffic;

determining a security policy to apply at the security platform to the new session based on the subscriber identity, the RAT type, the location, and the application identifier, wherein the security policy includes allowing or passing the new session, blocking or dropping the new session, or restricting access of the new session; and

performing threat detection and threat prevention based on the subscriber identity, the RAT type, and the application identifier.

12. The method of claim 11 , wherein the security platform is configured with a plurality of security policies based on the subscriber identity and the application identifier.

13. The method of claim 11 , further comprising:

performing security policy enforcement based on the subscriber identity and the application identifier.

14. The method of claim 11 , further comprising:

performing Uniform Resource Link (URL) filtering based on the subscriber identity and the application identifier.

15. The method of claim 11 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a control protocol and user data traffic in a mobile core network for a 3G and/or 4G network.

16. The method of claim 11 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a GPRS Tunneling Protocol (GTP) in a mobile core network for a 3G and/or 4G network.

17. The method of claim 11 , further comprising:

block the new session from accessing a resource based on the security policy.

18. The method of claim 11 , wherein the location includes four or more of the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), or LAC (Location Area Identifier).

19. The method of claim 11 , wherein the location includes the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), and LAC (Location Area Identifier).

20. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

monitoring, in real-time, network traffic on a service provider network at a security platform to identify a subscriber identity for a new session, comprising:

identifying, within the network traffic, a create session request message or a create PDP context request message to create the new session;

identifying, within the network traffic, a Radio Access Technology (RAT) type;

extracting the subscriber identity from the create session request message or the create PDP context request message, the subscriber identity including International Mobile Subscriber Identity (IMSI); and

extracting location from the create session request message or the create PDP context request message, the location including three or more of the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), and LAC (Location Area Identifier);

determining an application identifier for user traffic associated with the new session at the security platform, comprising:

monitoring, via deep packet inspection, tunneled user traffic after the new session has been created to obtain the application identifier, wherein the application identifier relates to web browsing using HyperText Transfer Protocol (HTTP), a Domain Name System (DNS) request, a file transfer using File Transfer Protocol (FTP), Telnet, Dynamic Host Configuration Protocol (DHCP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Trivial File Transfer Protocol (TFTP), or any combination thereof, and wherein the tunneled user traffic includes GPRS Tunneling Protocol User Plane (GTP-U) traffic;

determining a security policy to apply at the security platform to the new session based on the subscriber identity, the RAT type, the location, and the application identifier, wherein the security policy includes allowing or passing the new session, blocking or dropping the new session, or restricting access of the new session; and

performing threat detection and threat prevention based on the subscriber identity, the RAT type, and the application identifier.

21. The computer program product recited in claim 20 , wherein the security platform is configured with a plurality of security policies based on the subscriber identity and the application identifier.

22. The computer program product recited in claim 20 , further comprising computer instructions for:

performing security policy enforcement based on the subscriber identity and the application identifier.

23. The computer program product recited in claim 20 , further comprising computer instructions for:

performing Uniform Resource Link (URL) filtering based on the subscriber identity and the application identifier.

24. The computer program product recited in claim 20 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a control protocol and user data traffic in a mobile core network for a 3G and/or 4G network.

25. The computer program product recited in claim 20 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a GPRS Tunneling Protocol (GTP) in a mobile core network for a 3G and/or 4G network.

26. The computer program product recited in claim 20 , further comprising computer instructions for:

block the new session from accessing a resource based on the security policy.

27. The computer program product recited in claim 20 , wherein the location includes four or more of the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), or LAC (Location Area Identifier).

28. The computer program product recited in claim 20 , wherein the location includes the following: CGI (Cell Global Identifier), SAI (Service Area Identifier), RAI (Routing Area Identifier), TAI (Tracking Area Identifier), ECGI (E-UTRAN Cell Global Identifier), and LAC (Location Area Identifier).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: VERMA, SACHIN; BURAKOVSKY, LEONID; SHU, JESSE C.; CHANG, LEI
To: PALO ALTO NETWORKS, INC.
Reel/Frame 043460/0720 →
Continuity (1)
Related Publication 20180367571A1 · Dec 20, 2018