IP Library Granted Patent US 10,826,941
Granted Patent B2
US 10,826,941 · App. 16/023,388 · Granted Nov 3, 2020

Systems and methods for centrally managed host and network firewall services

Inventors: Anurag Jain (Edison, NJ); Kenneth Ammon (Leesburg, VA); Thomas Cross (Atlanta, GA); Michael C. Starr (Reston, VA)
Assignee: Fortinet, Inc.
H04L63/20H04L63/0245H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,826,941
App. No.
16/023,388
Granted
Nov 3, 2020
Kind
B2
Abstract

A method for protecting an enterprise network includes, at a system that is remote from the enterprise network: controlling communications to and from the enterprise network according to a set of security policies; controlling endpoint to endpoint connections within the enterprise network according to the set of security policies; receiving a request for modifications to the set of policies; automatically generating a policy digest formatted according to a predefined format, the policy digest comprising the modifications, and storing the policy digest in the memory; retrieving the policy digest from the memory; generating one or more calls to one or more system components that control the communications to and from the enterprise network and the endpoint to endpoint connections based on the policy digest; and modifying control of the communications and the endpoint to endpoint connections based on the one or more calls.

Claims (36)

1. A method for protecting an enterprise network, the method comprising, at a system comprising one or more processors and memory that are remote from the enterprise network:

controlling communications to and from the enterprise network according to a set of security policies;

controlling endpoint to endpoint connections within the enterprise network according to the set of security policies;

receiving a request for modifications to one or more policies of the set of policies;

automatically generating a policy digest formatted according to a predefined format, the policy digest comprising the modifications, and storing the policy digest in the memory;

retrieving the policy digest from the memory;

generating one or more calls to one or more system components that control the communications to and from the enterprise network and the endpoint to endpoint connections based on the policy digest; and

modifying control of the communications to and from the enterprise network and the endpoint to endpoint connections based on the one or more calls.

2. The method of claim 1 , wherein the request for modifications is based on selections made by a user via a user interface.

3. The method of claim 1 , wherein the communications for the enterprise network is routed through one or more perimeter points of presence and the one or more calls are one or more calls for modification of a security stack implemented by the one or more perimeter points of presence.

4. The method of claim 1 , wherein the policy digest comprises one or more of an inbound network traffic policy modification, an outbound network traffic policy modification, and an internal network traffic policy modification.

5. The method of claim 1 , wherein the policy digest is retrieved according to a predefined schedule.

6. The method of claim 1 , wherein the policy digest is retrieved by a daemon service that generates the one or more calls to the one or more system components.

7. The method of claim 6 , wherein the policy digest is stored in a memory location for a portal process and the daemon service initiates a connection to the portal process for retrieving the policy digest.

8. The method of claim 7 , wherein the portal process is prevented from initiating a connection with the daemon service.

9. The method of claim 1 , wherein prior to generating one or more calls to one or more system components, the policy digest is checked for adherence to the predefined format.

10. The method of claim 1 , wherein controlling endpoint to endpoint connections comprises receiving connection escalation requests from endpoint agents and replying to the connection escalation requests with responses that include actions for handling connections that are based on the set of policies.

11. The method of claim 10 , wherein a connection escalation request comprises a request from an endpoint agent running on a first endpoint of the enterprise network for approval to accept a connection request from a second endpoint and a response comprises an instruction to the first endpoint to accept or deny the connection request from the second endpoint of the enterprise network.

12. A system for protecting an enterprise network that is remote from the system, the system comprising one or more processors, memory, and one or more programs stored in the memory and executable by the one or more processors for:

controlling communications to and from the enterprise network according to a set of security policies;

controlling endpoint to endpoint connections within the enterprise network according to the set of security policies;

receiving a request for modifications to one or more policies of the set of policies;

automatically generating a policy digest formatted according to a predefined format, the policy digest comprising the modifications, and storing the policy digest in the memory;

retrieving the policy digest from the memory;

generating one or more calls to one or more system components that control the communications to and from the enterprise network and the endpoint to endpoint connections based on the policy digest; and

modifying control of the communications to and from the enterprise network and the endpoint to endpoint connections based on the one or more calls.

13. The system of claim 12 , wherein the request for modifications is based on selections made by a user via a user interface.

14. The system of claim 12 , wherein the communications for the enterprise network is routed through one or more perimeter points of presence and the one or more calls are one or more calls for modification of a security stack implemented by the one or more perimeter points of presence.

15. The system of claim 12 , wherein the policy digest comprises one or more of an inbound network traffic policy modification, an outbound network traffic policy modification, and an internal network traffic policy modification.

16. The system of claim 12 , wherein the policy digest is retrieved according to a predefined schedule.

17. The system of claim 12 , wherein the policy digest is retrieved by a daemon service that generates the one or more calls to the one or more system components.

18. The system of claim 17 , wherein the policy digest is stored in a memory location for a portal process and the daemon service initiates a connection to the portal process for retrieving the policy digest.

19. The system of claim 18 , wherein the portal process is prevented from initiating a connection with the daemon service.

20. The system of claim 12 , wherein prior to generating one or more calls to one or more system components, the policy digest is checked for adherence to the predefined format.

21. The system of claim 12 , wherein controlling endpoint to endpoint connections comprises receiving connection escalation requests from endpoint agents and replying to the connection escalation requests with responses that comprise actions for handling connections that are based on the set of policies.

22. The system of claim 21 , wherein a connection escalation request comprises a request from an endpoint agent running on a first endpoint of the enterprise network for approval to accept a connection request from a second endpoint and a response comprises an instruction to the first endpoint to accept or deny the connection request from the second endpoint of the enterprise network.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2020
From: STARR, MICHAEL C.
To: FORTINET, INC.
Reel/Frame 053764/0504 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2020
From: OPAQ NETWORKS, INC.
To: FORTINET, INC.
Reel/Frame 053613/0746 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2018
From: JAIN, ANURAG; AMMON, KENNETH; CROSS, THOMAS
To: OPAQ NETWORKS, INC
Reel/Frame 046329/0139 →
Continuity (2)
Provisional Application 62669544 · May 10, 2018
Related Publication 20190349404A1 · Nov 14, 2019
Cited By (77)
US 12,197,583 US 12,197,590 US 12,206,698 US 12,219,360 US 12,225,039 US 12,231,433 US 12,235,962 US 12,238,177 US 12,242,520 US 12,243,294 US 12,244,617 US 12,244,626 US 12,244,637 US 12,245,036 US 12,250,221 US 12,255,877 US 12,259,967 US 12,261,884 US 12,266,209 US 12,267,355 US 12,273,392 US 12,278,845 US 12,282,545 US 12,284,206 US 12,284,222 US 12,299,117 US 12,301,605 US 12,315,231 US 12,316,647 US 12,326,957 US 12,341,814 US 12,355,817 US 12,361,680 US 12,363,151 US 12,373,240 US 12,375,497 US 12,388,711 US 12,395,534 US 12,413,629 US 12,417,253 US 12,418,565 US 12,423,078 US 12,425,464 US 12,430,429 US 12,432,253 US 12,445,451 US 12,450,351 US 12,452,273 US 12,452,310 US 12,468,810 US 12,470,602 US 12,489,734 US 12,500,940 US 12,513,073 US 12,519,857 US 12,537,838 US 12,537,871 US 12,542,812 US 12,561,620 US 12,572,651 US 12,579,268 US 12,580,945 US 12,580,960 US 12,592,959 US 12,593,210 US 12,596,804 US 12,598,216 US 12,615,242 US 12,632,572 US 12,647,362 US 12,664,258 US 12,676,908 US 12,684,018 US 12,695,765 US 12,712,920 US 12,724,771 US 12,739,263