IP Library › Granted Patent US 11,785,048
Granted Patent B2
US 11,785,048 · App. 17/086,191 · Granted Oct 10, 2023

Consistent monitoring and analytics for security insights for network and security functions for a security service

Inventors: Anand Oswal (Pleasanton, CA); Arivu Mani Ramasamy (San Jose, CA); Kumar Ramachandran (Pleasanton, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/20H04L63/029H04L63/101H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,785,048
App. No.
17/086,191
Granted
Oct 10, 2023
Kind
B2
Abstract

Techniques for providing consistent monitoring and analytics for security insights for network and security functions for a security service are disclosed. In some embodiments, a system/process/computer program product for providing consistent monitoring and analytics for security insights for network and security functions for a security service includes receiving a flow at a software-defined wide area network (SD-WAN) device; inspecting the flow to determine whether the flow is associated with a split tunnel; and monitoring the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service.

Claims (55)

1. A system comprising:

a processor configured to:

receive a flow at a software-defined wide area network (SD-WAN) device;

analyze the flow to determine whether the flow is associated with a split tunnel, comprising to:

extract meta data information associated with one flow of the flow without performing deep packet inspection to independently determine the meta data information, wherein the meta data information includes one or more of the following: an application identifier (APP ID), User ID, Device ID, and/or Content ID;

compare the extracted meta data information with meta data information associated with a whitelist policy; and

in the event that the extracted meta data information matches the meta data information associated with the whitelist policy, determine that the one flow is associated with the split tunnel; and

monitor the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the flow is associated with the whitelist policy and is allowed to bypass the security service based on a security policy.

3. The system recited in claim 1 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy.

4. The system recited in claim 1 , wherein the processor is further configured to:

communicate the collected security information associated with the flow to the security service after a session associated with the flow is ended.

5. The system recited in claim 1 , wherein the processor is further configured to:

periodically communicate the collected security information associated with the flow to the security service.

6. The system recited in claim 1 , wherein the collected security information associated with the flow includes an ingress IP address, an egress IP address, an ingress port number, an egress port number, a protocol, and session data usage and time related statistics.

7. The system recited in claim 1 , wherein the security service is a cloud-based security service.

8. The system recited in claim 1 , wherein the security service is a cloud-based security service that is provided using a public cloud service provider.

9. The system recited in claim 1 , wherein the security service is a cloud-based security service that is provided using a plurality of public cloud service providers.

10. The system recited in claim 1 , wherein another flow is a site to site tunnel that bypasses the security service, and wherein the SD-WAN device collects security information associated with the another flow for reporting to the security service.

11. A method comprising:

receiving a flow at a software-defined wide area network (SD-WAN) device;

analyzing the flow to determine whether the flow is associated with a split tunnel, comprising:

extracting meta data information associated with one flow of the flow without performing deep packet inspection to independently determine the meta data information, wherein the meta data information includes one or more of the following: an application identifier (APP ID), User ID, Device ID, and/or Content ID;

comparing the extracted meta data information with meta data information associated with a whitelist policy; and

in the event that the extracted meta data information matches the meta data information associated with the whitelist policy, determining that the one flow is associated with the split tunnel; and

monitoring the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service.

12. The method of claim 11 , wherein the flow is associated with the whitelist policy and is allowed to bypass the security service based on a security policy.

13. The method of claim 11 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy.

14. The method of claim 11 , further comprising:

communicating the collected security information associated with the flow to the security service after a session associated with the flow is ended.

15. The method of claim 11 , further comprising:

periodically communicating the collected security information associated with the flow to the security service.

16. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving a flow at a software-defined wide area network (SD-WAN) device;

analyzing the flow to determine whether the flow is associated with a split tunnel, comprising:

extracting meta data information associated with one flow of the flow without performing deep packet inspection to independently determine the meta data information, wherein the meta data information includes one or more of the following: an application identifier (APP ID), User ID, Device ID, and/or Content ID;

comparing the extracted meta data information with meta data information associated with a whitelist policy; and

in the event that the extracted meta data information matches the meta data information associated with the whitelist policy, determining that the one flow is associated with the split tunnel; and

monitoring the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service.

17. The computer program product recited in claim 16 , wherein the flow is associated with the whitelist policy and is allowed to bypass the security service based on a security policy.

18. The computer program product recited in claim 16 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy.

19. The computer program product recited in claim 16 , further comprising computer instructions for:

communicating the collected security information associated with the flow to the security service after a session associated with the flow is ended.

20. The computer program product recited in claim 16 , further comprising computer instructions for:

periodically communicating the collected security information associated with the flow to the security service.

21. A system comprising:

a processor configured to:

receive a flow at a software-defined wide area network (SD-WAN) device;

analyze the flow to determine whether the flow is associated with a split tunnel, comprising to:

extract meta data information associated with one flow of the flow without performing deep packet inspection to independently determine the meta data information, wherein the meta data information includes one or more of the following: an application identifier (APP ID), User ID, Device ID, and/or Content ID;

compare the extracted meta data information with meta data information associated with a whitelist policy; and

in the event that the extracted meta data information matches the meta data information associated with the whitelist policy, determine that the one flow is associated with the split tunnel; and

mirror the flow from the SD-WAN device to a security service, wherein the security service monitors the flow mirrored from the SD-WAN device to collect security information associated with the flow for reporting; and

a memory coupled to the processor and configured to provide the processor with instructions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2021
From: OSWAL, ANAND; RAMASAMY, ARIVU MANI; RAMACHANDRAN, KUMAR
To: PALO ALTO NETWORKS, INC.
Reel/Frame 055105/0527 →
Continuity (1)
Related Publication 20220141254A1 · May 5, 2022