IP Library › Granted Patent US 12,075,249
Granted Patent B2
US 12,075,249 · App. 17/013,802 · Granted Aug 27, 2024

Controlling wi-fi traffic from network applications with centralized firewall rules implemented at the edge of a data communication network

Inventor: Ravikiran Mahamkali (Bangalore, IN)
Assignee: Fortinet, Inc.
H04W12/088H04L63/0263H04W12/121H04W28/0215H04W48/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,075,249
App. No.
17/013,802
Granted
Aug 27, 2024
Kind
B2
Abstract

Application data collected by an IDS (intrusion detection system) on the data communication network and concerning applications executing on stations coupled to the plurality of access points, is received. Additionally, firewall rules for applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points, are received. The firewall rules can be parsed to expose configured actions for applications. A customized application control policy is prepared for each particular application for implementation on the network edge by at least one of the plurality of access points.

Claims (36)

1. A computer-implemented method, in a Wi-Fi controller on a data communication network, for improving computer network security by implementing security policies of a firewall device locally at a plurality of access points, the method comprising the steps of:

receiving application data collected by an IDS (intrusion detection system) on the data communication network and concerning a plurality of applications executing on each station coupled to the plurality of access points;

receiving firewall rules for the plurality of applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points;

parsing the firewall rules to expose configured actions for the plurality of applications;

preparing a customized application control policy for each particular application for implementation by at least one of the plurality of access points, wherein the customized application policy concerns how the at least one access point prioritizes network traffic for DPI (deep packet inspection) for data packets for a specific application of the plurality of applications of a station based on the firewall rules and application data for the specific application; and

distributing customized application control policies to the plurality access points based on application traffic handled by each access point.

2. The method of claim 1 , further wherein the configured actions comprise one or more of monitor, block, and quarantine.

3. The method of claim 1 , further comprising:

receiving application information from an IPS (intrusion prevention system), the application information comprising at least one of application risk and application popularity.

4. The method of claim 1 , wherein the access point applies the firewall rules against a data packet, and responsive to the firewall rules, drops the data packet before reaching the firewall device.

5. The method of claim 1 , wherein the network applications is categorized as either high risk or low risk, wherein data packets from high risk applications are prioritized for processing over data packets from low risk applications.

6. The method of claim 1 , further comprising:

updating the firewall rules for applications and updating customized application control polices that are affected.

7. The method of claim 1 , further comprising:

providing less AirTime in a packet prioritization scheme for high risk applications relative to low risk applications.

8. The method of claim 1 , further comprising:

dropping one or more packets at the access point based on firewall rules.

9. The method of claim 1 , further comprising:

dropping one or more packets at the Wi-Fi controller based on firewall rules.

10. The method of claim 1 , further comprising:

dropping one or more packets based on an application generating the traffic.

11. A non-transitory computer-readable medium storing source code that, when executed by a processor, performs a computer-implemented method, in a Wi-Fi controller on a data communication network and implemented at least partially in hardware, for improving computer network security by implementing security policies of a firewall device locally at a plurality of access points, the method comprising the steps of:

receiving application data collected by an IDS (intrusion detection system) on the data communication network and concerning a plurality of applications executing on each station coupled to the plurality of access points;

receiving firewall rules for the plurality of applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points;

parsing the firewall rules to expose configured actions for the plurality of applications;

preparing a customized application control policy for each particular application for implementation by at least one of the plurality of access points, wherein the customized application policy concerns how the at least one access point prioritizes network traffic for DPI (deep packet inspection) for data packets for a specific application of the plurality of applications of a station based on the firewall rules and application data for the specific application; and

distributing customized application control policies to the plurality access points based on application traffic handled by each access point.

12. A Wi-Fi controller on a data communication network and implemented at least partially in hardware, for improving computer network security by implementing security policies of a firewall device locally at a plurality of access points, the Wi-Fi controller comprising:

a processor;

a network interface, communicatively coupled to the processor; and

a memory, communicatively coupled to the processor and storing source code, comprising:

a first module to receive application data collected by an IDS (intrusion detection system) on the data communication network and concerning plurality of applications executing on each station coupled to the plurality of access points;

a second module to receive firewall rules for the plurality of applications from a firewall device coupled to the data communication network and providing firewall services to the plurality of access points, including outbound traffic from the plurality of access points;

a third module to parse the firewall rules to expose configured actions for the plurality of applications;

a fourth module to prepare a customized application control policy for each particular application for implementation by at least one of the plurality of access points, wherein the customized application policy concerns how the at least one access point prioritizes network traffic for DPI (deep packet inspection) for data packets for a specific application of the plurality of applications of a station based on the firewall rules and application data for the specific application; and

a fifth module to distribute customized application control policies to the plurality access points based on application traffic handled by each access point.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2020
From: MAHAMKALI, RAVIKIRAN
To: FORTINET, INC.
Reel/Frame 053728/0341 →
Continuity (1)
Related Publication 20220078619A1 · Mar 10, 2022