IP Library Granted Patent US 12,593,210
Granted Patent B2
US 12,593,210 · App. 18/892,136 · Granted Mar 31, 2026

Dynamic security policy generation and recommendation for sim-based clientless sase

Inventors: Kallol Banerjee (San Jose, CA); Harsh Pandey (Santa Clara, CA); Bryan D. Black (Norton Shores, MI); Jonathan Bosanac (Ennis, MT)
Assignee: Netskope, Inc.
H04W12/088H04W12/122
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,593,210
App. No.
18/892,136
Filed
Sep 20, 2024
Granted
Mar 31, 2026
Kind
B2
Art Unit
2492
USPC
726/1
Abstract

A dynamic security system to secure cellular devices across a cellular network in a cloud-based environment. The dynamic security system includes a tenant of multiple tenants having multiple cellular devices, a tunnel, a traffic steering module, and a threat management module. The tunnel transmits and identifies traffic associated with different network identifiers. The traffic steering module routes traffic towards gateways and the threat management module analyzes traffic at the tunnel and generates policies and recommendations to remediate a threat. The threat management module intercepts traffic within the tunnel at an application layer of the cloud-based environment, creates policy profiles for tenants, monitors a threat landscape, and relates the threat with the policy profiles. The threat management module further stores tenant profiles, threat information, and policy profiles. Finally, the threat management module generates recommendations based on these profiles and provides recommendations at the cellular device to remediate the threat.

Claims (55)

1 . A dynamic security system to secure a plurality of cellular devices across a cellular network in a cloud-based environment, the dynamic security system comprises:

a tenant of a plurality of tenants using a plurality of cellular networks, the tenant includes the plurality of cellular devices;

a tunnel between a cellular device of the plurality of cellular devices and the cellular network, the tunnel is operable to:

transmit traffic from the cellular device of the plurality of cellular devices at the cellular network; and

identify traffic associated with a plurality of network identifiers;

a traffic steering module to route traffic towards a gateway of a plurality of gateways in the cloud-based environment; and

a threat management module to analyze traffic at the tunnel and to generate a plurality of policies and a plurality of recommendations or remediation actions to remediate a threat, the threat management module is operable to:

intercept traffic within the tunnel at an application layer of the cloud-based environment;

create a plurality of policy profiles for the plurality of tenants at the cellular network;

monitor a threat landscape of the cellular network and correlate the threat with the plurality of policy profiles;

store a plurality of tenant profiles, a plurality of threat information, and the plurality of policy profiles; and

based on the plurality of tenant profiles, the plurality of policy profiles, geo-location of the cellular device, and historical data of the plurality of policies, generate the plurality of recommendations or remediation actions and provide the plurality of recommendations or remediation actions at the cellular device to remediate the threat, wherein the plurality of recommendations or remediation actions are provided as options in a prioritized sequence, with top options being emphasized for user selection.

2 . The dynamic security system of claim 1 , wherein the plurality of recommendations is based on a plurality of updated policies, the plurality of policy profiles, and a plurality of user preferences.

3 . The dynamic security system of claim 1 , wherein a custom network identifier is used for traffic segregation in the cellular network to provide clientless security and the custom network identifier is an access point name (APN) for a 4G network and a data network name (DNN) for a 5G network.

4 . The dynamic security system of claim 1 , wherein the plurality of policies defines a plurality of inline security functions and access controls based on the tenant and a device identity.

5 . The dynamic security system of claim 1 , wherein the threat management module auto-applies a recommendation of the plurality of recommendations at the cellular device when a user of the cellular device is not selecting the recommendation of the plurality of recommendations.

6 . The dynamic security system of claim 1 , wherein feedback from a user of the cellular device and an update in a policy of the plurality of policies are used to train a machine learning module of the threat management module.

7 . The dynamic security system of claim 1 , wherein remediation in case of detection of violation of a policy of the plurality of policies includes:

blocking a corresponding traffic;

quarantining the cellular device of the plurality of cellular devices; and

allowing limited connectivity to the cellular device of the plurality of cellular devices.

8 . A dynamic security method for securing a plurality of cellular devices across a cellular network in a cloud-based environment, the dynamic security method comprises:

transmitting traffic from a cellular device of the plurality of cellular devices at the cellular network via a tunnel;

identifying traffic associated with a plurality of network identifiers;

routing traffic towards a gateway of a plurality of gateways in the cloud-based environment; and

analyzing traffic at the tunnel and generating a plurality of policies and a plurality of recommendations or remediation actions to remediate a threat via a threat management module, the threat management module is operable to:

intercept traffic within the tunnel at an application layer of the cloud-based environment;

create a plurality of policy profiles for a plurality of tenants at the cellular network;

monitor a threat landscape of the cellular network and relating the threat with the plurality of policy profiles;

store a plurality of tenant profiles, a plurality of threat information, and the plurality of policy profiles; and

based on the plurality of tenant profiles, the plurality of policy profiles, geo-location of the cellular device, and historical data of the plurality of policies, generate the plurality of recommendations or remediation actions and provide the plurality of recommendations or remediation actions at the cellular device to remediate the threat, wherein the plurality of recommendations or remediation actions are provided as options in a prioritized sequence, with top options being emphasized for user selection.

9 . The dynamic security method of claim 8 , wherein the plurality of recommendations is based on a plurality of updated policies, the plurality of policy profiles, and a plurality of user preferences.

10 . The dynamic security method of claim 8 , wherein a custom network identifier is used for traffic segregation in the cellular network to provide clientless security and the custom network identifier is an access point name (APN) for a 4G network and a data network name (DNN) for a 5G network.

11 . The dynamic security method of claim 8 , wherein the plurality of policies defines a plurality of inline security functions and access controls based on a tenant and a device identity.

12 . The dynamic security method of claim 8 , wherein the threat management module auto-applies a recommendation of the plurality of recommendations at the cellular device when a user of the cellular device is not selecting the recommendation of the plurality of recommendations.

13 . The dynamic security method of claim 8 , wherein feedback from a user of the cellular device and an update in a policy of the plurality of policies are used to train a machine learning module of the threat management module.

14 . The dynamic security method of claim 8 , wherein remediation in case of detection of violation of a policy of the plurality of policies includes:

blocking a corresponding traffic;

quarantining the cellular device of the plurality of cellular devices; and

allowing limited connectivity to the cellular device of the plurality of cellular devices.

15 . A non-transitory computer-readable storage medium having computer-executable instructions embodied thereon that, when executed by one or more processors, facilitate a dynamic security method for securing a plurality of cellular devices across a cellular network in a cloud-based environment, the non-transitory computer-readable storage medium comprises:

transmitting traffic from a cellular device of the plurality of cellular devices at the cellular network via a tunnel;

identifying traffic associated with a plurality of network identifiers;

routing traffic towards a gateway of a plurality of gateways in the cloud-based environment; and

analyzing traffic at the tunnel and generating a plurality of policies and a plurality of recommendations or remediation actions to remediate a threat via a threat management module, the threat management module is operable to:

intercept traffic within the tunnel at an application layer of the cloud-based environment;

create a plurality of policy profiles for a plurality of tenants at the cellular network;

monitor a threat landscape of the cellular network and relating the threat with the plurality of policy profiles;

store a plurality of tenant profiles, a plurality of threat information, and the plurality of policy profiles; and

based on the plurality of tenant profiles, the plurality of policy profiles, geo-location of the cellular device, and historical data of the plurality of policies, generate the plurality of recommendations or remediation actions and provide the plurality of recommendations or remediation actions at the cellular device to remediate the threat, wherein the plurality of recommendations or remediation actions are provided as options in a prioritized sequence, with top options of the prioritized sequence being emphasized for user selection.

16 . The computer-readable media of claim 15 , wherein the plurality of recommendations is based on a plurality of updated policies, the plurality of policy profiles, and a plurality of user preferences.

17 . The computer-readable media of claim 15 , wherein a custom network identifier is used for traffic segregation in the cellular network to provide clientless security and the custom network identifier is an access point name (APN) for a 4G network and a data network name (DNN) for a 5G network.

18 . The computer-readable media of claim 15 , wherein the plurality of policies defines a plurality of inline security functions and access controls based on a tenant and a device identity.

19 . The computer-readable media of claim 15 , wherein the threat management module auto-applies a recommendation of the plurality of recommendations at the cellular device when a user of the cellular device is not selecting the recommendation of the plurality of recommendations.

20 . The computer-readable media of claim 15 , wherein feedback from a user of the cellular device and an update in a policy of the plurality of policies are used to train a machine learning module of the threat management module.

Continuity (1)
Related Publication 20260089509A1 · Mar 26, 2026
References Cited (151)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8069483B1 · Matlock · 2011 [cited by examiner]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8464335B1 · Sinha et al. · 2013 [cited by applicant]
US 8713628B2 · Kopti · 2014 [cited by applicant]
US 8726338B2 · Narayanaswamy et al. · 2014 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 8892766B1 · Wei et al. · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 9948606B2 · Shaikh et al. · 2018 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10250624B2 · Mixer · 2019 [cited by examiner]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10587644B1 · Stolte · 2020 [cited by examiner]
US 10616072B1 · Lo · 2020 [cited by examiner]
US 10620241B2 · Pietrowicz · 2020 [cited by examiner]
US 10749907B2 · Sinha et al. · 2020 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 10834596B2 · Choi · 2020 [cited by examiner]
US 10893066B1 · Oliphant · 2021 [cited by examiner]
US 10938743B1 · Andrews · 2021 [cited by examiner]
US 10938850B2 · Tamir · 2021 [cited by examiner]
US 11012475B2 · Patnala et al. · 2021 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11316901B1 · Li et al. · 2022 [cited by applicant]
US 11323884B2 · Lifshitz · 2022 [cited by examiner]
US 11388175B2 · Pularikkal et al. · 2022 [cited by applicant]
US 11399276B2 · Weinberg et al. · 2022 [cited by applicant]
US 11516222B1 · Srinivasan · 2022 [cited by examiner]
US 11743298B1 · Badana · 2023 [cited by examiner]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060010497A1 · O'Brien · 2006 [cited by examiner]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070094735A1 · Cohen · 2007 [cited by examiner]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090205016A1 · Milas · 2009 [cited by examiner]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120216243A1 · Gill · 2012 [cited by examiner]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140237545A1 · Mylavarapu · 2014 [cited by examiner]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160269447A1 · Kailash et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170230402A1 · Greenspan · 2017 [cited by examiner]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170331859A1 · Bansal et al. · 2017 [cited by applicant]
US 20190026094A1 · Stammers · 2019 [cited by examiner]
US 20190222612A1 · Nainar et al. · 2019 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200329055A1 · Tyagi · 2020 [cited by examiner]
US 20210266348A1 · Manor · 2021 [cited by examiner]
US 20220019671A1 · Boone · 2022 [cited by examiner]
US 20220094600A1 · Khoo · 2022 [cited by examiner]
US 20220131759A1 · Boon · 2022 [cited by examiner]
US 20220166755A1 · Moore et al. · 2022 [cited by applicant]
US 20220224707A1 · Kapoor · 2022 [cited by examiner]
US 20220269817A1 · Nalluri · 2022 [cited by examiner]
US 20220350634A1 · Nenov · 2022 [cited by examiner]
US 20230164191A1 · Williams · 2023 [cited by applicant]
US 20230344797A1 · Filatov et al. · 2023 [cited by applicant]
US 20230370847A1 · Kim · 2023 [cited by examiner]
US 20240031411A1 · Levari · 2024 [cited by examiner]
EP 1063833A2 · 2000 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Nevvton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-US/newsroom/press-releases/2016/fortin… [cited by applicant]
Mccullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al. “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al. , Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” Tech Target, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?%20Offe… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1 , Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/%2010.1007/978-3-319… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al. “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&p. 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs,. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management for Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]