IP Library › Granted Patent US 12,627,667
Granted Patent B2
US 12,627,667 · App. 17/397,386 · Granted May 12, 2026

Systems and methods for resilient ZTNA micro-segmentation policy generation

Inventors: Rajiv Sreedhar (Sunnyvale, CA); Manuel Nedbal (Santa Clara, CA); Damodar K. Hegde (Santa Clara, CA); Jitendra B. Gaitonde (Cupertino, CA); Manoj Ahluwalia (San Jose, CA); Latha Krishnamurthi (San Jose, CA); Rajeshwari Rao (Princeton, NJ)
Assignee: Fortinet, Inc.
H04L63/101H04L43/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,667
App. No.
17/397,386
Filed
Aug 9, 2021
Granted
May 12, 2026
Kind
B2
Art Unit
2447
USPC
709/224
Abstract

Systems, devices, and methods are discussed for determining zero trust network access policy based upon intent defined groups of workloads.

Claims (49)

1 . A method for resilient access control list development, the method comprising:

identifying, by a processing resource, a first set of workloads in a set of network traffic that share at least a first trait, and a second set of workloads in the set of network traffic that share at least a second trait;

identifying, by the processing resource, a first suggested intent of the first set of workloads based upon metadata associated with the first set of workloads;

identifying, by the processing resource, a second suggested intent of the second set of workloads based upon metadata associated with the second set of workloads;

consolidating, by the processing resource, a plurality of network ports of the first set of workloads based at least in part on a network element associated with the first set of workloads into a set of network ports, wherein a given network port of the plurality of network ports is associated with a particular network protocol that transmits communication for a specific service between a traffic source and a traffic destination;

consolidating further, by the processing resource, ports from the plurality of network ports into ranges of ports used for an application, wherein ports from the plurality of network ports are consolidated with similar workloads;

receiving, by the processing resource, an access control list including at least a first access control rule allowing defined activity over multiple network ports, and second access control rule allowing defined activity for workloads having the first suggested intent, and a third access control rule allowing defined activity for workloads having the second suggested intent; and

forward testing, by the processing resource, the access control list comprising the first access control rule, the second access control rule, and the third access control rule, at an application-level of granularity, wherein the access control list is forward tested after the addition of each application and only the most recently added application has not been fully secured.

2 . The method of claim 1 , wherein identifying the first set of workloads in the set of network traffic and the second set of workloads in the set of network traffic includes eliminating network traffic corresponding to a scanner.

3 . The method of claim 1 , wherein identifying the first set of workloads in the set of network traffic and the second set of workloads in the set of network traffic includes eliminating incomplete workflows.

4 . The method of claim 3 , wherein the incomplete workflows are associated with a scanner accessing a closed port.

5 . The method of claim 3 , wherein the incomplete workflows are associated with a scanner accessing an open port and failing to respond to an acknowledgment returned from the open port.

6 . The method of claim 1 , the method further comprising: monitoring, by the processing resource, network activity to yield the set of network traffic.

7 . The method of claim 6 , wherein monitoring network activity to yield the set of network traffic is done such that the network traffic does not include any traffic corresponding to a scanner or any incomplete workflows.

8 . The method of claim 1 , wherein the multiple network ports are selected from a group consisting of: a set of continuous network ports, and a set of discontinuous network ports.

9 . The method of claim 1 , the method further comprising:

modifying, by the processing resource, a default rule of the access control list from allow to block; and

deploying, by the processing resource, the access control list.

10 . The method of claim 1 , wherein the method further comprises: dynamically adding one of the plurality of network ports of the first set of workloads based upon a negotiation of a control channel.

11 . A network appliance, the network appliance comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:

identify a first set of workloads in a set of network traffic that share at least a first trait, and a second set of workloads in the set of network traffic that share at least a second trait;

identify a first suggested intent of the first set of workloads based upon metadata associated with the first set of workloads;

identify a second suggested intent of the second set of workloads based upon metadata associated with the second set of workloads;

consolidate a plurality of network ports of the first set of workloads based at least in part on a network element associated with the first set of workloads into a set of network ports, wherein a given network port of the plurality of network ports is associated with a particular network protocol that transmits communication for a specific service between a traffic source and a traffic destination;

consolidate further ports from the plurality of network ports into ranges of ports used for an application, wherein ports from the plurality of network ports are consolidated with similar workloads;

receive an access control list including at least a first access control rule allowing defined activity over multiple network ports, and second access control rule allowing defined activity for workloads having the first suggested intent, and a third access control rule allowing defined activity for workloads having the second suggested intent; and

forward test the access control list comprising the first access control rule, the second access control rule, and the third access control rule at an application-level of granularity, wherein the access control list is forward tested after the addition of each application and only the most recently added application has not been fully secured.

12 . The network appliance of claim 11 , wherein identifying the first set of workloads in the set of network traffic and the second set of workloads in the set of network traffic includes eliminating network traffic corresponding to a scanner.

13 . The network appliance of claim 11 , wherein identifying the first set of workloads in the set of network traffic and the second set of workloads in the set of network traffic includes eliminating incomplete workflows.

14 . The network appliance of claim 13 , wherein the incomplete workflows are associated with a scanner accessing a closed port.

15 . The network appliance of claim 13 , wherein the incomplete workflows are associated with a scanner accessing an open port and failing to respond to an acknowledgement returned from the open port.

16 . The network appliance of claim 11 , wherein the instructions, that when executed by the processing resource, cause the processing resource further to: monitoring network activity to yield the set of network traffic.

17 . The network appliance of claim 16 , wherein monitoring network activity to yield the set of network traffic is done such that the network traffic does not include any traffic corresponding to a scanner or any incomplete workflows.

18 . The network appliance of claim 11 , wherein the instructions, that when executed by the processing resource, cause the processing resource further to:

dynamically add one of the plurality of network ports of the first set of workloads based upon a negotiation of a control channel.

19 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource, causes the processing resource to:

identify a first set of workloads in a set of network traffic that share at least a first trait, and a second set of workloads in the set of network traffic that share at least a second trait;

identify a first suggested intent of the first set of workloads based upon metadata associated with the first set of workloads;

identify a second suggested intent of the second set of workloads based upon metadata associated with the second set of workloads; and

consolidate a plurality of network ports of the first set of workloads based at least in part on a network element associated with the first set of workloads into a set of network ports, wherein a given network port of the plurality of network ports is associated with a particular network protocol that transmits communication for a specific service between a traffic source and a traffic destination;

consolidate further ports from the plurality of network ports into ranges of ports used for an application, wherein ports from the plurality of network ports are consolidated with similar workloads;

receive an access control list including at least a first access control rule allowing defined activity over multiple network ports, and second access control rule allowing defined activity for workloads having the first suggested intent, and a third access control rule allowing defined activity for workloads having the second suggested intent; and

forward test the access control list comprising the first access control rule, the second access control rule, and the third access control rule at an application-level of granularity, wherein the access control list is forward tested after the addition of each application and only the most recently added application has not been fully secured.

20 . The non-transitory computer-readable storage medium of claim 19 , wherein the multiple network ports are selected from a group consisting of: a set of continuous network ports, and a set of discontinuous network ports.

21 . The non-transitory computer-readable storage medium of claim 19 , wherein the set of instructions, which when executed by the processing resource, further causes the processing resource to:

modify a default rule of the access control list from allow to block; and

deploy the access control list.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2021
From: SREEDHAR, RAJIV; NEDBAL, MANUEL; AHLUWALIA, MANOJ; HEGDE, DAMODAR K.; GAITONDE, JITENDRA B.; KRISHNAMURTHI, LATHA; RAO, RAJESHWARI
To: FORTINET, INC.
Reel/Frame 057123/0681 →
Continuity (2)
Division 17348121 · Jun 15, 2021
Related Publication 20220400116A1 · Dec 15, 2022
References Cited (66)
US 8032557B1 · Vijendra · 2011 [cited by applicant]
US 8499331B1 · Yehuda · 2013 [cited by applicant]
US 8813236B1 · Saha · 2014 [cited by applicant]
US 9027077B1 · Bharali · 2015 [cited by applicant]
US 9444829B1 · Ashley · 2016 [cited by applicant]
US 10579407B2 · Ahuja et al. · 2020 [cited by applicant]
US 10944723B2 · Ahuja · 2021 [cited by applicant]
US 11120148B2 · Sreedhar et al. · 2021 [cited by applicant]
US 11258681B2 · Bansal · 2022 [cited by applicant]
US 11588859B2 · Keiser, Jr. · 2023 [cited by applicant]
US 11757888B2 · Sreedhar · 2023 [cited by examiner]
US 20070136788A1 · Monahan et al. · 2007 [cited by applicant]
US 20070248084A1 · Whitehead · 2007 [cited by examiner]
US 20100005505A1 · Gottimukkala · 2010 [cited by applicant]
US 20110138441A1 · Neystadt · 2011 [cited by applicant]
US 20140156814A1 · Barabash · 2014 [cited by applicant]
US 20140214914A1 · Alex · 2014 [cited by applicant]
US 20140280152A1 · Jun · 2014 [cited by applicant]
US 20140280946A1 · Mukherjee · 2014 [cited by applicant]
US 20150256413A1 · Du · 2015 [cited by applicant]
US 20160034269A1 · Furuichi · 2016 [cited by applicant]
US 20160062754A1 · Tripp · 2016 [cited by applicant]
US 20160112270A1 · Danait · 2016 [cited by applicant]
US 20160182557A1 · Grzelak · 2016 [cited by applicant]
US 20160337200A1 · Wei · 2016 [cited by applicant]
US 20160344772A1 · Monohan · 2016 [cited by applicant]
US 20160359680A1 · Parandehgheibi · 2016 [cited by applicant]
US 20160359740A1 · Parandehgheibi · 2016 [cited by applicant]
US 20160359915A1 · Gupta · 2016 [cited by applicant]
US 20170126834A1 · Fransen · 2017 [cited by applicant]
US 20170207980A1 · Hudis · 2017 [cited by applicant]
US 20170237778A1 · DiGiambattista · 2017 [cited by applicant]
US 20170272442A1 · Klimopvs et al. · 2017 [cited by applicant]
US 20170324765A1 · McLaughlin · 2017 [cited by applicant]
US 20170339178A1 · Hahaffey · 2017 [cited by applicant]
US 20180027006A1 · Zimmerman · 2018 [cited by applicant]
US 20180054418A1 · El Defrawy · 2018 [cited by examiner]
US 20180069899A1 · Lang · 2018 [cited by applicant]
US 20180103052A1 · Chondhury · 2018 [cited by applicant]
US 20180176252A1 · Nimmagadda · 2018 [cited by examiner]
US 20180247188A1 · Wong · 2018 [cited by applicant]
US 20180278496A1 · Kulshreshtha · 2018 [cited by applicant]
US 20180287907A1 · Kulshreshtha · 2018 [cited by applicant]
US 20180373462A1 · Childress · 2018 [cited by applicant]
US 20190036950A1 · Isola · 2019 [cited by applicant]
US 20200007396A1 · Fainberg · 2020 [cited by applicant]
US 20200244684A1 · Meshi · 2020 [cited by examiner]
US 20200296134A1 · Sreedhar et al. · 2020 [cited by applicant]
US 20200396207A1 · Motwani · 2020 [cited by applicant]
US 20210037001A1 · Sapek · 2021 [cited by applicant]
US 20210126948A1 · Nedbal et al. · 2021 [cited by applicant]
US 20210314297A1 · Peterson · 2021 [cited by applicant]
US 20210336959A1 · Shah · 2021 [cited by applicant]
US 20220166756A1 · Gupta · 2022 [cited by examiner]
US 20220200993A1 · Smith · 2022 [cited by applicant]
US 20220210128A1 · Allam · 2022 [cited by applicant]
US 20220210196A1 · Parekh · 2022 [cited by applicant]
US 20220294828A1 · Keiser, Jr. · 2022 [cited by applicant]
US 20220368673A1 · Strein · 2022 [cited by applicant]
US 20220393943A1 · Pangeni · 2022 [cited by applicant]
US 20220400113A1 · Sreedhar · 2022 [cited by examiner]
US 20230069738A1 · Sreedhar · 2023 [cited by examiner]
US 20240048564A1 · Sreedhar · 2024 [cited by examiner]
Office Action for U.S. Appl. No. 17/348,121, mailed Aug. 18, 2023, 11 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/348,121, mailed Oct. 27, 2023, 10 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/348,121, mailed May 23, 2024, 11 pages. [cited by applicant]