IP Library › Granted Patent US 12,701,103
Granted Patent B2
US 12,701,103 · App. 18/884,844 · Granted Aug 4, 2026

Application context via endpoint-aware traffic for enhanced security

Inventors: Rui Zhong (Sunnyvale, CA); Jiangnan Li (Santa Clara, CA); Amy Lee (Milpitas, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0263H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,701,103
App. No.
18/884,844
Filed
Sep 13, 2024
Granted
Aug 4, 2026
Kind
B2
Art Unit
2498
USPC
726/11
Abstract

Techniques for providing application context via endpoint-aware traffic for enhanced security are disclosed. In some embodiments, a system/process/computer program product for providing application context via endpoint-aware traffic for enhanced security includes collecting process information for a process at an endpoint; injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint environment to apply a security policy based on a contextual application identifier (App-ID).

Claims (37)

1 . A system, comprising:

a processor configured to:

collect process information for a process at an endpoint;

inject the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic;

extract the process information and automatically group a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; and

process the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID), wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying a security policy based on a contextual App-ID for the plurality of traffic sessions; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the security platform includes a firewall, a network gateway firewall (NGFW), and/or another network device, and wherein the security service includes a cloud-based security service.

3 . The system of claim 1 , wherein the security platform and/or the security service monitors the endpoint-aware traffic, and wherein the security platform includes a firewall, a network gateway firewall (NGFW), and/or another network device, and wherein the security service includes a cloud-based security service.

4 . The system of claim 1 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint.

5 . The system of claim 1 , wherein indicators are configured on the endpoint to collect the process information at the endpoint, and wherein the process information includes a process identifier (PID), a process parent identifier (PPID), and a process name.

6 . The system of claim 1 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy.

7 . The system of claim 1 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on the contextual App-ID.

8 . The system of claim 1 , wherein identification of the contextual App-ID is performed prior to a start of a new session associated with network traffic for the new session, and wherein the identification of the contextual App-ID prior to the start of the new session reduces risks associated with data leakage by preventing a forwarding of any packets from the new session based on the contextual App-ID and the security policy.

9 . The system of claim 1 , wherein the processor is further configured to:

wherein if any of the network traffic within the group matches one or more existing App-ID signatures for identifying an application, then each of the plurality of traffic sessions associated with the group are automatically identified as being associated with the application.

10 . A method, comprising:

collecting process information for a process at an endpoint;

injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic;

extracting the process information and automatically group a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; and

processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID), wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying a security policy based on a contextual App-ID for the plurality of traffic sessions.

11 . The method of claim 10 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint.

12 . The method of claim 10 , wherein indicators are configured on the endpoint to collect the process information at the endpoint, and wherein the process information includes a process identifier (PID), a process parent identifier (PPID), and a process name.

13 . The method of claim 10 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy.

14 . The method of claim 10 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on the contextual App-ID.

15 . The method of claim 10 , wherein identification of the contextual App-ID is performed prior to a start of a new session associated with network traffic for the new session, and wherein the identification of the contextual App-ID prior to the start of the new session reduces risks associated with data leakage by preventing a forwarding of any packets from the new session based on the contextual App-ID and the security policy.

16 . The method of claim 10 ,

wherein if any of the network traffic within the group matches one or more existing App-ID signatures for identifying an application, then each of the plurality of traffic sessions associated with the group are automatically identified as being associated with the application.

17 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

collecting process information for a process at an endpoint;

injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic;

extracting the process information and automatically group a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; and

processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID), wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying a security policy based on a contextual App-ID for the plurality of traffic sessions.

18 . The computer program product of claim 17 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint.

19 . The computer program product of claim 17 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on the contextual App-ID.

20 . The computer program product of claim 17 , wherein identification of the contextual App-ID is performed prior to a start of a new session associated with network traffic for the new session, and wherein the identification of the contextual App-ID prior to the start of the new session reduces risks associated with data leakage by preventing a forwarding of any packets from the new session based on the contextual App-ID and the security policy.

21 . The computer program product of claim 17 , wherein if any of the network traffic within the group matches one or more existing App-ID signatures for identifying an application, then each of the plurality of traffic sessions associated with the group are automatically identified as being associated with the application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2024
From: ZHONG, RUI; LI, JIANGNAN; LEE, AMY
To: PALO ALTO NETWORKS, INC.
Reel/Frame 069397/0180 →
Continuity (1)
Related Publication 20260081893A1 · Mar 19, 2026
References Cited (74)
US 6772332B1 · Boebert · 2004 [cited by applicant]
US 7089592B2 · Adjaoute · 2006 [cited by applicant]
US 7386889B2 · Shay · 2008 [cited by applicant]
US 7747730B1 · Harlow · 2010 [cited by applicant]
US 7801518B1 · Urbanek · 2010 [cited by applicant]
US 7930746B1 · Sheleheda · 2011 [cited by applicant]
US 7958228B2 · Riise · 2011 [cited by applicant]
US 8131851B2 · Harlow · 2012 [cited by applicant]
US 8365276B1 · Sallam · 2013 [cited by applicant]
US 8418249B1 · Nucci · 2013 [cited by applicant]
US 9043905B1 · Allen · 2015 [cited by applicant]
US 9348985B2 · Davis · 2016 [cited by applicant]
US 9648035B2 · Basavapatna · 2017 [cited by applicant]
US 10572823B1 · Feinman · 2020 [cited by applicant]
US 11153444B2 · Xu · 2021 [cited by examiner]
US 11616761B2 · Lam · 2023 [cited by applicant]
US 20020087882A1 · Schneier · 2002 [cited by applicant]
US 20030084323A1 · Gales · 2003 [cited by applicant]
US 20070058551A1 · Brusotti · 2007 [cited by applicant]
US 20070192865A1 · Mackin · 2007 [cited by applicant]
US 20070195753A1 · Judge · 2007 [cited by applicant]
US 20070199061A1 · Byres · 2007 [cited by applicant]
US 20070206741A1 · Tiliks · 2007 [cited by applicant]
US 20070294369A1 · Ginter et al. · 2007 [cited by applicant]
US 20080047009A1 · Overcash · 2008 [cited by applicant]
US 20080175226A1 · Alperovitch · 2008 [cited by applicant]
US 20090178139A1 · Stute · 2009 [cited by applicant]
US 20100192225A1 · Ma · 2010 [cited by applicant]
US 20110238979A1 · Harp · 2011 [cited by applicant]
US 20120304277A1 · Li · 2012 [cited by applicant]
US 20130019314A1 · Ji · 2013 [cited by applicant]
US 20130083701A1 · Tomic · 2013 [cited by applicant]
US 20130291099A1 · Donfried · 2013 [cited by applicant]
US 20130298244A1 · Kumar · 2013 [cited by applicant]
US 20150103136A1 · Anderson · 2015 [cited by applicant]
US 20150288709A1 · Singhal · 2015 [cited by applicant]
US 20160142435A1 · Bernstein · 2016 [cited by applicant]
US 20160164893A1 · Levi · 2016 [cited by applicant]
US 20160191563A1 · Beauchesne · 2016 [cited by applicant]
US 20160359889A1 · Yadav · 2016 [cited by applicant]
US 20170053120A1 · Kamble · 2017 [cited by applicant]
US 20170099278A1 · Ducatel · 2017 [cited by applicant]
US 20170103215A1 · Mahaffey · 2017 [cited by applicant]
US 20170118228A1 · Cp · 2017 [cited by applicant]
US 20170163666A1 · Venkatramani · 2017 [cited by applicant]
US 20170235967A1 · Ray · 2017 [cited by applicant]
US 20170237762A1 · Ogawa · 2017 [cited by applicant]
US 20170279819A1 · More · 2017 [cited by applicant]
US 20190052659A1 · Weingarten · 2019 [cited by applicant]
US 20190081983A1 · Teal · 2019 [cited by applicant]
US 20200322230A1 · Natal · 2020 [cited by examiner]
US 20210227438A1 · Xu · 2021 [cited by examiner]
US 20230135699A1 · Liao · 2023 [cited by examiner]
US 20240154883A1 · Li · 2024 [cited by examiner]
US 20240187340A1 · Ding · 2024 [cited by examiner]
US 20240276290A1 · Bangolae · 2024 [cited by examiner]
US 20250323950A1 · Avula · 2025 [cited by examiner]
US 20250351008A1 · Marquezan · 2025 [cited by examiner]
CN 102918801 · 2016 [cited by applicant]
CN 103765846 · 2017 [cited by applicant]
WO 2014138115 · 2014 [cited by applicant]
Author Unknown, Malware Traffic Analysis, https://blog.brillantit.com/, CryptoWall 3.0 Traffic Analysis, Oct. 29, 2015. [cited by applicant]
Author Unknown, Threat Analytics Platform, Gurducul Predictive Security Analytics, downloaded from gurucul.com_wp-content_uploads_2015_04_TAP on May 20, 2015. [cited by applicant]
Cappelli et al., Common Sense Guide to Prevention and Detection of Insider Threats, 3rd Edition, Version 3.1, CyLab, Jan. 2009. [cited by applicant]
Dan Cybulski, Palo Alto Networks Uses Neural Networks to Attack Insider Threat, Apr. 9, 2015. [cited by applicant]
Darren Manners, The User Agent Field: Analyzing and Detecting the Abnormal or Malicious in your Organization, published Oct. 20, 2011, retrieved From https://www.sans.org/reading-room/whitepapers/malicious/user-agent-fi… [cited by applicant]
Freiling et al., Botnet tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-Of-Service Attacks, Retrieved from http://link.springer.com/chapter/10.1007%2F11555827_19 , European Symposium on Resear… [cited by applicant]
Greitzer et al., Predictive Modeling for Insider Threat Mitigation, Pacific Northwest National Laboratory, Apr. 2009. [cited by applicant]
Microsoft, Security Monitoring and Attack Detection, Microsoft MSDN Library, published Aug. 29, 2006, Retrieved From https://msdn.microsoft.com/en-us/library/cc875806.aspx. [cited by applicant]
Schnackengerg et al., Cooperative Intrusion Traceback and Response Architecture (CITRA), Retrieved from http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=932192, DARPA Information Survivability Conference & Exposi… [cited by applicant]
Silowash et al., Insider Threat Control: Understanding Data Loss Prevention (DLP) and Detection by Correlating Events from Multiple Sources, Software Engineering Institute, Carnegie Mellon, Jan. 2013. [cited by applicant]
Stiawan et al., Characterizing Network Intrusion Prevention System, International Journal of Computer Applications, vol. 14, Jan. 2011. [cited by applicant]
Tim Treat, What We Learn From Protecting Artificially Intelligent Cars, Palo Alto Networks, Sep. 5, 2014. [cited by applicant]
Warkentin et al., Behavioral and Policy Issues in Information Systems Security: The Insider Threat, European Journal of Information Systems, Apr. 2009. [cited by applicant]