IP Library › Granted Patent US 12,726,523
Granted Patent B2
US 12,726,523 · App. 19/053,043 · Granted Sep 1, 2026

Flow metadata exchanges between network and security functions for a security service

Inventors: Anand Oswal (Pleasanton, CA); Arivu Mani Ramasamy (San Jose, CA); Kumar Ramachandran (Pleasanton, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/20H04L63/029H04L63/101H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,523
App. No.
19/053,043
Granted
Sep 1, 2026
Kind
B2
Abstract

In some embodiments, a system/process/computer program product for flow metadata exchanges between network and security functions for a security service includes receiving a flow at a software-defined wide area network (SD-WAN) device; analyzing the flow to determine whether the flow is associated with a split tunnel, comprising: extracting meta data information associated with one flow of the flow to determine the meta data information, wherein the meta data information includes one or more of the following: a user identifier, an application identifier, and/or a device identifier; comparing the extracted meta data information with meta data information associated with a predetermined set of users, applications, and devices; and in the event that the extracted meta data information matches the meta data information associated with one or more of the predetermined set of users, applications, and devices, then determining that the one flow is associated with the split tunnel; and monitoring the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service.

Claims (46)

1 . A system comprising:

a processor configured to:

receive a flow at a software-defined wide area network (SD-WAN) device;

analyze the flow to determine whether the flow is associated with a split tunnel, comprising to:

extract meta data information associated with the flow to determine the meta data information, wherein the meta data information includes one or more of the following: a user identifier, an application identifier, and/or a device identifier;

compare the extracted meta data information with meta data information associated with a predetermined set of users, applications, and devices; and

in the event that the extracted meta data information matches the meta data information associated with one or more of the predetermined set of users, applications, and devices, then determine that the one flow is associated with the split tunnel; and

monitor the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system recited in claim 1 , wherein the flow is associated with one or more of the predetermined set of users, applications, and devices and is allowed to bypass the security service based on a security policy, and wherein the meta data information associated with the flow is communicated in-band or out of band to the SD-WAN device.

3 . The system recited in claim 1 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy, and wherein the meta data information associated with the flow is communicated in-band or out of band to the SD-WAN device.

4 . The system recited in claim 1 , wherein the processor is further configured to:

communicate the collected security information associated with the flow to the security service after a session associated with the flow is ended.

5 . The system recited in claim 1 , wherein the processor is further configured to:

periodically communicate the collected security information associated with the flow to the security service.

6 . The system recited in claim 1 , wherein the collected security information associated with the flow includes an ingress IP address, an egress IP address, an ingress port number, an egress port number, a protocol, and session data usage and time related statistics.

7 . The system recited in claim 1 , wherein the security service is a cloud-based security service.

8 . The system recited in claim 1 , wherein the security service is a cloud-based security service that is provided using a public cloud service provider.

9 . The system recited in claim 1 , wherein the security service is a cloud-based security service that is provided using a plurality of public cloud service providers.

10 . The system recited in claim 1 , wherein another flow is a site to site tunnel that bypasses the security service, and wherein the SD-WAN device collects security information associated with the another flow for reporting to the security service.

11 . A method comprising:

receiving a flow at a software-defined wide area network (SD-WAN) device;

analyzing the flow to determine whether the flow is associated with a split tunnel, comprising:

extracting meta data information associated with one flow of the flow to determine the meta data information, wherein the meta data information includes one or more of the following: a user identifier, an application identifier, and/or a device identifier;

comparing the extracted meta data information with meta data information associated with a predetermined set of users, applications, and devices; and

in the event that the extracted meta data information matches the meta data information associated with one or more of the predetermined set of users, applications, and devices, then determining that the one flow is associated with the split tunnel; and

monitoring the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service.

12 . The method of claim 11 , wherein the flow is associated with one or more of the predetermined set of users, applications, and devices and is allowed to bypass the security service based on a security policy, and wherein the meta data information associated with the flow is communicated in-band or out of band to the SD-WAN device.

13 . The method of claim 11 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy, and wherein the meta data information associated with the flow is communicated in-band or out of band to the SD-WAN device.

14 . The method of claim 11 , further comprising:

communicating the collected security information associated with the flow to the security service after a session associated with the flow is ended.

15 . The method of claim 11 , further comprising:

periodically communicating the collected security information associated with the flow to the security service.

16 . A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving a flow at a software-defined wide area network (SD-WAN) device;

analyzing the flow to determine whether the flow is associated with a split tunnel, comprising:

extracting meta data information associated with one flow of the flow to determine the meta data information, wherein the meta data information includes one or more of the following: a user identifier, an application identifier, and/or a device identifier;

comparing the extracted meta data information with meta data information associated with a predetermined set of users, applications, and devices; and

in the event that the extracted meta data information matches the meta data information associated with one or more of the predetermined set of users, applications, and devices, then determining that the one flow is associated with the split tunnel; and

monitoring the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service.

17 . The computer program product recited in claim 16 , wherein the flow is associated with one or more of the predetermined set of users, applications, and devices and is allowed to bypass the security service based on a security policy, and wherein the meta data information associated with the flow is communicated in-band or out of band to the SD-WAN device.

18 . The computer program product recited in claim 16 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy, and wherein the meta data information associated with the flow is communicated in-band or out of band to the SD-WAN device.

19 . The computer program product recited in claim 16 , further comprising computer instructions for:

communicating the collected security information associated with the flow to the security service after a session associated with the flow is ended.

20 . The computer program product recited in claim 16 , further comprising computer instructions for:

periodically communicating the collected security information associated with the flow to the security service.

Continuity (4)
Continuation 18901381 · Sep 30, 2024
Continuation 18360485 · Jul 27, 2023
Continuation 17086191 · Oct 30, 2020
Related Publication 20250193253A1 · Jun 12, 2025
References Cited (13)
US 8856910B1 · Rostami-Hesarsorkh · 2014 [cited by applicant]
US 11425098B2 · Bosch · 2022 [cited by examiner]
US 11665139B2 · McDowall · 2023 [cited by examiner]
US 20140115654A1 · Rogers · 2014 [cited by applicant]
US 20190182213A1 · Saavedra · 2019 [cited by applicant]
US 20190384933A1 · Lebel · 2019 [cited by applicant]
US 20200177606A1 · Valluri · 2020 [cited by applicant]
EP 3414932B1 · 2020 [cited by examiner]
KR 20030042919A · 2003 [cited by examiner]
KR 100782919B1 · 2007 [cited by examiner]
KR 100886925B1 · 2009 [cited by examiner]
WO WO2014026050A1 · 2014 [cited by examiner]
WO WO2017139699A1 · 2017 [cited by examiner]