IP Library › Granted Patent US 12,744,822
Granted Patent B2
US 12,744,822 · App. 18/901,381 · Granted Sep 22, 2026

Consistent monitoring and analytics for security insights for network and security functions for a security service

Inventors: Anand Oswal (Pleasanton, CA); Arivu Mani Ramasamy (San Jose, CA); Kumar Ramachandran (Pleasanton, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/20H04L63/029H04L63/101H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,822
App. No.
18/901,381
Granted
Sep 22, 2026
Kind
B2
Abstract

Techniques for providing consistent monitoring and analytics for security insights for network and security functions for a security service are disclosed. In some embodiments, a system/process/computer program product for providing consistent monitoring and analytics for security insights for network and security functions for a security service includes receiving a flow at a software-defined wide area network (SD-WAN) device; inspecting the flow to determine whether the flow is associated with a split tunnel; and monitoring the flow at the SD-WAN device to collect security information associated with the flow for reporting to a security service.

Claims (65)

1 . A system comprising:

a processor configured to:

receive a flow at a virtual private network (VPN) client on an endpoint device;

inspect the flow to determine whether the flow is associated with a split tunnel;

monitor the flow at the VPN client to collect security information associated with the flow for reporting to a security service, comprising to:

collect flow data with security context using the VPN client, wherein the flow data includes the following: an ingress IP address, an egress IP address, an ingress port number, an egress port number, a protocol, and session data usage and time related statistics; and

communicate the collected security information associated with the flow to the security service after a session associated with the flow is ended, comprising to:

send, using the VPN client, the flow data with the security context to the security service, wherein the security service is a cloud-based security service; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system recited in claim 1 , wherein the flow is associated with a whitelist policy and is allowed to bypass the security service based on a security policy.

3 . The system recited in claim 1 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy.

4 . The system recited in claim 1 , wherein the processor is further configured to:

periodically communicate the collected security information associated with the flow from the VPN client to the security service.

5 . The system recited in claim 1 , wherein the security service is the cloud-based security service that is provided using a public cloud service provider.

6 . The system recited in claim 1 , wherein the security service is the cloud-based security service that is provided using a plurality of public cloud service providers.

7 . The system recited in claim 1 , wherein another flow is a site to site tunnel that bypasses the security service, and wherein the VPN client collects security information associated with the another flow for reporting to the security service.

8 . A method, comprising:

receiving a flow at a virtual private network (VPN) client on an endpoint device;

inspecting the flow to determine whether the flow is associated with a split tunnel;

monitoring the flow at the VPN client to collect security information associated with the flow for reporting to a security service, comprising to:

collecting flow data with security context using the VPN client, wherein the flow data includes the following: an ingress IP address, an egress IP address, an ingress port number, an egress port number, a protocol, and session data usage and time related statistics; and

communicating the collected security information associated with the flow to the security service after a session associated with the flow is ended, comprising:

sending, using the VPN client, the flow data with security context to the security service, wherein the security service is a cloud-based security service.

9 . The method of claim 8 , wherein the flow is associated with a whitelist policy and is allowed to bypass the security service based on a security policy.

10 . The method of claim 8 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy.

11 . The method of claim 8 , further comprising:

periodically communicating the collected security information associated with the flow from the VPN client to the security service.

12 . The method of claim 8 , wherein the security service is the cloud-based security service that is provided using a plurality of public cloud service providers.

13 . The method of claim 8 , wherein another flow is a site to site tunnel that bypasses the security service, and wherein the VPN client collects security information associated with the another flow for reporting to the security service.

14 . A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving a flow at a virtual private network (VPN) client on an endpoint device;

inspecting the flow to determine whether the flow is associated with a split tunnel;

monitoring the flow at the VPN client to collect security information associated with the flow for reporting to a security service, comprising to:

collecting flow data with security context using the VPN client, wherein the flow data includes the following: an ingress IP address, an egress IP address, an ingress port number, an egress port number, a protocol, and session data usage and time related statistics; and

communicating the collected security information associated with the flow to the security service after a session associated with the flow is ended, comprising:

sending, using the VPN client, the flow data with security context to the security service, wherein the security service is a cloud-based security service.

15 . The computer program product recited in claim 14 , wherein the flow is associated with a whitelist policy and is allowed to bypass the security service based on a security policy.

16 . The computer program product recited in claim 14 , wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy.

17 . The computer program product recited in claim 14 , further comprising computer instructions for:

periodically communicating the collected security information associated with the flow to the security service.

18 . The computer program product recited in claim 14 , wherein the security service is the cloud-based security service that is provided using a plurality of public cloud service providers.

19 . The computer program product recited in claim 14 , wherein another flow is a site to site tunnel that bypasses the security service, and wherein the VPN client collects security information associated with the another flow for reporting to the security service.

20 . A system comprising:

a processor configured to:

receive a flow at a virtual private network (VPN) client on an endpoint device;

analyze the flow to determine whether the flow is associated with a split tunnel, comprising to:

extract meta data information associated with the flow without performing deep packet inspection to independently determine the meta data information, wherein the meta data information includes one or more of the following: an application identifier (APP ID), User ID, Device ID, and/or Content ID;

compare the extracted meta data information with meta data information associated with a whitelist policy; and

in the event that the extracted meta data information matches the meta data information associated with the whitelist policy, determine that the flow is associated with the split tunnel; and

mirror the flow from the VPN client to a security service, wherein the security service monitors the flow mirrored from the VPN client to collect security information associated with the flow for reporting; and

a memory coupled to the processor and configured to provide the processor with instructions.

21 . A method, comprising:

receiving a flow at a virtual private network (VPN) client on an endpoint device;

analyzing the flow to determine whether the flow is associated with a split tunnel, comprising:

extracting meta data information associated with the flow without performing deep packet inspection to independently determine the meta data information, wherein the meta data information includes one or more of the following: an application identifier (APP ID), User ID, Device ID, and/or Content ID;

comparing the extracted meta data information with meta data information associated with a whitelist policy; and

in the event that the extracted meta data information matches the meta data information associated with the whitelist policy, determining that the flow is associated with the split tunnel; and

mirroring the flow from the VPN client to a security service, wherein the security service monitors the flow mirrored from the VPN client to collect security information associated with the flow for reporting.

22 . A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving a flow at a virtual private network (VPN) client on an endpoint device;

analyzing the flow to determine whether the flow is associated with a split tunnel, comprising:

extracting meta data information associated with the flow without performing deep packet inspection to independently determine the meta data information, wherein the meta data information includes one or more of the following: an application identifier (APP ID), User ID, Device ID, and/or Content ID;

comparing the extracted meta data information with meta data information associated with a whitelist policy; and

in the event that the extracted meta data information matches the meta data information associated with the whitelist policy, determining that the flow is associated with the split tunnel; and

mirroring the flow from the VPN client to a security service, wherein the security service monitors the flow mirrored from the VPN client to collect security information associated with the flow for reporting.

Continuity (3)
Continuation 18360485 · Jul 27, 2023
Continuation 17086191 · Oct 30, 2020
Related Publication 20250023920A1 · Jan 16, 2025
References Cited (63)
US 8856910B1 · Rostami-Hesarsorkh · 2014 [cited by applicant]
US 10116624B2 · Mower · 2018 [cited by applicant]
US 10397116B1 · Volpe · 2019 [cited by applicant]
US 11425098B2 · Bosch · 2022 [cited by examiner]
US 11665139B2 · McDowall · 2023 [cited by applicant]
US 20020023089A1 · Woo · 2002 [cited by applicant]
US 20070104197A1 · King · 2007 [cited by applicant]
US 20090241170A1 · Kumar · 2009 [cited by applicant]
US 20130111040A1 · Vempati · 2013 [cited by applicant]
US 20130298201A1 · Aravindakshan · 2013 [cited by applicant]
US 20130322255A1 · Dillon · 2013 [cited by applicant]
US 20140040503A1 · Mower · 2014 [cited by applicant]
US 20140115654A1 · Rogers · 2014 [cited by applicant]
US 20140259094A1 · Narayanaswamy · 2014 [cited by applicant]
US 20140317312A1 · Mitchell · 2014 [cited by applicant]
US 20150128267A1 · Gupta · 2015 [cited by applicant]
US 20150205600A1 · Grillo · 2015 [cited by applicant]
US 20160050182A1 · Edross · 2016 [cited by applicant]
US 20160080502A1 · Yadav · 2016 [cited by applicant]
US 20170093681A1 · Chaubey · 2017 [cited by applicant]
US 20170155590A1 · Dillon · 2017 [cited by applicant]
US 20170250997A1 · Rostamabadi · 2017 [cited by applicant]
US 20180041472A1 · Mower · 2018 [cited by applicant]
US 20190036814A1 · Aranha · 2019 [cited by applicant]
US 20190104111A1 · Cidon · 2019 [cited by applicant]
US 20190158371A1 · Dillon · 2019 [cited by applicant]
US 20190182155A1 · Chang · 2019 [cited by applicant]
US 20190182213A1 · Saavedra · 2019 [cited by applicant]
US 20190372937A1 · Song · 2019 [cited by applicant]
US 20190384933A1 · Lebel · 2019 [cited by applicant]
US 20200145405A1 · Bosch · 2020 [cited by applicant]
US 20200159947A1 · Shenefiel · 2020 [cited by applicant]
US 20200177606A1 · Valluri · 2020 [cited by applicant]
US 20200195557A1 · Duan · 2020 [cited by applicant]
US 20200213212A1 · Dillon · 2020 [cited by applicant]
US 20200304459A1 · Konda, Jr. · 2020 [cited by applicant]
US 20200322230A1 · Natal · 2020 [cited by applicant]
US 20200366530A1 · Mukundan · 2020 [cited by applicant]
US 20210021564A1 · Chand · 2021 [cited by applicant]
US 20210083983A1 · Chin · 2021 [cited by applicant]
US 20210273913A1 · Bosch · 2021 [cited by applicant]
US 20210344651A1 · Joshi · 2021 [cited by applicant]
US 20220103597A1 · Gobena · 2022 [cited by applicant]
US 20220116381A1 · Bosch · 2022 [cited by applicant]
US 20230155983A1 · Farmer · 2023 [cited by applicant]
CN 103907330 · 2017 [cited by applicant]
CN 111614605 · 2022 [cited by applicant]
EP 3414932 · 2020 [cited by applicant]
JP 2008084246 · 2008 [cited by applicant]
JP 2016146192 · 2016 [cited by applicant]
JP 2018038062 · 2018 [cited by applicant]
KR 20030042919 · 2003 [cited by applicant]
KR 100782919 · 2007 [cited by applicant]
KR 100886925 · 2009 [cited by applicant]
WO 2007055915 · 2007 [cited by applicant]
WO 2014026050 · 2014 [cited by applicant]
WO 2017139699 · 2017 [cited by applicant]
WO 2019043827 · 2019 [cited by applicant]
WO 2020139675 · 2020 [cited by applicant]
Gordeychik et al., SD-WAN Threat Landscape, Nov. 12, 2018. [cited by applicant]
Michael Wood, Top Requirements on the SD-WAN Security Checklist, Network Security, Jul. 2017, pp. 9-11. [cited by applicant]
Raghavan Kasturi Rangan, Trends in SD-WAN and SDN, CSIT (Mar. 2020) 8(1):21-27, Special Issue on SDN, Published online Apr. 22, 2020. [cited by applicant]
Uchibayashi et al., iKaaS, Privacy Preserved IoT Platform, Sep. 29, 2017. [cited by applicant]