-
公开(公告)号:US11743175B2
公开(公告)日:2023-08-29
申请号:US17566829
申请日:2021-12-31
申请人: Fortinet, Inc.
IPC分类号: H04L45/24 , H04L45/16 , H04W28/02 , H04W72/21 , H04W72/542
CPC分类号: H04L45/24 , H04L45/16 , H04W28/0205 , H04W72/21 , H04W72/542
摘要: Redundant upstream mesh links are formed with a gateway access point for each of the radio capabilities. A resource load is measured across each of the redundant upstream mesh links. During runtime, a packet is received for upstream (or downstream) transmission from a specific client from the plurality of clients. An upstream link is selected for transmission of the packet from the redundant upstream mesh links for transmission of the packet and packets of the packet session, based on a highest link quality available from the plurality of mesh links according to the resource load measurement.
-
公开(公告)号:US11683688B2
公开(公告)日:2023-06-20
申请号:US17487258
申请日:2021-09-28
申请人: Fortinet, Inc.
发明人: Ankur Jain
IPC分类号: H04W48/16 , H04W84/12 , H04W76/10 , H04W12/084 , H04W72/0453 , H04L5/00 , H04W80/12
CPC分类号: H04W12/084 , H04L5/0007 , H04W48/16 , H04W72/0453 , H04W76/10 , H04W80/12 , H04W84/12
摘要: Access credentials for a user of each of the plurality of stations connecting to the Wi-Fi network are forwarded to a RADIUS server. In response to the forwarded access credentials, priority-token values derived from the access credentials of the connecting users for storage in association with a MAC address of each of the plurality of stations, are received from the RADIUS and stored. Priority-token values responsive to detecting multiple users of at least two different priorities needing to access the Wi-Fi network. Available subcarriers are allocated based on the priority-token values for data transmissions.
-
公开(公告)号:US11617123B2
公开(公告)日:2023-03-28
申请号:US17117012
申请日:2020-12-09
申请人: Fortinet, Inc.
发明人: Mohan Jayaraman , P C Sridhar , Pradeep Mohan
摘要: Airtime network policies for quarantined station network policies are stored in a database for application to quarantined stations. Quarantined stations are moved from a first VLAN to a quarantine VLAN with a dedicated BSSID on the Wi-Fi communication network. An RU airtime allocation module of the access point allocates airtime RUs for suppression of some or all transmissions from the quarantined stations. The airtime RU allocation module determines an amount of RUs for access to airtime on a Wi-Fi communications network, based on a network policy that limits an amount of airtime allowed by quarantined stations.
-
公开(公告)号:US11574051B2
公开(公告)日:2023-02-07
申请号:US16053479
申请日:2018-08-02
申请人: Fortinet, Inc.
发明人: Xu Yang
摘要: Systems and methods for malware detection using multiple neural networks are provided. According to one embodiment, for each training sample, a supervised learning process is performed, including: (i) generating multiple code blocks of assembly language instructions by disassembling machine language instructions contained within the training sample; (ii) extracting dynamic features corresponding to each of the code blocks by executing each of the code blocks within a virtual environment; (iii) feeding each code block into a first neural network and the corresponding dynamic features into a second neural network; (iv) updating weights and biases of the neural networks based on whether the training sample was malware or benign; and (v) after processing a predetermined or configurable number of the training samples, the neural networks criticize each other and unify their respective weights and biases by exchanging their respective weights and biases and adjusting their respective weights and biases accordingly.
-
公开(公告)号:US11546769B1
公开(公告)日:2023-01-03
申请号:US17364740
申请日:2021-06-30
申请人: Fortinet, Inc.
IPC分类号: H04W12/128 , H04W12/106 , H04W12/122
摘要: One or more MSRP data packets are received from a first MSRP session and creates a first log entry. One or more MSRP data packets are also received from a second MSRP session and create a second log entry. A correlation between the first and second MSRP sessions based on MDNs can be detected, and mapped correlating information to malicious activity. The mapping includes reconstructing MSRP messages sent from a source and encapsulated in a data field of the packets, including MDNs, and matching to at least one threat from a malicious activity database. In response to the threat matching, to conduct a security action on the first and second MSRP sessions.
-
公开(公告)号:US11539599B2
公开(公告)日:2022-12-27
申请号:US17218689
申请日:2021-03-31
申请人: Fortinet, Inc.
IPC分类号: H04L41/16 , G06N20/00 , G06N5/04 , H04L41/069 , H04L41/147 , H04L41/0677 , H04W84/12
摘要: Multi-level machine learning models can be generated from the captured log events. Outcomes are predicted for input events in real-time. The captured log events are received and parsed to expose event outcome data. A first data set is generated by determining whether an outcome associated with the event outcome data was a success or a failure. Responsive to a failed event outcome, a second data set is generated by categorizing the failed event outcome, to train multiple level SVMs for prediction of Wi-Fi input events and automatic remediation of Wi-Fi issues.
-
公开(公告)号:US11464046B2
公开(公告)日:2022-10-04
申请号:US17218071
申请日:2021-03-30
申请人: Fortinet, Inc.
IPC分类号: H04W74/06 , H04B17/318 , H04W24/10 , H04W84/12
摘要: Responsive to the number of stations exceeding a first threshold number, the transmitting stations are prioritized relative to the station based on a station type. Responsive to the number of stations exceeding a second threshold number, the transmitting stations are prioritized relative to the station based on a station RSSI value. The station is assigned to the run queue with an ATF token responsive to being prioritized within the first or second thresholds permitting transmission of the data packet for the station. The station is assigned to a wait queue responsive to being prioritized outside of the first or second threshold not permitting transmission of the data packet for the station.
-
公开(公告)号:US11184741B1
公开(公告)日:2021-11-23
申请号:US17013612
申请日:2020-09-06
申请人: Fortinet, Inc.
发明人: Venkatesh Kannan
摘要: Quarantine stations are steered to a hidden virtual access point for quarantining multicast and broadcast traffic from other traffic on an access point, or other device. The hidden virtual access point can be spawned, with the same configurations as a non-quarantine virtual access point, for on demand traffic containment. The data stream transmitted over Wi-Fi to the quarantine client using a different GTK key generated under virtual access point of hidden SSID for encryption of the multicast or broadcast transmission, and the data packet stream transmitted over wi-fi to the non-quarantine station using different GTK key generated under virtual access point SSID of regular SSID for encryption of the multicast or broadcast transmission.
-
公开(公告)号:US11044138B2
公开(公告)日:2021-06-22
申请号:US15702594
申请日:2017-09-12
申请人: Fortinet, Inc.
发明人: Mathieu Nantel
摘要: Systems and methods for increasing layer 2 visibility of layer 3 network devices so as to facilitate implementation of device-oriented policy actions by layer 3 network devices are provided. According to one embodiment, unique physical addresses of one or more host devices are retrieved by a dynamic host configuration protocol (DHCP) agent that is operatively coupled with a DHCP server. The physical addresses are mapped to corresponding Internet Protocol (IP) addresses assigned by the DHCP server to the one or more host devices. The mapping is relayed directly or indirectly to a network security device. Network traffic management/security policies are defined within the network security device corresponding to at least one of the unique physical addresses.
-
公开(公告)号:US10945167B2
公开(公告)日:2021-03-09
申请号:US16436834
申请日:2019-06-10
申请人: Neutrino8, Inc.
发明人: Bojan Likar , Ihab Abu-Hakima
IPC分类号: H04W36/00 , H04B17/327 , H04W36/30 , H04W36/32
摘要: A cloud-based Wi-Fi controller facilitates forced transitions. Dynamic RSSI thresholds for sticky-client stations are calculated and periodically updated based on changing conditions. When measured RSSI values reach a dynamic RSSI threshold, the cloud-based Wi-Fi controller reassociates the sticky-client station with a preferred access point, regardless of whether the sticky-client station has reached the same determination.
-
-
-
-
-
-
-
-
-