Exchange of flow metadata between network and security services' security functions

By exchanging streaming metadata between SD-WAN devices and cloud-based security services, the problems of wasted computing resources and inconsistent security monitoring in SD-WAN environments are solved, enabling efficient and low-cost implementation and monitoring of consistent security policies.

CN116633607BActive Publication Date: 2026-04-28PALO ALTO NETWORKS INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
PALO ALTO NETWORKS INC
Filing Date
2021-07-30
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

In SD-WAN environments, existing technologies lead to inefficient use of computing resources and inconsistent security monitoring, particularly in the determination of application IDs, user IDs, device IDs, and content IDs, resulting in wasted computing resources and inconsistent security policy implementation.

Method used

By exchanging streaming metadata, including application ID, user ID, device ID, and content ID, between SD-WAN devices and cloud-based security services, redundant calculations are reduced, enabling consistent security policy enforcement and monitoring.

Benefits of technology

It improves the scalability of SD-WAN devices, reduces computing costs, and enables consistent monitoring and analysis between network and security services, avoiding resource waste and policy inconsistencies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116633607B_ABST
    Figure CN116633607B_ABST
Patent Text Reader

Abstract

Techniques are disclosed that provide for exchange of flow metadata between network and security services' security functions. In some embodiments, a system / process / computer program product for providing for exchange of flow metadata between network and security services' security functions includes receiving, at a network gateway of a security service, a flow from a software-defined wide-area network (SD-WAN) device, inspecting the flow to determine meta-information associated with the flow, and communicating the meta-information associated with the flow to the SD-WAN device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the patent application filed on July 30, 2021, with application number 202110871478.1 and invention title "Exchange of streaming data between security functions of network and security services". Background Technology

[0002] Firewalls typically protect networks from unauthorized access while allowing authorized communication to pass through. A firewall is usually a device or collection of devices, or software running on a device such as a computer, that provides firewall functionality for network access. For example, a firewall may be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of device capable of network communication). Firewalls may also be integrated into computer servers, gateways, network / routing devices (e.g., network routers), or data devices (e.g., security devices or other types of specialized devices) or executed as software thereon.

[0003] Firewalls typically deny or allow network traffic based on a set of rules. These sets of rules are often called policies. For example, a firewall can filter inbound traffic by applying a set of rules or policies. A firewall can also filter outbound traffic by applying a set of rules or policies. Firewalls can also perform basic routing functions. Attached Figure Description

[0004] Various embodiments of the invention are disclosed in the following detailed description and accompanying drawings.

[0005] Figure 1A-1B This is a system environment diagram including an example SD-WAN architecture and security services based on some embodiments.

[0006] Figure 2 This is a system diagram illustrating example components for exchanging streaming metadata between security functions that provide network and security services according to some embodiments.

[0007] Figure 3 This is a system diagram illustrating example components for providing consistent monitoring and analysis of security functions for network security insights and security services, according to some embodiments.

[0008] Figure 4A An embodiment of a network gateway according to some embodiments is illustrated.

[0009] Figure 4B This is a functional diagram of the logic components of an embodiment of a data device.

[0010] Figure 5 This is a flowchart illustrating the process of exchanging streaming metadata between security functions that provide network and security services according to some embodiments.

[0011] Figure 6 This is a flowchart illustrating a process, according to some embodiments, for providing consistent monitoring and analysis of security functions for network security insights and security services.

[0012] Figure 7 This is another flowchart illustrating a process, according to some embodiments, for providing consistent monitoring and analysis of security functions for network security insights and security services. Detailed Implementation

[0013] This invention can be implemented in a variety of ways, including as a process; an apparatus; a system; a composition of matter; a computer program product embodied on a computer-readable storage medium; and / or a processor, such as a processor configured to execute instructions stored on and / or provided by memory coupled to the processor. In this specification, these embodiments or any other form in which the invention may take place can be referred to as technology. Generally, the order of steps of the disclosed process can be changed within the scope of the invention. Unless otherwise stated, a component such as a processor or memory described as being configured to perform a task can be implemented as a general component temporarily configured to perform that task at a given time or manufactured as a specific component to perform that task. As used herein, the term "processor" refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.

[0014] The following detailed description of one or more embodiments of the invention, together with the accompanying drawings illustrating the principles of the invention, provides for illustrative purposes. The invention has been described in conjunction with such embodiments, but is not limited to any particular embodiment. The scope of the invention is limited only by the claims, and the invention encompasses many alternatives, modifications, and equivalents. Numerous specific details are set forth in the following description to provide a thorough understanding of the invention. These details are provided for illustrative purposes and the invention may be practiced without some or all of these specific details. For clarity, technical materials known in the art related to the invention have not been described in detail so as not to unnecessarily obscure the invention.

[0015] Advanced or next-generation firewalls

[0016] Malware is a general term commonly used to refer to malicious software (e.g., including various types of hostile, intrusive, and / or otherwise unwanted software). Malware can take the form of code, scripts, active content, and / or other software. Examples of malware use include disrupting computer and / or network operations, stealing proprietary information (e.g., confidential information such as identity, financial, and / or intellectual property-related information), and / or gaining access to private / proprietary computer systems and / or computer networks. Unfortunately, as technologies are developed to help detect and mitigate malware, malicious authors find ways to circumvent these efforts. Therefore, there is a continuous need for improvements in the technologies used to identify and mitigate malware.

[0017] Firewalls typically protect networks from unauthorized access while allowing authorized communication through them. A firewall is usually a device or collection of devices, or software running on a device, that provides firewall functionality for network access. For example, a firewall may be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of device capable of network communication). Firewalls can also be integrated into or executed as software applications on various types of devices or security devices, such as computer servers, gateways, network / routing devices (e.g., network routers), or data devices (e.g., security devices or other types of dedicated devices, and in some implementations, certain operations may be implemented in dedicated hardware (e.g., ASICs or FPGAs)).

[0018] Firewalls typically deny or allow network traffic based on a set of rules. These sets of rules are often referred to as policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by applying a set of rules or policies to prevent unwanted external traffic from reaching a protected device. A firewall can also filter outbound traffic by applying a set of rules or policies (e.g., allowing, blocking, monitoring, notifying, or logging, and / or specifying other actions in firewall rules or policies that can be triggered based on various criteria, such as those described herein). A firewall can also filter local network (e.g., intranet) traffic by similarly applying a set of rules or policies.

[0019] Security devices (e.g., security apparatuses, security gateways, security services, and / or other security devices) can perform various security operations (e.g., firewalls, anti-malware, intrusion prevention / detection, proxying, and / or other security functions), networking functions (e.g., routing, Quality of Service (QoS), workload balancing of network-related resources, and / or other networking functions), and / or other security and / or networking-related operations. For example, routing can be performed based on source information (e.g., IP address and port), destination information (e.g., IP address and port), and protocol information (e.g., Layer-3 IP-based routing).

[0020] Basic packet-filtering firewalls filter network traffic by inspecting individual packets sent over the network (e.g., packet-filtering firewalls or first-generation firewalls, which are stateless packet-filtering firewalls). Stateless packet-filtering firewalls typically inspect individual packets themselves and apply rules based on the inspected packets (e.g., using a combination of packet source and destination address information, protocol information, and port number).

[0021] Application firewalls can also perform application-layer filtering (e.g., using an application-layer filtering firewall or a second-generation firewall, which operates at the application level of the TCP / IP stack). Application-layer filtering firewalls or application firewalls can typically identify certain applications and protocols (e.g., web browsing using Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfer using File Transfer Protocol (FTP), and various other types of applications and protocols such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, application firewalls can block unauthorized protocols attempting to communicate over standard ports (e.g., application firewalls can often be used to identify unauthorized / policy-exceeding protocols attempting to sneak through using non-standard ports of the protocol).

[0022] Stateful firewalls can also perform state-based packet inspection, where each packet is examined within the context of a series of packets associated with a flow / packet stream of packets transmitted over the network (e.g., stateful firewalls or third-generation firewalls). This firewall technique is often referred to as stateful packet inspection because it maintains a record of all connections passing through the firewall and is able to determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection itself can be one of the criteria for triggering rules within a policy.

[0023] As discussed above, advanced or next-generation firewalls can perform stateless and stateful packet filtering and application-layer filtering. Next-generation firewalls can also perform additional firewall technologies. For example, some newer firewalls, sometimes referred to as advanced or next-generation firewalls, can also identify users and content. In particular, some next-generation firewalls are expanding the list of applications that these firewalls can automatically identify to thousands of applications. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks' PA series firewalls).

[0024] For example, Palo Alto Networks' next-generation firewalls enable enterprises to use a variety of identification technologies to identify and control applications, users, and content—not just ports, IP addresses, and packets—such as: application-IDs for accurate application identification, user-IDs for user identification (e.g., by a user or group of users), and content-IDs for real-time content scanning (e.g., controlling web surfing and restricting data and file transfers). These identification technologies allow enterprises to securely enable application usage using business-relevant concepts, rather than following the traditional methods provided by conventional port-blocking firewalls. Furthermore, for example, the dedicated hardware of next-generation firewalls implemented as dedicated devices typically provides a higher level of performance than application inspection using software running on general-purpose hardware (e.g., security devices such as those offered by Palo Alto Networks, which utilize dedicated function-specific processing tightly integrated with a single-pass software engine to maximize network throughput while minimizing latency).

[0025] Advanced or next-generation firewalls can also be implemented using virtualized firewalls. Commercial examples of such next-generation firewalls can be found from Palo Alto Networks (e.g., Palo Alto Networks' firewalls support a variety of commercial virtualization environments, including, for example, ESXi TM and NSX TM , Netscaler SDX TM , KVM / OpenStack (Centos / RHEL, Accessible through Amazon Web Services (AWS). For example, virtualized firewalls can support similar or identical next-generation firewall and advanced threat prevention features available in physical form factor devices, allowing enterprises to securely enable applications to flow into and across their private, public, and hybrid cloud environments. Automation features such as VM monitoring, dynamic address groups, and REST-based APIs allow enterprises to proactively monitor VM changes and dynamically feed that context into security policies, thereby eliminating policy lag that can occur when VMs change.

[0026] Technical challenges of security solutions in evolving SD-WAN environments

[0027] Security service providers offer a variety of commercially available cloud-based security solutions, including various firewalls, VPNs, and other security-related services. For example, some security service providers have their own data centers in multiple geographic regions around the world to provide such cloud-based security solutions to their customers.

[0028] Typically, cloud-based security services are provided by cloud-based security service providers in different locations / regions around the world. However, customers (e.g., enterprise customers of a given cloud-based security service provider) may have headquarters, branches, and / or other offices in various locations / regions that network with each other and with the cloud-based security service and the Internet using various SD-WAN connections (e.g., via SD-WAN architectures). This typically introduces another layer of security surveillance at each office location (e.g., branch, headquarters, etc.) and at each SD-WAN device of the cloud-based security service. Consequently, this network / security architecture creates inefficient use of computing resources and / or the possibility of inconsistent security surveillance and enforcement, as described further below.

[0029] An example of this inefficient use of computing resources (e.g., CPU and memory / storage devices) is that security monitoring may include providing accurate identification of applications (e.g., also referred to herein as application IDs). Network gateway firewalls (e.g., in cloud-based security services and / or within enterprise network infrastructure, such as in a private cloud used to provide such cloud-based security services, and / or combinations thereof) and SD-WAN devices (e.g., customer premises equipment (CPE) SD-WAN devices in headquarters and branch office sites) may utilize such application ID information (e.g., and / or other metadata associated with flows as described below) for performing security monitoring / enforcement and / or network functions (e.g., security policy enforcement and / or network routing, etc.). For example, the application ID information used to identify flows (e.g., new flows) can also be extended to perform application layer gateway (ALG) functions.

[0030] However, application ID determination processes are typically expensive in terms of computing resources (e.g., memory and CPU resources). Therefore, performing application ID determination processes at the device / computing element / location can reduce the scalability of both platforms (e.g., security services on an enterprise network and network gateway firewalls at CPE SD-WAN devices).

[0031] Similarly, the process of determining the user ID, device ID, content ID, and / or other metadata associated with a flow is also typically expensive in terms of computing resources (e.g., memory and CPU resources). For example, network traffic from a branch office (e.g., different flows) can travel through an SD-WAN device and then to a cloud-based security service. Therefore, the expensive determination of metadata associated with each flow (e.g., application ID, user ID, device ID, content ID, and / or other metadata associated with the flow) is often performed twice, which is an inefficient use of computing resources, as described similarly above.

[0032] As will be further described below, the process of performing such metadata determination (e.g., application ID, user ID, device ID, content ID, and / or other metadata associated with the flow) for each flow can, in some cases, be performed inconsistently at SD-WAN devices (e.g., CPE SD-WAN devices on an enterprise network) and (e.g., at a cloud-based security service) at network gateway firewalls. For example, the application ID, user ID, device ID, content ID, and / or other metadata associated with the flow may be performed slightly differently at SD-WAN devices (e.g., CPE SD-WAN devices on an enterprise network) and (e.g., at a cloud-based security service) at network gateway firewalls. This can lead to inconsistent network routing / application layer gateway implementation and / or security policy monitoring / enforcement, which is generally undesirable for enterprise network / security policy implementation.

[0033] An overview of technologies for exchanging streaming metadata between security functions that provide network and security services. Therefore, various technologies for exchanging streaming metadata between security functions that provide network and security services are disclosed.

[0034] In some embodiments, a system / process / computer program product for providing flow metadata exchange between security functions of a network and security services includes: receiving a flow from a software-defined wide area network (SD-WAN) device at a network gateway of the security services; inspecting the flow to determine metadata associated with the flow; and transmitting the metadata associated with the flow to the SD-WAN device.

[0035] For example, the process for determining such metadata information associated with each stream (e.g., application ID, user ID, device ID, content ID, and / or other metadata associated with the stream) can be performed at one of the computing devices / components / locations using the disclosed techniques (e.g., at a cloud-based security service, such as one provided via Prisma Access, which is a commercially available cloud-based security service from Palo Alto Networks, Inc., headquartered in Santa Clara, California, or another commercially available cloud-based security service that can be similarly used to implement the disclosed techniques, and the cloud-based security service can be provided using a private cloud, one or more public cloud service providers, and / or any combination thereof). The determined metadata associated with each flow can then be transmitted (e.g., securely and efficiently, such as using various techniques, including encapsulating such metadata in packet headers as described further below) to an SD-WAN device (e.g., a commercially available SD-WAN device, such as a commercially available SD-WAN device from Palo Alto Networks, Inc., headquartered in Santa Clara, California, which provides traffic engineering, monitoring, and troubleshooting, etc., or another commercially available SD-WAN device that can be similarly used to implement the disclosed techniques). In the example implementation, such determined metadata associated with each flow is transmitted on the flow (e.g., using TCP options) in-band or out-of-band, as will be described further below. Therefore, SD-WAN devices / compute elements can then use the metadata information associated with a given flow to perform security policy enforcement, network routing, and / or other actions without having to perform checks (e.g., deep packet inspection (DPI)) to independently determine such metadata information (e.g., application ID, user ID, device ID, content ID, and / or other metadata associated with the flow). This is more efficient and reduces the use of CPU and memory resources at SD-WAN devices / compute elements.

[0036] In the example enterprise network, where SD-WAN functionality is provided by SD-WAN Customer Premises Equipment (CPE) elements / devices and security functions are provided in the cloud by cloud-based security services, metadata determined / extracted on the flow through the SD-WAN CPE and the cloud-based security services can then be exchanged between the SD-WAN CPE and the cloud-based security services to enrich functionality and / or avoid performance-computationally expensive features, such as for inspection / DPI, which is used to determine application ID, user ID, device ID, content ID, and / or other metadata associated with the flow executed more than once / at each location in the SD-WAN CPE and the cloud-based security services.

[0037] In this example, if the SD-WAN CPE has already performed application identification (application ID), it can pass the application ID to the cloud-based security service to avoid the cloud security function having to perform application identification again. Similarly, if the cloud security function has already performed application layer gateway (ALG) functionality, it can pass predictive streams to the SD-WAN CPE.

[0038] Therefore, the disclosed technology is used to provide significant performance improvements for providing streaming metadata exchange between security functions of network and security services, which can also facilitate reduced computing costs for performing cloud security services and better scalability of SD-WAN devices / components (e.g., thereby also allowing for lower-cost branched SD-WAN device / component solutions).

[0039] Therefore, as will be further described below, various technologies for exchanging streaming metadata between security functions that provide network and security services are disclosed.

[0040] In addition, as will now be further described below, the disclosed technology also facilitates unique and integrated security solutions that provide consistency in metadata information (e.g., application ID, user ID, device ID, content ID, and / or other metadata associated with the flow) associated with each flow across these networking and security functions.

[0041] An overview of technologies used to provide consistent monitoring and analysis of security functions for network security insights and security services. In enterprise networks, where traffic engineering allows policies to permit specific types of traffic to be whitelisted and allowed to exit branches or mobile devices (e.g., split tunnel configurations, such as whitelisting certain types of traffic like Netflix or YouTube), security monitoring can be compromised because whitelisted traffic will bypass cloud security functions. Enterprises typically configure network / security policies to allow subsets of applications to exit, such as branches directly to the internet, which can be enforced using SD-WAN traffic forwarding policies.

[0042] Therefore, the security context of such applications on the stream does not exist in network / security logging data (e.g., from commercially available Cortex from Palo Alto Networks, headquartered in Santa Clara, California). TMData lakes or other commercially available network / security logging data solutions (which can be similarly used to implement the disclosed technology) are used because such flows are routed to bypass cloud-based security services and exit, for example, directly to a branch of the Internet. This resulting lack of visibility on such flows can lead to gaps in an enterprise's security posture. Similar problems may arise in the following scenarios: (1) flows passed directly (through an SD-WAN architecture) between enterprise sites; and (2) split tunnel configurations on VPN clients for endpoint devices that allow flows to exit from the endpoint devices to the Internet. In both cases, the flows bypass security monitoring at the security service, leading to the technical problem of a lack of security context on the flows in the network / security logging data due to such network / security policy configurations.

[0043] Therefore, various technologies for providing consistent monitoring and analysis of security functions for network security insights and security services have been disclosed.

[0044] In some embodiments, a system / process / computer program product for providing consistent monitoring and analysis of security functions for network security insights and security services includes: receiving flows at a software-defined wide area network (SD-WAN) device; inspecting the flows to determine whether the flows are associated with split tunnels; and monitoring the flows at the SD-WAN device to collect security information associated with the flows for reporting to security services.

[0045] In some embodiments, a system / process / computer program product for providing consistent monitoring and analysis of security functions for network security insights and security services includes: receiving flows at a software-defined wide area network (SD-WAN) device; inspecting the flows to determine whether the flows are associated with split tunnels; and mirroring the flows from the SD-WAN device to a security service, wherein the security service monitors the flows mirrored from the SD-WAN device to collect security information associated with the flows for reporting purposes.

[0046] For example, this blind spot can be mitigated by enabling branched SD-WAN and / or VPN clients on endpoint devices (e.g., commercially available VPN clients, such as the Global Protection client from Palo Alto Networks, Inc., Santa Clara, California, or another commercially available VPN client solution that can be similarly used to implement the disclosed technology) to collect and derive security information about the flow (e.g., including security information equivalent to / consistent with information that would be collected by the cloud security function itself). Similar techniques can be applied to site-to-site enterprise traffic via site-to-site tunnels, thereby bypassing cloud security functions.

[0047] For example, the disclosed technology may include configuring SD-WAN devices / components to collect streaming data with a security context and send it to a cloud-based security service (e.g., at a cloud-based security service such as provided via PrimaAccess, a commercially available cloud-based security service from Palo Alto Networks Inc., headquartered in Santa Clara, California, or another commercially available cloud-based security service that may be similarly used to implement the disclosed technology, and the cloud-based security service may be provided using a private cloud, one or more public cloud service providers and / or any combination thereof).

[0048] As another example, the disclosed techniques may include configuring SD-WAN devices / components to mirror traffic flows associated with selected applications (e.g., application IDs) to cloud-based security services, enabling the collection of security context on those flows (e.g., the SD-WAN devices / components may export the flow data via IPfix / NetFlow or using other secure communication mechanisms, as further described below).

[0049] In these examples, the data ingestion and processing layer associated with cloud-based security services can fuse data from SD-WAN devices / components and cloud-based security services to provide a consistent security context that facilitates consistent monitoring and analysis of network security insights and the security functions of cloud-based security service solutions.

[0050] When using these publicly available technologies to provide consistent monitoring and analysis of network security insights and the security functions of security services, enterprise customers do not need to deploy, manage, and monitor services on other devices and endpoints (e.g., mobile devices, such as laptops or smartphones) in a branch. For example, SD-WAN devices or VPN clients operate in the data plane and perform split tunneling. Therefore, SD-WAN devices or VPN clients can determine which flows are being sent to the cloud, the internet, or another enterprise site, thereby bypassing cloud security services. Consequently, SD-WAN devices or VPN clients can be intelligently configured to collect data on traffic routed along these different paths (e.g., at varying granularities) to facilitate consistent monitoring and analysis of network security insights and the security functions of cloud-based security service solutions.

[0051] Therefore, the disclosed technology also facilitates unique and integrated security solutions that provide consistent security context and monitoring, regardless of how traffic flows within an enterprise network.

[0052] Therefore, as will be further described below, various technologies are disclosed for providing consistent monitoring and analysis of security functions for network security insights and security services.

[0053] System environment including example SD-WAN architecture and security services

[0054] Figure 1A-1B These are system environment diagrams including example SD-WAN architectures and security services according to some embodiments. These example system diagrams typically illustrate security services for protecting branch offices and headquarters sites by leveraging SD-WAN connections to communicate with security services (e.g., cloud-based security services).

[0055] As organizations expand across diverse geographical locations, network selection becomes a delicate balancing act of cost, performance, and security. Software-defined WAN (SD-WAN) simplifies WAN management and operation by separating networking hardware (the data plane) from its control mechanisms (the control plane). SD-WAN technology allows companies to build higher-performance WANs using low-cost internet access. With the adoption of SD-WAN, organizations are increasingly connecting directly to the internet, introducing security challenges for protecting remote networks and mobile users. Furthermore, the deployment of Software as a Service (SaaS) applications has increased significantly, with many organizations directly connecting to such cloud-based SaaS applications, introducing additional security challenges. While the adoption of SD-WAN technology introduces numerous cost benefits and enables organizations to be flexible and optimized, it also makes branch offices and users targets for cyberattacks and other technical security challenges, as described above.

[0056] SD-WAN security is often expected to be as flexible as networking, but as will be described below, in situations such as... Figure 1A and 1B Adapting traditional security methods to this evolving SD-WAN networking in the various enterprise network environments illustrated is also technically challenging. In traditional campus network designs, there is a complete stack of network security devices around the internet that can protect branches, a scenario where all traffic passes through the core network via such a complete stack of network security devices around the internet. However, SD-WAN does not always use this network architecture, such as when SD-WAN is configured to integrate cloud / SaaS applications.

[0057] An alternative to the traditional approach is to deploy cybersecurity devices at branch offices. However, this traditional approach complicates deployment because it brings security equipment / components closer to the branch offices.

[0058] SD-WAN technology typically uses the principles of Software-Defined Networking (SDN) and separates the control plane and data plane. Based on this principle, SD-WAN deployments typically include the following components: (1) a controller used by the administrator to centrally configure the WAN topology and define traffic path rules; and (2) physical or virtual SD-WAN edge devices that reside at each site and act as connection and termination points for the SD-WAN architecture.

[0059] In an example SD-WAN Type 1 deployment (e.g., branch and headquarters deployment), an organization can deploy one or more SD-WAN edge devices at each branch site and connect them to form an SD-WAN infrastructure or SD-WAN coverage. Administrators use a cloud-based or site-based SD-WAN controller to manage and configure these edge devices and define traffic forwarding policies at each site.

[0060] refer to Figure 1A For the example deployment (e.g., branch, headquarters, and regional data center deployment), an IPsec tunnel is established between each of the SD-WAN edge devices 102A, 102B, and 102C at each data center (e.g., including an IPsec tunnel between one or more SD-WAN edge devices at each branch and headquarters site) and security service 120 (e.g., a cloud-based security service, such as that provided via Prisma Access, which is a commercially available cloud-based security service from Palo Alto Networks, Inc., located in Santa Clara, California). This example system diagram is an example deployment for anchoring traffic from each branch site to a single WAN link (Type 1) as shown at 110. SD-WAN infrastructure 110 and security service 120 each communicate with the Internet 140. Security service 120 communicates with data storage 130 (e.g., data storage for network / security logging data, such as a commercially available Cortex from Palo Alto Networks, Inc., located in Santa Clara, California). TM Data lake communication.

[0061] Specifically, this architecture adds SD-WAN devices to regional data centers, as well as at each branch and headquarters site. These regional data centers can be public or private cloud environments. The SD-WAN devices at the regional data centers aggregate network traffic from smaller sites within the region. For example, an organization can use this deployment when there are multiple regional branch sites with low-bandwidth connections to the Internet.

[0062] refer to Figure 1BFor another example deployment (e.g., branch offices, headquarters, and regional data centers), an IPsec tunnel is established between the SD-WAN edge device (e.g., including SD-WAN devices 102D and 102E) at each data center and security service 120 (e.g., a cloud-based security service, such as one provided via Prisma Access, which is a commercially available cloud-based security service from Palo Alto Networks, headquartered in Santa Clara, California). This example system diagram is an example deployment for securing an SD-WAN deployment using a regional hub / POP architecture. As shown, an IPsec tunnel is established between each regional data center or hub 106A and 106B and security service 120.

[0063] Today's common network architecture tunnels traffic between an enterprise's headquarters and branches via MPLS links or dedicated encrypted VPN links. This is especially true as more and more services are cloud-based (e.g., including SaaS solutions such as Microsoft Office). Furthermore, with more information available on the Internet, tunneling traffic back to the aggregation point before routing it to its final destination is generally less meaningful. Disrupting traffic locally from the branch (as opposed to on-premises devices) typically allows traffic to reach its destination faster and results in more efficient use of bandwidth. However, allowing traffic between devices directly in the branch and the Internet also introduces new technological security challenges, as described above.

[0064] Specifically, in these and other example SD-WAN architectures and security services, flows can be configured to pass through or bypass security service 120 and be routed to a regional data center or hub or the Internet without passing through security service 120. Therefore, these and other example SD-WAN architectures and security services cause the aforementioned technical security issues because traffic passing through the security service is inefficiently inspected / monitored (e.g., by DPI or other monitoring / inspection activities) at both the egress SD-WAN device / component and the security service. Furthermore, these and other example SD-WAN architectures and security services cause the aforementioned technical security issues because traffic bypassing the security service is not consistently inspected / monitored, and no security insights into the network are collected in conjunction with the analysis of the security functions of the security service.

[0065] Therefore, the disclosed technologies can be implemented in these example SD-WAN architectures and security services, as will be discussed below. Figure 2 As further described.

[0066] Figure 2This is a system diagram illustrating example components for exchanging streaming metadata between security functions that provide network and security services according to some embodiments.

[0067] refer to Figure 2 At 202, a device protected by a network gateway / behind a network gateway is shown; at 204A, 204B, and 204C, a site network gateway (e.g., a security platform, such as a commercially available network gateway firewall solution from Palo Alto Networks, or another commercially available security platform solution that may be similarly configured to implement the network gateway disclosed herein) is shown; and at 206A, 206B, and 206C, a cloud device (e.g., an SD-WAN CPE device / component, such as a commercially available SD-WAN solution from Palo Alto Networks, or another commercially available SD-WAN solution that may be similarly configured to implement the disclosed technology) is shown.

[0068] Specifically, Figure 2 The illustration depicts an example mechanism for exchanging streaming metadata between security functions of network and security services. As shown, in this example, packets are embedded with additional streaming metadata information, such as application ID information. As illustrated, packet 208 includes an IP header 210, a UDP header 212, an application ID encapsulation 214, an internal IP header 216, and an internal UDP / TCP header 218. Additional types of metadata information associated with the stream (e.g., user ID, device ID, content ID, and / or other streaming metadata) can be similarly encapsulated and included in the packet header.

[0069] For example, the process for determining such metadata information associated with each stream (e.g., application ID, user ID, device ID, content ID, and / or other metadata associated with the stream) can be performed at one of the computing devices / components / locations (e.g., at a cloud-based security service, such as...). Figure 1A and 1B The security service 120 shown is implemented using the disclosed technology. The determined metadata information associated with each flow can then be transmitted (e.g., securely and efficiently) to the SD-WAN device (e.g., as shown). Figure 1A and 1B The SD-WAN devices shown are 102A, 102B, or 102C. In the example implementation, such defined metadata information associated with each flow is transmitted in-band on the flow (e.g., using packet header information encapsulated as described above, such as in...). Figure 2(as shown in the diagram) or out-of-band transmission. Therefore, SD-WAN devices / compute elements can then use the metadata information associated with a given flow to perform security policy enforcement and / or other actions without having to perform local checks (e.g., deep packet inspection (DPI)) to independently determine such metadata information (e.g., application ID, user ID, device ID, content ID, and / or other metadata associated with the flow). This is more efficient and reduces the use of CPU and memory resources at the SD-WAN device / compute element.

[0070] In an example enterprise network where SD-WAN functionality is provided by SD-WAN Customer Premises Equipment (CPE) components / devices and security functions are provided in the cloud by cloud-based security services, metadata determined / extracted on flows through the SD-WAN CPE and cloud-based security services can be exchanged between the SD-WAN CPE and cloud-based security services to enrich functionality and / or avoid computationally expensive features, such as inspection / DPI, which is used to determine application ID, user ID, device ID, content ID, and / or other metadata associated with flows that are executed more than once / at each location in the SD-WAN and cloud-based security services.

[0071] In this example, if the SD-WAN CPE has already performed application identification (application ID), it can pass the application ID to the cloud-based security service to avoid the cloud security function having to perform application identification again. Similarly, if the cloud security function has already performed application layer gateway (ALG) functionality, it can pass predictive streams to the SD-WAN CPE.

[0072] Various other packet headers (e.g., to encapsulate user ID, device ID, content ID, and / or other metastream information) can be similarly implemented to facilitate various other stream metadata exchanges between security functions of the network and security services, to perform the disclosed techniques for providing stream metadata exchanges between security functions of the network and security services, as will now be apparent to those skilled in the art in light of the various disclosed embodiments.

[0073] Therefore, using the disclosed techniques for exchanging streaming metadata between security functions that provide network and security services can deliver significant performance improvements, which can facilitate reduced computing costs for performing cloud security services and better scalability of SD-WAN devices / components (e.g., thereby allowing for lower-cost branched SD-WAN device / component solutions).

[0074] In addition, as will now be further described below, the disclosed technology also facilitates unique and integrated security solutions that provide consistency in metadata information (e.g., application ID, user ID, device ID, content ID, and / or other metadata associated with the flow) associated with each flow across these networking and security functions.

[0075] Figure 3 This is a system diagram illustrating example components for providing consistent monitoring and analysis of security functions for network security insights and security services, according to some embodiments.

[0076] refer to Figure 3 Network traffic for YouTube service 340 is whitelisted and configured to be routed from branch / headquarters to the Internet from SD-WAN devices / components, such as at 302A, and bypasses security services 320, as shown at 312a. In enterprise networks where traffic engineering allows policies to permit specific types of traffic to be whitelisted and allowed to exit branch or endpoint devices (e.g., split tunnel configurations, such as whitelisting certain types of traffic like Netflix or YouTube), security monitoring can be compromised because the whitelisted traffic bypasses cloud security features. Enterprises typically allow a subset of applications to exit, for example, directly to the Internet at a branch, which can be enforced using SD-WAN traffic forwarding policies.

[0077] Consequently, the security context of such applications' flows is not present in network / security log data (e.g., from a commercially available Cortex™ data lake from Palo Alto Networks, headquartered in Santa Clara, California), because such flows will be routed to bypass cloud-based security services and exit, for example, directly to a branch of the Internet. This resulting lack of visibility on such flows can lead to gaps in an enterprise's security posture. Similar problems may arise in the following scenarios: (1) flows flowing directly (through an SD-WAN architecture) between enterprise sites; and (2) split tunnel configurations on VPN clients for endpoint devices that allow flows to exit directly from the endpoint device to the Internet.

[0078] For example, this blind spot can be remedied by having a branch CPE SD-WAN (e.g., and / or a VPN client) such as that shown at 302A collect and export security information on the stream (which is equivalent to the information collected by the cloud security function itself), and by transmitting such security information on the stream to a security service 320 (e.g., for a stream configured to bypass split tunnel traffic of the security service, such as that shown at 312n, which uses a secure communication connection as described above similarly at 312a, such as an out-of-band communication mechanism or other periodic connection with the security service or other similar secure communication mechanisms that can be similarly implemented to perform the disclosed techniques), which can then store security information for logging in a data storage 330 (e.g., a network / security logging data storage, such as using a commercially available Cortex from Palo Alto Networks, Inc., headquartered in Santa Clara, California). TM Data lakes can be used for reporting and analysis of security services targeting such enterprise network activities.

[0079] Similar techniques can be applied to site-to-site enterprise traffic communicating via site-to-site tunnels, thereby bypassing cloud security features such as those shown at 314a and 316a, such as for traffic via SD-WAN architecture 304 to data center 306, which includes an email server 308 for the enterprise. For example, the disclosed techniques may include configuring SD-WAN devices / elements to collect and send streaming data with a security context to cloud-based security services, such as those shown at 314n (e.g., using secure communication connections, such as out-of-band communication mechanisms or other periodic communication connections with security services, or other similar secure communication mechanisms or other similar secure communication mechanisms that can be similarly implemented to perform the disclosed techniques).

[0080] As another example, the disclosed techniques may include configuring SD-WAN devices / components to mirror traffic streams belonging to selected applications to cloud-based security services such as those shown at 318m, enabling similar collection of security context on those streams (e.g., establishing secure communication connections to the security service that would otherwise be used for new streams, or other similar secure communication mechanisms that may be implemented to perform the disclosed techniques).

[0081] Instead, certain flows, such as those to Salesforce service 350, will be routed from SD-WAN devices 302A and 302B via security service 320, and therefore no further action is required to ensure that such flows are consistently monitored and that their flow data is logged in data storage 330.

[0082] In these examples, the data ingestion and processing layer associated with cloud-based security services can fuse data from SD-WAN devices / components and cloud-based security services to provide a consistent security context, facilitating consistent monitoring and analysis of network security insights and the security functions of cloud-based security service solutions.

[0083] When using these publicly available technologies to provide consistent monitoring and analysis of network security insights and security functions for security services, enterprise customers do not need to deploy, manage, and monitor services on other devices and endpoints in a branch (e.g., mobile devices such as laptops or smartphones). For example, SD-WAN devices or VPN clients operate in the data plane and perform split tunneling. Therefore, SD-WAN devices or VPN clients can determine which flows are being sent to the cloud, the internet, or another enterprise site, thereby bypassing cloud security services. Consequently, SD-WAN devices or VPN clients can be intelligently configured to (e.g., at varying granular levels) collect data on traffic routed along these different paths to facilitate consistent monitoring and analysis of network security insights and security functions for cloud-based security service solutions.

[0084] Therefore, the disclosed technology also facilitates unique and integrated security solutions that provide consistent security context and monitoring, regardless of how traffic flows within an enterprise network.

[0085] exist Figure 4A An embodiment of network gateway 204 is shown (e.g., such as...). Figure 2(Network gateway shown at 204A-C). In various embodiments, the examples shown are representations of physical components that can be included in network gateway 204 when the network gateway is implemented as a data device. Specifically, the data device includes a high-performance multi-core central processing unit (CPU) 402 and random access memory (RAM) 404. The data device also includes storage device 410 (such as one or more hard disks or solid-state storage units). In various embodiments, the data device stores (whether in RAM 404, storage device 410, and / or other suitable locations) information used in monitoring the corporate network and implementing the disclosed techniques. Examples of such information include application identifiers, content identifiers, user identifiers, requested URLs, IP address mappings, policies and other configuration information, signatures, hostname / URL classification information, malware profiles, and machine learning models. The data device may also include one or more optional hardware accelerators. For example, the data device may include a cryptographic engine 406 configured to perform encryption and decryption operations, and one or more field-programmable gate arrays (FPGAs) 408 configured to perform matching, act as a network processor, and / or perform other tasks.

[0086] The functionality described herein as being performed by a data device can be provided / implemented in various ways. For example, a data device can be a dedicated device or a collection of devices. The functionality provided by the data device can also be integrated into a general-purpose computer, computer server, gateway, and / or network / routing device, or executed as software thereon. In some embodiments, at least some of the services described as being provided by the data device are alternatively (or additionally) provided to a client device (e.g., an endpoint device, such as a laptop, smartphone, etc.) through software executed on the client device.

[0087] Whenever a data device is described as performing a task, a single component, a subset of components, or all components of the data device can collaborate to perform the task. Similarly, whenever a component of the data device is described as performing a task, a sub-component can perform the task and / or a component can combine with other components to perform the task. In various embodiments, portions of the data device are provided by one or more third parties. Depending on factors such as the amount of computing resources available to the data device, various logical components and / or features of the data device may be omitted, and the techniques described herein may be adapted accordingly. Similarly, where applicable, embodiments of the data device may include additional logical components / features. In various embodiments, an example of a component included in the data device is an application identification engine configured to identify applications (e.g., using various application signatures for identifying applications based on packet flow analysis). For example, the application identification engine may determine what type of traffic a session involves, such as web browsing—social networking; web browsing—news; SSH, etc.

[0088] The disclosed system processing architecture can be used with different types of clouds in various deployment scenarios, such as: (1) public cloud; (2) private cloud at the site; and (3) internal high-end physical firewall. Some processing power can be allocated to perform private cloud operations (e.g., using the management plane (MP) in the Palo Alto Networks PA-5200 Series firewall appliance).

[0089] Figure 4B This is a functional diagram of the logical components of an embodiment of a data device. The example shown is one that may be included in network gateway 204 (e.g., such as...) in various embodiments. Figure 2 The representation of logical components in the network gateway (shown at 204A-C) is shown. Unless otherwise stated, the various logical components of the network gateway 204 can generally be implemented in various ways, including as a collection of one or more scripts (e.g., written in Java, Python, etc. where applicable).

[0090] As shown, network gateway 204 includes a firewall and includes a management plane 432 and a data plane 434. The management plane is responsible for managing user interactions, such as by providing a user interface for configuring policies and viewing log data. The data plane is responsible for managing data, such as by performing packet processing and session processing.

[0091] Network processor 436 is configured to receive packets from client devices (such as client device 204) and provide them to data plane 434 for processing. Whenever flow module 438 identifies a packet as part of a new session, it creates a new session flow. Subsequent packets are identified as belonging to that session based on flow lookup. SSL decryption is applied by SSL decryption engine 440, if applicable. Otherwise, the processing performed by SSL decryption engine 440 is omitted. Decryption engine 440 helps network gateway 204 inspect and control SSL / TLS and SSH encrypted traffic, and thus helps stop threats that might otherwise remain hidden in encrypted traffic. Decryption engine 440 also helps prevent sensitive content from leaving the enterprise / protected customer's network. Decryption can be selectively controlled (e.g., enabled or disabled) based on parameters such as URL category, traffic source, traffic destination, user, user group, and port. In addition to decryption policies (e.g., specifying which sessions to decrypt), decryption profiles can be assigned to control various options for policy-controlled sessions. For example, specific cipher suites and encryption protocol versions may be required.

[0092] The application identification (application-ID) engine 442 is configured to determine what type of traffic a session involves. As an example, the application identification engine 442 can identify GET requests in received data and infer that the session requires an HTTP decoder. In some cases, such as web browsing sessions, the identified application can change, and such changes will be noticed by the network gateway 204. For example, a user might initially browse a business wiki (whose access-based URL is categorized as "Web Browsing - Productivity") and then subsequently browse a social networking site (whose access-based URL is categorized as "Web Browsing - Social Networking"). Different types of protocols have corresponding decoders.

[0093] Based on the determination made by the application identification engine 442, the packet is sent by the threat engine 444 to the appropriate decoder, which is configured to assemble the packets (which may be received out of order) into the correct sequence, perform tokenization, and extract the information. The threat engine 444 also performs signature matching to determine what should happen to the packet. The SSL encryption engine 446 can also re-encrypt and decrypt the data as needed. The forwarding module 448 forwards the packet for transmission (e.g., to the destination).

[0094] For example Figure 4BAs shown, policy 452 is received and stored in management plane 432. The policy may include one or more rules that can be specified using domain and / or host / server names, and the rules may apply one or more signatures or other matching criteria or heuristics, such as those used for security policy enforcement based on various extracted parameters / information from monitored session traffic flows of subscribers / IP flows. Interface (I / F) communicator 450 is provided for management communication (e.g., via (REST) ​​API, messaging or network protocol communication, or other communication mechanisms).

[0095] Example process for exchanging streaming metadata between security functions that provide network and security services.

[0096] Figure 5 This is a flowchart illustrating the process of exchanging streaming metadata between security functions that provide network and security services according to some embodiments.

[0097] In one embodiment, the above (e.g., such as the above regarding) is used. Figure 1A-4B The system architecture described is used to execute process 500.

[0098] The process begins at position 502 when a flow is received from a software-defined wide area network (SD-WAN) device at the network gateway of the security service. For example, the security service could be a cloud-based security service as described above.

[0099] At 504, the flow is inspected to determine if metadata associated with the flow is being performed. For example, the flow may be identified as a new flow at the network gateway for a security service, and deep packet inspection (DPI) may be used to determine the application ID of the new flow, as described similarly above.

[0100] At point 506, metadata associated with the flow to the SD-WAN device is transmitted. For example, application ID information (e.g., or other inspected / extracted metadata associated with the flow, such as user ID, device ID, content ID, etc.) can be encapsulated and included in the packet header, as described similarly above. The SD-WAN device can then use the metadata associated with the flow to enforce routing or security policies, also as described similarly above.

[0101] In some embodiments, the SD-WAN device transmits metadata associated with another flow to the security service.

[0102] Example procedures for providing consistent monitoring and analysis of security functions for network security insights and security services.

[0103] Figure 6This is another flowchart illustrating a process, according to some embodiments, for providing consistent monitoring and analysis of security functions for network security insights and security services.

[0104] In one embodiment, using (for example, such as the above regarding) Figure 1A-4B The system architecture described above is used to execute process 600.

[0105] When a stream is received at a software-defined wide area network (SD-WAN) device, the process begins at position 602.

[0106] At 604, the flow is inspected to determine if it is being executed in connection with a split tunnel. For example, an SD-WAN device can be configured to implement a split tunnel using a security policy (e.g., for whitelisted traffic / flows), and if a flow is associated with a split tunnel, the flow can be allowed to bypass security services based on the security policy, as described similarly above.

[0107] At position 606, the SD-WAN device monitors flows to collect security information associated with flows used for reporting to the security service. For example, the security information collected associated with a flow may include ingress IP address, egress IP address, ingress port number, egress port number, protocol and session data usage, and time-related statistics, as described above. The security information collected associated with a flow may be reported to the security service after the session associated with the flow has ended, and / or such information may be reported to the security service periodically, also as described above.

[0108] In some embodiments, the other flow is a site-to-site tunnel that bypasses the security service, and the SD-WAN device collects security information associated with the other flow for reporting to the security service, as described similarly above.

[0109] Figure 7 This is another flowchart illustrating a process, according to some embodiments, for providing consistent monitoring and analysis of security functions for network security insights and security services.

[0110] In one embodiment, using (for example, such as the above regarding) Figure 1A-4B The system architecture described above is used to execute process 700.

[0111] The process begins at 702 when a stream is received at a software-defined wide area network (SD-WAN) device.

[0112] At 704, the flow is inspected to determine if it is being executed in connection with a split tunnel. For example, an SD-WAN device can be configured to implement a split tunnel using a security policy (e.g., for whitelisted traffic / flows), and if a flow is associated with a split tunnel, the flow can be allowed to bypass security services based on the security policy, as described similarly above.

[0113] At 706, flows are mirrored from the SD-WAN device to a security service, which monitors the mirrored flows to collect security information associated with the flows for reporting purposes. For example, the security service may monitor flows mirrored from the SD-WAN device to collect various security information associated with the flows, which may include ingress IP address, egress IP address, ingress port number, egress port number, protocol, and session data usage and time-related statistics, as described similarly above.

[0114] While the foregoing embodiments have been described in considerable detail for the purpose of clarity, the invention is not limited to the details provided. Many alternative ways of implementing the invention exist. The disclosed embodiments are illustrative and not restrictive.

Claims

1. A system comprising: The processor is configured to: Receive a stream at a software-defined wide area network (SD-WAN) device, wherein the stream comprises a set of network packets associated with a session, and the stream includes embedded metadata; Inspecting the flow to determine whether it is associated with a split tunnel includes: The embedded metadata is extracted from the stream without performing deep grouping checks to independently determine the metadata, wherein the metadata includes one or more of the following: application identifier, user identifier, device identifier, content identifier, and Based on the extracted metadata, determine whether the stream is associated with a whitelist policy; and The flow is monitored at the SD-WAN device to collect security information associated with the flow for reporting to a security service, wherein the flow is associated with the split tunnel and is permitted to bypass the security service based on a security policy, and wherein the collected security information associated with the flow includes ingress IP address, egress IP address, ingress port number, egress port number, protocol, and session data usage and time-related statistics; and A memory coupled to the processor and configured to provide instructions to the processor.

2. The system of claim 1, wherein the processor is further configured to: After the session associated with the stream ends, the security information collected associated with the stream is transmitted to the security service.

3. The system of claim 1, wherein the processor is further configured to: The collected security information associated with the stream is periodically transmitted to the security service.

4. The system according to claim 1, wherein the security service is a cloud-based security service.

5. The system according to claim 1, wherein the security service is a cloud-based security service provided by a public cloud service provider.

6. The system of claim 1, wherein the security service is a cloud-based security service provided by multiple public cloud service providers.

7. The system of claim 1, wherein the other flow is a site-to-site tunnel bypassing the security service, and wherein the SD-WAN device collects security information associated with the other flow to report to the security service.

8. A method comprising: Receive streams at a software-defined wide area network (SD-WAN) device, wherein the streams include embedded metadata; Inspecting the flow to determine whether it is associated with a split tunnel includes: The embedded metadata is extracted from the stream without performing deep grouping checks to independently determine the metadata, wherein the metadata includes one or more of the following: application identifier, user identifier, device identifier, content identifier, and Based on the extracted metadata, determine whether the stream is associated with a whitelist policy; as well as The flow is monitored at the SD-WAN device to collect security information associated with the flow for reporting to a security service, wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy, and wherein the collected security information associated with the flow includes ingress IP address, egress IP address, ingress port number, egress port number, protocol, and session data usage and time-related statistics.

9. The method according to claim 8, further comprising: After the session associated with the stream ends, the security information collected associated with the stream is transmitted to the security service.

10. The method of claim 8, further comprising: The collected security information associated with the stream is periodically transmitted to the security service.

11. A computer program product embodied in a tangible computer-readable storage medium and comprising computer instructions for performing the following operations: Receive streams at a software-defined wide area network (SD-WAN) device, wherein the streams include embedded metadata; Inspecting the flow to determine whether it is associated with a split tunnel includes: The embedded metadata is extracted from the stream without performing deep grouping checks to independently determine the metadata, wherein the metadata includes one or more of the following: application identifier, user identifier, device identifier, content identifier, and Based on the extracted metadata, determine whether the stream is associated with a whitelist policy; as well as The flow is monitored at the SD-WAN device to collect security information associated with the flow for reporting to a security service, wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on a security policy, and wherein the collected security information associated with the flow includes ingress IP address, egress IP address, ingress port number, egress port number, protocol, and session data usage and time-related statistics.

12. The computer program product of claim 11, further comprising computer instructions for performing the following operations: After the session associated with the stream ends, the security information collected associated with the stream is transmitted to the security service.

13. The computer program product of claim 11, further comprising computer instructions for performing the following operations: The collected security information associated with the stream is periodically transmitted to the security service.

14. A system comprising: The processor is configured to: Receive streams at a software-defined wide area network (SD-WAN) device, wherein the streams include embedded metadata; Inspecting the flow to determine whether it is associated with a split tunnel includes: The embedded metadata is extracted from the stream without performing deep grouping checks to independently determine the metadata, wherein the metadata includes one or more of the following: application identifier, user identifier, device identifier, content identifier, and Based on the extracted metadata, determine whether the stream is associated with a whitelist policy; and The flow is mirrored from the SD-WAN device to a security service, wherein the security service monitors the flow mirrored from the SD-WAN device to collect security information associated with the flow for reporting purposes, wherein the flow is associated with the split tunnel and is allowed to bypass the security service based on security policies, and wherein the collected security information associated with the flow includes ingress IP address, egress IP address, ingress port number, egress port number, protocol, and session data usage and time-related statistics; and A memory coupled to the processor and configured to provide instructions to the processor.

Citation Information

Patent Citations

  • Providing application metadata using export protocols in computer networks

    US20170093681A1