US 11,838,326 B2
Mobile equipment identity and/or IoT equipment identity and application identity based security enforcement in service provider networks
Sachin Verma, Danville, CA (US); Leonid Burakovsky, Pleasanton, CA (US); Jesse C. Shu, Palo Alto, CA (US); and Chang Li, San Jose, CA (US)
Assigned to Palo Alto Networks, Inc., Santa Clara, CA (US)
Filed by Palo Alto Networks, Inc., Santa Clara, CA (US)
Filed on Mar. 7, 2022, as Appl. No. 17/688,675.
Application 17/688,675 is a continuation of application No. 16/880,852, filed on May 21, 2020, granted, now 11,323,483.
Application 16/880,852 is a continuation of application No. 15/624,437, filed on Jun. 15, 2017, granted, now 10,721,272, issued on Jul. 21, 2020.
Prior Publication US 2022/0191252 A1, Jun. 16, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01); H04W 12/06 (2021.01); H04W 12/48 (2021.01); H04W 12/088 (2021.01); H04L 67/02 (2022.01); H04W 84/04 (2009.01); H04L 67/12 (2022.01)
CPC H04L 63/20 (2013.01) [H04L 63/029 (2013.01); H04L 63/0236 (2013.01); H04L 63/0263 (2013.01); H04L 63/0876 (2013.01); H04W 12/06 (2013.01); H04W 12/088 (2021.01); H04W 12/48 (2021.01); H04L 67/02 (2013.01); H04L 67/12 (2013.01); H04W 84/042 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A system, comprising:
a hardware processor configured to:
monitor network traffic on a service provider network at a security platform to identify a device identifier for a new session, comprising to:
extract the device identifier from a message associated with the new session, wherein the device identifier is a mobile device identifier, and wherein the mobile device identifier includes an Internet of Things (IoT) equipment identity that includes International Mobile Equipment Identity Software Version (IMEISV) information that is extracted by parsing a GTP-C message;
determine an application identifier for user traffic associated with the new session at the security platform, comprising to:
monitor, via deep packet inspection, tunneled user traffic after the new session has been created to obtain the application identifier, wherein the tunneled user traffic includes General Packet Radio Service (GPRS) Tunneling Protocol User Plane (GTP-U) traffic; and
enforce a security policy at the security platform applied to the new session based on the device identifier that includes the IMEISV information and the application identifier; and
a memory coupled to the hardware processor and configured to provide the hardware processor with instructions.