Contextual Security Recommendations for Network Data Fabric

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems generate lengthy reports of security issues, overwhelming administrators and requiring expensive on-demand calls to retrieve operational state data, making it difficult to prioritize and remediate security threats effectively.

Innovation Solution

A system that provides contextual security recommendations based on periodically cached state information, allowing administrators to navigate a GUI that prioritizes security issues and overlays recommendations directly on the relevant pages, enabling quick remediation without costly on-demand data retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security reporting methods are used to examine all network devices, then comprehensive security coverage is achieved, but the security report becomes a long list of thousands of issues that overwhelms administrators

Engineering Contradiction:
Improvesecurity coverageVSAvoidadministrative workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the overwhelming list of security issues by organizing them according to network device hierarchy and topology. Security findings are grouped by device type (routers, switches, firewalls, etc.) and further organized by their position in the network hierarchy, transforming a flat list of thousands of issues into a structured, navigable hierarchy that administrators can systematically address.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing contextual information specific to each device and location in the network hierarchy. Each security finding is presented with device-specific operational state data, configuration details, and localized remediation guidance, allowing administrators to focus on the specific context of each issue rather than generic security advice.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If on-demand calls are made to network devices to retrieve operational state data, then current security state information is obtained, but expensive calls are made to the relevant network devices

Engineering Contradiction:
Improvesecurity state accuracyVSAvoiddata retrieval cost
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by periodically caching operational state data from network devices before security analysis is needed. The system proactively collects and stores device configuration, performance metrics, and operational state information in a local cache, so that when security analysis is performed, the data is already available without requiring expensive on-demand retrieval calls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates copies of operational state data by maintaining a cached replica of device information locally. Instead of repeatedly querying the original devices, the system uses cached copies of device data for security analysis and reporting, significantly reducing the number of expensive communication calls to network devices while maintaining analysis accuracy.

Inventive Principle:
Principle #26Copying

3Ease of operation

If a GUI is used to navigate different aspects of network security, then detailed security information can be examined, but expensive calls are made to retrieve operational state data on-demand

Engineering Contradiction:
Improvesecurity analysis accessibilityVSAvoiddata retrieval cost
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent integrates the cached operational state data directly into the GUI interface, so that when administrators navigate through security findings and device details, the contextual information is already loaded and displayed without triggering additional data retrieval calls. The GUI leverages the pre-cached data to provide responsive, detailed security analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cached copies of device operational state data to populate the GUI interface. All device information, configuration details, and security findings displayed in the GUI are drawn from the local cache rather than making real-time calls to network devices, enabling comprehensive security navigation without incurring additional data retrieval costs.

Inventive Principle:
Principle #26Copying

4Productivity

If security recommendations are provided without contextual information, then remediation steps can be identified, but administrators lack the operational state data needed to implement remediation effectively

Engineering Contradiction:
Improveremediation speedVSAvoidcontextual data
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent merges security recommendations with contextual operational state data by co-locating remediation guidance directly with the relevant device information and current state data in the GUI. Each security finding is presented alongside the specific device configuration, operational metrics, and contextual information needed to implement the remediation, eliminating the need for administrators to switch between multiple data sources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses the cached operational state data as an intermediary that bridges security recommendations and device configuration. The cached data provides the contextual link between identified security issues and the specific device state, allowing administrators to understand both the problem and the exact configuration changes needed for remediation without directly querying devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12301588B2Contextual security recommendations for optimization and security best practices in a data network security fabric
Publication Date: 2025.05.13 FORTINET INC
  • US12301588B2 patent drawing
  • US12301588B2 patent drawing
  • US12301588B2 patent drawing

AI summary

A network gateway interrogates a plurality of network devices to collect security state data and operational state data on a periodic basis. Contextual security recommendations are generated based on the security rating report. Security actions can be taken based on the contextual security recommendations.