Network Security Fabric Monitoring for Automated Vulnerability Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems fail to provide comprehensive remediations for vulnerabilities across an enterprise network, neglecting the operational state of connected devices and requiring manual intervention by trained administrators.

Innovation Solution

A system that centrally collects and analyzes security and operational state data from network devices, automatically uploads security reports to a cloud server, and downloads remediation actions to address vulnerabilities, enhancing network security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional operating system update wizards are used, then the subject device can be updated, but the surrounding connected network devices and their operational state are not considered

Engineering Contradiction:
Improvedevice update completenessVSAvoidnetwork context awareness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the network into a subject device and multiple connected peripheral devices, analyzing each device's security state and operational state separately through centralized interrogation, then synthesizing comprehensive remediation recommendations that consider the entire network context rather than isolated device updates

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The centralized analysis system performs multiple functions: collecting security state data, collecting operational state data, analyzing cached data, identifying vulnerabilities, and generating remediation recommendations that account for both the subject device and connected network devices, replacing the single-function update wizard

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If manual vulnerability remediation is performed by trained administrators, then security issues can be addressed, but the process becomes complex and time-consuming

Engineering Contradiction:
Improvevulnerability remediation effectivenessVSAvoidremediation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-service remediation by centrally analyzing security and operational state data to automatically generate and implement remediation recommendations, eliminating the need for trained administrators to manually recall and execute complex remediation steps for each vulnerability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously interrogates network devices to collect security state data and operational state data on a periodic basis, feeds this information to the centralized analysis system, and uses the analysis results to generate updated remediation recommendations, creating a closed-loop feedback mechanism that adapts to changing network conditions

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive network security analysis is performed, then vulnerability identification improves, but the time and computational resources required increase

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by collecting and caching security state data and operational state data from all network devices before vulnerability analysis is needed, so that when analysis is required, the data is already prepared and available, reducing the time required for comprehensive network security assessment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements periodic action by interrogating network devices to collect security state data and operational state data on a periodic basis, updating cached information at regular intervals rather than performing continuous real-time analysis, balancing detection accuracy with time and computational resource consumption

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12375479B2Proactive detection of vulnerabilities in a data network security fabric
Publication Date: 2025.07.29 FORTINET INC
  • US12375479B2 patent drawing
  • US12375479B2 patent drawing
  • US12375479B2 patent drawing

AI summary

A network gateway interrogates a plurality of network devices to collect security state data and operational state data on a periodic basis. A vulnerability resolution module to automatically uploads a security report and downloads actions (e.g., updates to operating system, configurations or policies) from a cloud vulnerability server corresponding to resolution of the vulnerabilities. A security remediation module can remediate on the network device for protection against at least the specific vulnerability of the at least one the peripheral.