Network Security Fabric Monitoring for Automated Vulnerability Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems fail to provide comprehensive remediations for vulnerabilities across an enterprise network, neglecting the operational state of connected devices and requiring manual intervention by trained administrators.
Innovation Solution
A system that centrally collects and analyzes security and operational state data from network devices, automatically uploads security reports to a cloud server, and downloads remediation actions to address vulnerabilities, enhancing network security and performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional operating system update wizards are used, then the subject device can be updated, but the surrounding connected network devices and their operational state are not considered
Solution Approach 1:
The system segments the network into a subject device and multiple connected peripheral devices, analyzing each device's security state and operational state separately through centralized interrogation, then synthesizing comprehensive remediation recommendations that consider the entire network context rather than isolated device updates
Solution Approach 2:
The centralized analysis system performs multiple functions: collecting security state data, collecting operational state data, analyzing cached data, identifying vulnerabilities, and generating remediation recommendations that account for both the subject device and connected network devices, replacing the single-function update wizard
2Reliability
If manual vulnerability remediation is performed by trained administrators, then security issues can be addressed, but the process becomes complex and time-consuming
Solution Approach 1:
The system enables automated self-service remediation by centrally analyzing security and operational state data to automatically generate and implement remediation recommendations, eliminating the need for trained administrators to manually recall and execute complex remediation steps for each vulnerability
Solution Approach 2:
The system continuously interrogates network devices to collect security state data and operational state data on a periodic basis, feeds this information to the centralized analysis system, and uses the analysis results to generate updated remediation recommendations, creating a closed-loop feedback mechanism that adapts to changing network conditions
3Measurement precision
If comprehensive network security analysis is performed, then vulnerability identification improves, but the time and computational resources required increase
Solution Approach 1:
The system performs preliminary action by collecting and caching security state data and operational state data from all network devices before vulnerability analysis is needed, so that when analysis is required, the data is already prepared and available, reducing the time required for comprehensive network security assessment
Solution Approach 2:
The system implements periodic action by interrogating network devices to collect security state data and operational state data on a periodic basis, updating cached information at regular intervals rather than performing continuous real-time analysis, balancing detection accuracy with time and computational resource consumption
Data Source
AI summary
A network gateway interrogates a plurality of network devices to collect security state data and operational state data on a periodic basis. A vulnerability resolution module to automatically uploads a security report and downloads actions (e.g., updates to operating system, configurations or policies) from a cloud vulnerability server corresponding to resolution of the vulnerabilities. A security remediation module can remediate on the network device for protection against at least the specific vulnerability of the at least one the peripheral.


