Automated Risk-Based Network Security Focus

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing complex network environments with hundreds of software applications is challenging due to the manual complexity of setting firewall rules and determining high-risk areas, leading to inefficiencies and increased risk of lateral attacks.

Innovation Solution

Implementing a system that automatically determines risk-based focus areas by assigning risk scores to applications, application tiers, and workloads, using machine learning and automation to prioritize segmentation and protection efforts, and generating and testing access control lists to secure network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual firewall rule configuration is used to secure network applications, then security coverage can be achieved, but the complexity of operation and time consumption increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically discovering applications, generating firewall rules, and configuring security policies without human intervention. The automated rule generation engine analyzes application traffic patterns and creates appropriate firewall rules, while the forward testing module validates rules before deployment, eliminating manual configuration efforts

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical operations with automated systems. Instead of operators manually creating and testing firewall rules, an automated engine generates rules based on application behavior analysis, and a forward testing system validates them programmatically, substituting human mechanical work with automated computational processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive security rules are implemented across all applications, then security coverage improves, but the time required for testing and implementation increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidtesting and implementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by conducting forward testing in a simulated environment before deploying firewall rules to production. The forward testing module validates rule correctness and identifies potential issues beforehand, preventing costly rework and reducing overall implementation time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the security implementation process into distinct phases: application discovery, rule generation, forward testing, and deployment. This segmentation allows parallel processing of multiple applications and enables incremental implementation, reducing the overall time required for comprehensive security coverage

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If manual security rule modification is performed to adapt to network changes, then security policies can be updated, but the difficulty of detecting and measuring impacts on other applications increases

Engineering Contradiction:
Improvepolicy update capabilityVSAvoidimpact analysis complexity
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements feedback mechanisms where forward testing results provide information about rule impacts on application functionality. This feedback loop allows the system to detect and measure the effects of security rules on network applications, enabling informed adjustments and reducing the difficulty of impact analysis

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12261875B2Systems and methods for automated risk-based network security focus
Publication Date: 2025.03.25 FORTINET INC
  • US12261875B2 patent drawing
  • US12261875B2 patent drawing
  • US12261875B2 patent drawing

AI summary

Systems, devices, and methods are discussed for automatically determining a risk-based focus in determining zero trust network access policy on one or more network elements.