IP Library Granted Patent US 12706942
Granted Patent B2
US 12706942 · App. 18/237,139 · Granted Aug 11, 2026

Systems and methods for deploying agentless countermeasures in a network environment

Inventors: Jason Abate (Chicago, IL); Shabbir Karimi (Downers Grove, IL)
Assignee: Fortinet Inc.
H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706942
App. No.
18/237,139
Granted
Aug 11, 2026
Kind
B2
Abstract

Various approaches for providing network maintenance and health monitoring are discussed. In some cases, some approaches include systems, methods, and/or devices that provide for detecting problematic network behavior and deploying countermeasures in relation to the detected behavior without an agent operating on the device where the countermeasures are implemented.

Claims (50)

1 . A method for remedying network incidents, the method comprising:

providing, by a processor, telemetry from a plurality of network elements to an incident solution processing service, wherein the processor is deployed in a secure network with at least one of the plurality of network elements;

receiving, by the processor, a remediation command from the incident solution processing service, wherein the remediation command includes:

an indication of at least one remediation maintained in a local remediation database communicably coupled to the processor; and

identification information capable of identifying at least one of the plurality of network elements to which the remediation is to be applied;

determining, by the processor, the at least one of the plurality of network elements to which the remediation is to be applied;

accessing, by the processor, the at least one remediation from the local remediation database; and

causing, by the processor, the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied, including: authenticating, by the processor, to the at least one of the plurality of network elements; and issuing, by the processor, a command line command to execute the remediation on the at least one of the plurality of network elements.

2 . The method of claim 1 , wherein the at least one of the plurality of network elements is selected from a group consisting of: a network security appliance, a network switch, a network access point, a network database server, and a mobile device.

3 . The method of claim 1 , wherein the processor is separate from a network security appliance governing access to the secure network, and wherein causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied includes causing the network security appliance to execute the at least one remediation.

4 . The method of claim 3 , wherein executing the at least one remediation by the network security appliance causes the network security appliance to make a modification to an operation of another of the plurality of network elements.

5 . The method of claim 1 , wherein causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied includes causing a network security appliance to execute the at least one remediation.

6 . The method of claim 1 , the method further comprising:

accessing, by the processor, the remediation from the local remediation database.

7 . The method of claim 6 , wherein the remediation is a local remediation, and wherein the method further comprises:

receiving, by the processor, the local remediation and at least one rule governing application of the local remediation;

storing, by the processor, the local remediation to the local remediation database; and

communicating, by the processor, an identification of the local remediation and the at least one rule governing application of the local remediation to the incident solution processing service.

8 . The method of claim 1 , wherein the incident solution processing service is operated on a server outside of the secure network.

9 . The method of claim 1 , wherein the telemetry from the plurality of network elements includes telemetry from at least one network service outside of the secure network and one network device within the secure network.

10 . A network incident system, the network incident system comprising:

a processing resource;

a local remediation database, wherein the local remediation database includes at least one remediation;

a non-transitory computer readable medium, wherein all of the processing resource, the local remediation database, and the non-transitory computer readable medium are deployed in a secure network, and wherein the non-transitory computer readable medium includes instructions executable by the processing resource to:

provide telemetry from a plurality of network elements to an incident solution processing service, wherein at least one of the plurality of network elements is deployed in the secure network, and wherein the incident solution processing service is outside of the secure network;

receive a remediation command from the incident solution processing service, wherein the remediation command includes:

an indication of at least one remediation maintained in a local remediation database communicably coupled to the processor; and

identification information capable of identifying at least one of the plurality of network elements to which the remediation is to be applied;

determine the at least one of the plurality of network elements to which the remediation is to be applied;

accessing, by the processor, the at least one remediation from the local remediation database; and

cause the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied, including: authenticating, by the processor, to the at least one of the plurality of network elements; and issuing, by the processor, a command line command to execute the remediation on the at least one of the plurality of network elements.

11 . The system of claim 10 , wherein the at least one of the plurality of network elements is selected from a group consisting of: a network security appliance, a network switch, a network access point, a network database server, and a mobile device.

12 . The system of claim 10 , wherein the processing resource is separate from a network security appliance governing access to the secure network, and wherein causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied includes causing the network security appliance to execute the at least one remediation.

13 . The system of claim 12 , wherein executing the at least one remediation by the network security appliance causes the network security appliance to make a modification to an operation of another of the plurality of network elements.

14 . The system of claim 10 , wherein causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied includes causing a network security appliance to execute the at least one remediation.

15 . The system of claim 10 , wherein the non-transitory computer readable medium further includes instructions executable by the processing resource to:

access the remediation from the local remediation database.

16 . The system of claim 15 , wherein the remediation is a local remediation, and wherein the non-transitory computer readable medium further includes instructions executable by the processing resource to:

receive the local remediation and at least one rule governing application of the local remediation;

store the local remediation to the local remediation database; and

communicate an identification of the local remediation and the at least one rule governing application of the local remediation to the incident solution processing service.

17 . The system of claim 10 , wherein the telemetry from the plurality of network elements includes telemetry from at least one network service outside of the secure network and one network device within the secure network.

18 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource deployed within a secure network, cause the processing resource to perform a method comprising:

providing telemetry from a plurality of network elements to an incident solution processing service, wherein at least one of the plurality of network elements is deployed separate from the processing resource in the secure network, and wherein the incident solution processing service is outside of the secure network;

receiving a remediation command from the incident solution processing service, wherein the remediation command includes:

an indication of at least one remediation maintained in a local remediation database communicably coupled to the processor;

access the at least one remediation from the local remediation database; and

identification information capable of identifying at least one of the plurality of network elements to which the remediation is to be applied;

determining the at least one of the plurality of network elements to which the remediation is to be applied; and

causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied, including: authenticating, by the processor, to the at least one of the plurality of network elements; and issuing, by the processor, a command line command to execute the remediation on the at least one of the plurality of network elements.