IP Library › Granted Patent US 12,549,571
Granted Patent B2
US 12,549,571 · App. 18/620,793 · Granted Feb 10, 2026

Resolving the disparate impact of security exploits to resources within a resource group

Inventors: Manuel Nedbal (Santa Clara, CA); Ratinder Paul Singh Ahuja (Saratoga, CA); Sumanth Gangashanaiah (Cupertino, CA)
Assignee: Fortinet, Inc.
H04L63/1416H04L43/0882
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,571
App. No.
18/620,793
Granted
Feb 10, 2026
Kind
B2
Abstract

Systems, methods, and apparatuses enable one or more security microservices to resolve the disparate impact of security exploits to resources within a resource group. When a resource group is determined to be impacted by a security exploit, the one or more security microservices determines whether the members of the resource group are disparately impacted. In response, the one or more security microservices splits the resource group into an impacted resource group and a non-impacted resource group and applies exploit mitigation to the resource group members in the impacted resource group. When the one or more security microservices determine that the resource group members of the split resource group are no longer disparately impacted, the one or more security microservices combine the impacted resource group and the non-impacted resource group back into a single resource group.

Claims (59)

1 . A computer-implemented method comprising:

during runtime, identifying, by a security service executing on one or more processors, a plurality of resource groups, each resource group having at least one computing resource available to a host computing system, wherein the host computing system provides a plurality of security microservices that have a hierarchical organization and are independent of each other;

identifying a security exploit and, using at least one of the plurality of microservices, identifying a first a resource group from the plurality of resource groups as impacted by a security exploit;

splitting the first resource group into an impacted resource group comprising those impacted by the security exploit and a second resource group comprising those not impacted by the security exploit;

intercepting traffic directed to and from the first resource group by configuring an interface microservice to operate in-line for the first resource group while not intercepting traffic directed to a non-impacted resource group;

applying an exploit mitigation to at least a portion of the intercepted traffic with one or more of the plurality of security microservices; and

determining that the security exploit has been resolved with the one or more of the plurality of security microservices.

2 . The computer-implemented method of claim 1 , wherein identifying that there is a disparate impact to the resource group members of the identified resource group comprises identifying a first set of resource group members as impacted by a security exploit and a second set of resource group members as non-impacted by the security exploit with one or more of the plurality of security microservices.

3 . The computer-implemented method of claim 2 , further comprising splitting the identified resource group into the impacted resource group and the non-impacted resource group with one or more of the plurality of security microservices by:

generating a first data structure for the first set of resource group members and a second data structure for the second set of resource group members;

moving first metadata for the first set of resource group members to the first data structure;

moving second metadata for the second set of resource group members to the second data structure; and

associating the first data structure and the second data structure.

4 . The computer-implemented method of claim 2 , further comprising splitting the identified resource group into the impacted resource group and the non-impacted resource group with one or more of the plurality of security microservices by:

generating a first data structure for the first set of resource group members;

moving metadata for the first set of resource group members to the first data structure; and

associating the first data structure with the identified resource group.

5 . The computer-implemented method of claim 1 further comprising combining the impacted resource group and the non-impacted resource group into a single resource group in response to determining if the security exploit has been resolved with one or more of the plurality of security microservices.

6 . The computer-implemented method of claim 2 , wherein determining if the security exploit has been resolved with one or more of the plurality of security microservices comprises determining that the first set of resource group members are updated to the same version of an application as the second set of resource group members.

7 . One or more non-transitory computer-readable storage media storing instructions which, when executed by one or more hardware processors, cause performance of a method comprising:

during runtime, identifying, by a security service executing on one or more processors, a plurality of resource groups, each resource group having at least one computing resource available to a host computing system, wherein the host computing system provides a plurality of security microservices that have a hierarchical organization and are independent of each other;

identifying a security exploit and, using at least one of the plurality of microservices, identifying a first a resource group from the plurality of resource groups as impacted by a security exploit;

splitting the first resource group into an impacted resource group comprising those impacted by the security exploit and a second resource group comprising those not impacted by the security exploit;

intercepting traffic directed to and from the first resource group by configuring an interface microservice to operate in-line for the first resource group while not intercepting traffic directed to a non-impacted resource group;

applying an exploit mitigation to at least a portion of the intercepted traffic with one or more of the plurality of security microservices; and

determining that the security exploit has been resolved with the one or more of the plurality of security microservices.

8 . The non-transitory computer-readable storage media of claim 7 , wherein identifying that there is a disparate impact to the resource group members of the identified resource group comprises identifying a first set of resource group members as impacted by a security exploit and a second set of resource group members as non-impacted by the security exploit with one or more of the plurality of security microservices.

9 . The non-transitory computer-readable storage media of claim 8 , further comprising splitting the identified resource group into the impacted resource group and the non-impacted resource group with one or more of the plurality of security microservices by:

generating a first data structure for the first set of resource group members and a second data structure for the second set of resource group members;

moving first metadata for the first set of resource group members to the first data structure;

moving second metadata for the second set of resource group members to the second data structure; and

associating the first data structure and the second data structure.

10 . The non-transitory computer-readable storage media of claim 8 , further comprising splitting the identified resource group into the impacted resource group and the non-impacted resource group with one or more of the plurality of security microservices by:

generating a first data structure for the first set of resource group members;

moving metadata for the first set of resource group members to the first data structure; and

associating the first data structure with the identified resource group.

11 . The non-transitory computer-readable storage media of claim 7 further comprising combining the impacted resource group and the non-impacted resource group into a single resource group in response to determining if the security exploit has been resolved with one or more of the plurality of security microservices.

12 . The non-transitory computer-readable storage media of claim 8 , wherein determining if the security exploit has been resolved with one or more of the plurality of security microservices comprises determining that the first set of resource group members are updated to a same version of an application as the second set of resource group members.

13 . An apparatus comprising:

one or more hardware processors;

memory coupled to the one or more hardware processors, the memory storing instructions which, when executed by the one or more hardware processors, causes the apparatus to:

during runtime, identify, by a security service executing on one or more processors, a plurality of resource groups, each resource group having at least one computing resource available to a host computing system, wherein the host computing system provides a plurality of security microservices that have a hierarchical organization and are independent of each other;

identify a security exploit and, using at least one of the plurality of microservices, identifying a first a resource group from the plurality of resource groups as impacted by a security exploit;

split the first resource group into an impacted resource group comprising those impacted by the security exploit and a second resource group comprising those not impacted by the security exploit;

intercept traffic directed to and from the first resource group by configuring an interface microservice to operate in-line for the first resource group while not intercepting traffic directed to a non-impacted resource group;

apply an exploit mitigation to at least a portion of the intercepted traffic with one or more of the plurality of security microservices; and

determine that the security exploit has been resolved with the one or more of the plurality of security microservices.

14 . The apparatus of claim 13 , wherein identifying that there is a disparate impact to the resource group members of the identified resource group comprises identifying a first set of resource group members as impacted by a security exploit and a second set of resource group members as non-impacted by the security exploit with one or more of the plurality of security microservices.

15 . The apparatus of claim 14 , further comprising splitting the identified resource group into the impacted resource group and the non-impacted resource group with one or more of the plurality of security microservices by:

generating a first data structure for the first set of resource group members and a second data structure for the second set of resource group members;

moving first metadata for the first set of resource group members to the first data structure;

moving second metadata for the second set of resource group members to the second data structure; and

associating the first data structure and the second data structure.

16 . The apparatus of claim 14 , further comprising splitting the identified resource group into the impacted resource group and the non-impacted resource group with one or more of the plurality of security microservices by:

generating a first data structure for the first set of resource group members;

moving metadata for the first set of resource group members to the first data structure; and

associating the first data structure with the identified resource group.

17 . The apparatus of claim 14 further comprises combining the impacted resource group and the non-impacted resource group into a single resource group in response to determining if the security exploit has been resolved with one or more of the plurality of security microservices.

18 . The apparatus of claim 14 , wherein determining if the security exploit has been resolved with one or more of the plurality of security microservices comprises determining that the first set of resource group members are updated to a same version of an application as the second set of resource group members.

Continuity (2)
Continuation 16653532 · Oct 15, 2019
Related Publication 20240244069A1 · Jul 18, 2024
References Cited (65)
US 9467476B1 · Shieh · 2016 [cited by examiner]
US 9716617B1 · Ahuja · 2017 [cited by examiner]
US 10142356B2 · Ahuja · 2018 [cited by examiner]
US 10148504B2 · Ahuja · 2018 [cited by examiner]
US 10158672B2 · Shieh · 2018 [cited by examiner]
US 10212132B2 · Ahuja · 2019 [cited by examiner]
US 10218730B2 · Ahuja · 2019 [cited by examiner]
US 10313362B2 · Ahuja · 2019 [cited by examiner]
US 10419469B1 · Singh · 2019 [cited by examiner]
US 10484418B2 · Ahuja · 2019 [cited by examiner]
US 10498601B2 · Ahuja · 2019 [cited by examiner]
US 10579407B2 · Ahuja · 2020 [cited by examiner]
US 10581884B2 · Ahuja · 2020 [cited by examiner]
US 10608991B2 · Ahuja · 2020 [cited by examiner]
US 10630710B2 · Ahuja · 2020 [cited by examiner]
US 10659496B2 · Ahuja · 2020 [cited by examiner]
US 10666617B2 · Ahuja · 2020 [cited by examiner]
US 10749889B2 · Henderson · 2020 [cited by examiner]
US 10868825B1 · Dominessy · 2020 [cited by examiner]
US 10958519B2 · Ahuja · 2021 [cited by examiner]
US 10979446B1 · Stevens · 2021 [cited by examiner]
US 10986114B1 · Singh · 2021 [cited by examiner]
US 11063823B2 · Punathil · 2021 [cited by examiner]
US 11171969B2 · Ahuja · 2021 [cited by examiner]
US 11368486B2 · Sreedhar · 2022 [cited by examiner]
US 11481498B2 · Velur · 2022 [cited by examiner]
US 11637849B1 · Chen · 2023 [cited by examiner]
US 11677772B1 · Kapoor · 2023 [cited by examiner]
US 11689553B1 · Singh · 2023 [cited by examiner]
US 11882141B1 · Chen · 2024 [cited by examiner]
US 12034750B1 · Bog · 2024 [cited by examiner]
US 12120140B2 · Singh · 2024 [cited by examiner]
US 20160294866A1 · Mihelich · 2016 [cited by examiner]
US 20170063933A1 · Shieh · 2017 [cited by examiner]
US 20170104756A1 · Rosenthal · 2017 [cited by examiner]
US 20170359217A1 · Ahuja · 2017 [cited by examiner]
US 20180034778A1 · Ahuja · 2018 [cited by examiner]
US 20180034832A1 · Ahuja · 2018 [cited by examiner]
US 20180034833A1 · Ahuja · 2018 [cited by examiner]
US 20180034839A1 · Ahuja · 2018 [cited by examiner]
US 20180041598A1 · Vats · 2018 [cited by examiner]
US 20180083985A1 · Ahuja · 2018 [cited by examiner]
US 20180103064A1 · Ahuja · 2018 [cited by examiner]
US 20180115635A1 · Ahuja · 2018 [cited by examiner]
US 20180121221A1 · Ahuja · 2018 [cited by examiner]
US 20180191680A1 · Ahuja · 2018 [cited by examiner]
US 20180288094A1 · Ahuja · 2018 [cited by examiner]
US 20180343281A1 · Ahuja · 2018 [cited by examiner]
US 20190057015A1 · Hassan · 2019 [cited by examiner]
US 20190057213A1 · Hassan · 2019 [cited by examiner]
US 20190124096A1 · Ahuja · 2019 [cited by examiner]
US 20190140903A1 · Ahuja · 2019 [cited by examiner]
US 20190251082A1 · Ahuja · 2019 [cited by examiner]
US 20190312900A1 · Ahuja · 2019 [cited by examiner]
US 20190342323A1 · Henderson · 2019 [cited by examiner]
US 20190394214A1 · Ahuja · 2019 [cited by examiner]
US 20200195503A1 · Ahuja · 2020 [cited by examiner]
US 20200242254A1 · Velur · 2020 [cited by examiner]
US 20200296134A1 · Sreedhar · 2020 [cited by examiner]
US 20200351286A1 · Ahuja · 2020 [cited by examiner]
US 20200351306A1 · Nedbal · 2020 [cited by examiner]
US 20200403868A1 · Punathil · 2020 [cited by examiner]
US 20220286483A1 · Sreedhar · 2022 [cited by examiner]
US 20240031390A1 · Singh · 2024 [cited by examiner]
Notice of Allowance for U.S. Appl. No. 18/745,677 Mar. 27, 2025, 11 pages. [cited by applicant]