IP Library › Granted Patent US 12,596,799
Granted Patent B2
US 12,596,799 · App. 18/822,744 · Granted Apr 7, 2026

Externally securing unmanaged devices using artificial intelligence operations (AIOPS) for network operations

Inventors: Naga Kishore Reddy Tarimala (Bangalore, IN); Siva Yogendra Jupudi (Basavanagudi, IN)
Assignee: Fortinet, Inc.
G06F21/554H04L63/10H04L63/1433H04L63/1441G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,799
App. No.
18/822,744
Granted
Apr 7, 2026
Kind
B2
Abstract

An unknown operational technology (OT) or Internet of Things (IoT) device is detected by capturing network transactions related to downstream network devices and identifying the unknown OT or IoT device from non-OT or non-IoT network devices on the enterprise network. A device type of the unknown OT or IoT device is determined using an AIOP detection model. The AIOP detection model is trained from unsupervised cluster learning from a history of externally captured network transactions of the plurality of known OT and IoT devices. The vulnerabilities of the unknown OT or IoT device are assessed by predicting services from correlating the device type to the externally captured network transactions.

Claims (39)

1 . A computer-implemented method in a network security device, for externally securing unmanaged devices on an enterprise network using Artificial Intelligence Operations (AIOPs), the method comprising the steps of:

detecting an unknown operational technology (OT) or Internet of Things (IoT) device, on the enterprise network comprising a plurality of known OT and IoT devices, by capturing network transactions related to downstream network devices and identifying the unknown OT or IoT device from non-OT or non-IoT network devices on the enterprise network, wherein the unknown OT or IoT device and the plurality of known OT and IoT devices are unable to internally execute non-native apps;

determining a device type of the unknown OT or IoT device using an AIOP detection model, wherein the AIOP detection model is trained from unsupervised cluster learning from a history of externally captured network transactions of the plurality of known OT and IoT devices;

assessing vulnerabilities of the unknown OT or IoT device by predicting services from correlating the device type to the externally captured network transactions;

monitoring the unknown OT or IoT device to detect anomalous activity related to an assessed vulnerability of the unknown OT or IoT device, using an AIOP intrusion model generated from the history of known OT and IoT devices; and

responsive to detecting anomalous activity, taking a security action based on relevant security rules.

2 . The method of claim 1 , further comprising: checking for malware based on the detected anomalous activity.

3 . The method of claim 1 , wherein the plurality of OT and IoT devices are unable to internally execute non-native apps, wherein the non-native apps comprise at least one of a third-party app, a downloaded app, and a daemon.

4 . The method of claim 1 , wherein the AIOP detection model is trained from unsupervised cluster learning from a history of externally captured network transactions of the plurality of known OT and IoT devices, wherein the captured network transaction comprise at least one parameter from application name or type, destination address, application category, number of sessions, number of applications, and bandwidth.

5 . The method of claim 1 , wherein the vulnerability assessment of the unknown OT or IoT device by predicting services from correlating the device type to the externally captured network transactions further comprises sending artificially generated probes.

6 . The method of claim 1 , wherein the vulnerability assessment of the unknown OT or IoT device by predicting services from correlating the device type to the externally captured network transactions further comprises capturing organic transactions.

7 . The method of claim 1 , wherein monitoring the unknown OT or IoT device to detect anomalous activity related to the assessed vulnerability of the unknown OT or IoT device, using the AIOP intrusion model generated from the history of known OT and IoT devices, wherein the detected anomalous activity comprises at least one parameter of real time-event type, date and time of event, and time lapse from previous occurrence of same event type.

8 . The method of claim 7 , wherein the real time-event type parameter comprises at least one of denial of service, misconfig, and network scan.

9 . The method of claim 7 , wherein the real time-event type parameter comprises at least one of denial of service, misconfig, and network scan.

10 . The method of claim 1 , wherein the captured network transactions related to downstream network devices and identifying the unknown OT or IoT device from non-OT or non-IoT network devices on the enterprise network are captured from at least one of a network gateway, an access point, a router, a switch and a station.

11 . The method of claim 1 , wherein the network security device comprises an AIOPs server.

12 . The method of claim 1 , wherein the AIOP detection model is trained from unsupervised cluster learning from a history of externally captured network transactions of the plurality of known OT and IoT devices, wherein the captured network transaction comprise at least one parameter from application name or type, destination address, application category, number of sessions, number of applications, and bandwidth.

13 . The method of claim 1 , wherein the vulnerability assessment of the unknown OT or IoT device by predicting services from correlating the device type to the externally captured network transactions further comprises sending artificially generated probes.

14 . The method of claim 1 , wherein the vulnerability assessment of the unknown OT or IoT device by predicting services from correlating the device type to the externally captured network transactions further comprises capturing organic transactions.

15 . The method of claim 1 , wherein monitoring the unknown OT or IoT device to detect anomalous activity related to the assessed vulnerability of the unknown OT or IoT device, using the AIOP intrusion model generated from the history of known OT and IoT devices, wherein the detected anomalous activity comprises at least one parameter of real time-event type, date and time of event, and time lapse from previous occurrence of same event type.

16 . The method of claim 1 , wherein the captured network transactions related to downstream network devices and identifying the unknown OT or IoT device from non-OT or non-IoT network devices on the enterprise network are captured from at least one of a network gateway, an access point, a router, a switch and a station.

17 . A non-transitory computer-readable medium in a network security device, on a data communication network, storing code that when executed, performing a method for externally securing unmanaged devices on an enterprise network using Artificial Intelligence Operations (AIOPs), the method comprising:

detecting an unknown operational technology (OT) or Internet of Things (IoT) device, on the enterprise network comprising a plurality of known OT and IoT devices, by capturing network transactions related to downstream network devices and identifying the unknown OT or IoT device from non-OT or non-IoT network devices on the enterprise network, wherein the unknown OT or IoT device and the plurality of known OT and IoT devices are unable to internally execute non-native apps;

determining a device type of the unknown OT or IoT device using an AIOP detection model, wherein the AIOP detection model is trained from unsupervised cluster learning from a history of externally captured network transactions of the plurality of known OT and IoT devices;

assessing vulnerabilities of the unknown OT or IoT device by predicting services from correlating the device type to the externally captured network transactions;

monitoring the unknown OT or IoT device to detect anomalous activity related to an assessed vulnerability of the unknown OT or IoT device, using an AIOP intrusion model generated from the history of known OT and IoT devices; and

responsive to detecting anomalous activity, taking a security action based on relevant security rules.

18 . The method of claim 17 , further comprising:

checking for malware based on the detected anomalous activity.

19 . The method of claim 17 , wherein the plurality of OT and IoT devices are unable to internally execute non-native apps, wherein the non-native apps comprise at least one of a third-party app, a downloaded app, and a daemon.

20 . A network security device, on a data communication network, for externally securing unmanaged devices on an enterprise network using Artificial Intelligence Operations (AIOPs), the network security device comprising:

a processor;

a network interface communicatively coupled to the processor and to a data communication network; and

a memory, communicatively coupled to the processor and storing:

a device detection module to detect an unknown operational technology (OT) and/or Internet of Things (IoT) device, on the enterprise network comprising a plurality of known OT and IoT devices, by capturing network transactions related to downstream network devices and identifying the unknown OT or IoT device from non-OT or non-IoT network devices on the enterprise network, wherein the unknown OT or IoT device and the plurality of known OT and IoT devices are unable to internally execute non-native apps;

a device type module to determine a device type of the unknown OT or IoT device using an AIOP detection model, wherein the AIOP detection model is trained from unsupervised cluster learning from a history of externally captured network transactions of the plurality of known OT and IoT devices;

a device assessment module to assess vulnerabilities of the unknown OT or IoT device by predicting services from correlating the device type to the externally captured network transactions;

an intrusion monitoring module to monitor the unknown OT or IoT device to detect anomalous activity related to an assessed vulnerability of the unknown OT or IoT device, using an AIOP intrusion model generated from the history of known OT and IoT devices; and

a security action module to, responsive to detecting anomalous activity, take a security action based on relevant security rules.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: TARIMALA, NAGA KISHORE REDDY; JUPUDI, SIVA Y OGENDRA
To: FORTINET, INC.
Reel/Frame 068468/0659 →
Continuity (1)
Related Publication 20260064835A1 · Mar 5, 2026
References Cited (19)
US 10440577B1 · Vasseur · 2019 [cited by examiner]
US 12406069B2 · Kurian · 2025 [cited by examiner]
US 20110126111A1 · Gill · 2011 [cited by examiner]
US 20180129805A1 · Samuel · 2018 [cited by examiner]
US 20180219920A1 · Patel · 2018 [cited by examiner]
US 20180357560A1 · Di Pietro · 2018 [cited by examiner]
US 20200162516A1 · Israel · 2020 [cited by examiner]
US 20200202007A1 · Nagaraja · 2020 [cited by examiner]
US 20210014689A1 · Wang · 2021 [cited by examiner]
US 20230370334A1 · Mannengal · 2023 [cited by examiner]
US 20240223596A1 · Sellars · 2024 [cited by examiner]
US 20250384131A1 · Kornegay · 2025 [cited by examiner]
CN 117319066A · 2023 [cited by examiner]
KR 20220162774A · 2022 [cited by examiner]
KR 20240123461A · 2024 [cited by examiner]
WO WO2025097073A1 · 2025 [cited by examiner]
Machine translation of Kang, KR 2024-0123461, 1 page (Year: 2024). [cited by examiner]
Machine translation of Du et al, CN 117319066 A, pp. 1-3 (Year: 2023). [cited by examiner]
Machine translation of Du, KR 10-2022-0162774, p. 1 (Year: 2022). [cited by examiner]