Fortinet, Inc.
Learning network topology and monitoring compliance with security goals

Last updated:

Abstract:

Systems and methods for monitoring compliance with security goals by a network or part thereof are provided. According to one embodiment, a topology of a network segment of a private network is discovered by a network security device associated with the private network. Security policies implemented by one or more network security devices that form part of the network segment are learned by the network security device. Compliance with a security goal associated with the network segment is then determined by the network security device by: (i) analyzing traffic passing through the network segment; (ii) analyzing respective system configurations of the one or more network security devices; and (iii) evaluating performance of the security policies based on the traffic.

Status:
Grant
Type:

Utility

Filling date:

27 Dec 2017

Issue date:

17 Nov 2020