Adaptive Endpoint Security Policy Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional endpoint security systems rely on static policies, which fail to dynamically adjust security measures in response to emerging threats, leaving an open attack surface until manual intervention occurs, thus compromising network stability and user productivity.

Innovation Solution

A conditional policy engine that automatically applies adaptive security policies based on real-time threat assessments, transitioning endpoints between different security profiles to enhance or reduce security enforcement according to the risk level, thereby reducing the attack surface and facilitating rapid threat remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security policies are used, then security enforcement is simple and stable, but the attack surface remains open until manual intervention occurs

Engineering Contradiction:
Improvesecurity enforcementVSAvoidtime to remediate threat
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust based on real-time threat detection. The system transitions from static policies to dynamic policies that adapt to changing security conditions, enabling automatic response to threats without manual intervention and reducing the time the attack surface remains open.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where security events are continuously monitored and analyzed. When threats are detected, the system receives feedback about the security state and automatically adjusts policies accordingly, creating a closed-loop system that responds to security conditions in real-time.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual intervention is required for policy changes, then security control is precise, but productivity is reduced due to response delays

Engineering Contradiction:
Improvesecurity control precisionVSAvoidendpoint usability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service security management where the security infrastructure automatically detects threats, analyzes them, and applies appropriate policy changes without requiring manual analyst intervention. This maintains security control precision through automated decision-making while preserving endpoint productivity by eliminating response delays.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring multiple security policies and having them automatically applied based on detected threat conditions. Rather than waiting for manual intervention, the system has remedial actions ready to be applied immediately when threats are detected, maintaining both precision and productivity.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If dynamic security policies are implemented, then the attack surface is reduced in real-time, but system complexity increases

Engineering Contradiction:
Improveattack surfaceVSAvoidsecurity system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system segments security policies into distinct, manageable configurations that can be independently applied based on specific threat conditions. By dividing the security response into discrete policy segments rather than a monolithic complex system, the solution reduces the attack surface through targeted controls while managing complexity through modular policy design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240089273A1Systems, methods, and devices for risk aware and adaptive endpoint security controls
Publication Date: 2024.03.14 SENTINELONE INC
  • US20240089273A1 patent drawing
  • US20240089273A1 patent drawing
  • US20240089273A1 patent drawing

AI summary

A computer-implemented method may include detecting, by an agent running on a first computing system, information indicative of a security threat, wherein the first computing system is operating with a first security policy. A method may include sending, from the first computing system to a second computing system via a network connection, an indication of the security threat. A method may include receiving, by the first computing system from the second computing system via the network connection, an indication of a second security policy to apply. A method may include applying, by the agent, the second security policy to the first computing system.