Agent-Based Endpoint Modeling for Elastic Edge Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise networks face challenges in protecting against both known and unknown malware due to their elastic nature, which extends beyond traditional firewall boundaries, and current security systems lack the ability to continuously verify endpoint integrity and manage network access effectively.
Innovation Solution
A dynamic endpoint-based edge networking system that employs agents installed on endpoints to monitor operating system processes and network communications, transmit data to a central server for network-wide analysis, and apply local and network-wide security protocols to identify and respond to anomalous indicators, ensuring continuous verification and authentication of endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall-based network security is used, then network boundary protection is provided, but it cannot effectively protect elastic networks with endpoints outside the firewall
Solution Approach 1:
The patent divides network security into two layers: perimeter firewall protection for traditional boundary security and endpoint-based agents for distributed security across elastic network components. This segmentation allows each layer to address specific security needs without compromising the other.
Solution Approach 2:
The patent transitions from two-dimensional perimeter-based security to three-dimensional security by adding the endpoint dimension. Agents installed on endpoints create security coverage in the previously unprotected dimension of distributed network components outside the firewall.
2Reliability
If endpoints are continuously monitored and authenticated, then security and integrity are improved, but system complexity and computational overhead increase
Solution Approach 1:
The patent implements self-service mechanisms where endpoint agents autonomously perform integrity verification, self-authentication, and compliance checking. This reduces the need for complex centralized management while maintaining continuous monitoring capabilities.
Solution Approach 2:
The patent performs preliminary authentication and integrity verification before endpoints access network resources. This proactive approach prevents unauthorized access and reduces the need for complex real-time monitoring during operation.
3Measurement precision
If deep visibility into endpoint processes and communications is obtained, then malware detection accuracy is improved, but privacy concerns and data security risks increase
Solution Approach 1:
The patent introduces encrypted communication channels and secure enclaves as intermediaries between the monitoring agent and the data being monitored. This allows deep visibility for malware detection while protecting sensitive data through cryptographic safeguards.
Solution Approach 2:
The patent applies different monitoring intensities and privacy protection levels to different types of data and processes. Sensitive operations receive enhanced privacy protection while less sensitive operations undergo more rigorous monitoring, optimizing both detection accuracy and privacy preservation.
Data Source
AI summary
Various embodiments described herein disclose an endpoint modeling and grouping management system that can collect data from endpoint computer devices in a network. In some embodiments, agents installed on the endpoints can collect real-time information at the kernel level providing the system with deep visibility. In some embodiments, the endpoint modeling and grouping management system can identify similarities in behavior in response to assessing the data collected by the agents. In some embodiments, the endpoint modeling and grouping management system can dynamically model groups such as logical groups, and cluster endpoints based on the similarities and/or differences in behavior of the endpoints. In some embodiments, the endpoint modeling and grouping management system transmits the behavioral models to the agents to allow the agents to identify anomalies and/or security threats autonomously.


