Application Control System Intercepting Launch Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing application control systems face challenges in maintaining a secure and adaptable environment within computer networks, particularly in large organizations with diverse user needs, as they struggle to keep up with evolving threats and complex application updates while ensuring authorized applications can be accessed without compromising security.

Innovation Solution

A computer-implemented method and system that intercepts application launch requests, determines user interaction requirements, and uses a policy database to manage authorized applications, incorporating a secure gatekeeper agent that provides privilege management and custom messaging to ensure only approved applications are executed, while allowing users to interact with the system to override policies when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized application control system enforces strict security policies to block unauthorized applications, then network security is improved, but user productivity deteriorates due to restricted access to necessary applications

Engineering Contradiction:
Improvenetwork securityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements feedback mechanisms by monitoring application behavior and user interactions in real-time, allowing dynamic adjustment of security policies. When authorized applications exhibit suspicious behavior or when users require additional functionality, the system can respond by updating policies or requesting user verification, thus maintaining security while enabling productivity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The application control system transitions from static, pre-defined security policies to dynamic policy enforcement. Policies are adjusted in real-time based on contextual factors such as user role, application behavior, and security threats. This allows the system to be restrictive when necessary for security and permissive when safe, balancing security and productivity.

Inventive Principle:
Principle #15Dynamics

2Stability of the object's composition

If the application control system maintains a fixed set of authorized applications to ensure security, then system stability is improved, but adaptability to new threats and applications deteriorates

Engineering Contradiction:
Improvesystem stabilityVSAvoidadaptability to new threats
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by pre-configuring security policies and authorized application lists, but also prepares mechanisms for rapid updates. When new threats are identified or legitimate applications need to be authorized, the system can quickly update its controls without compromising the stability of the overall security framework.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The application control system incorporates self-service capabilities that allow it to automatically detect, evaluate, and respond to new applications and threats. Through automated scanning, behavior analysis, and policy adjustment, the system maintains stability while adapting to changing security landscapes without requiring constant manual intervention.

Inventive Principle:
Principle #25Self-service

3Reliability

If complex security rules are implemented to manage diverse user needs in large organizations, then security coverage is improved, but system complexity increases making management difficult

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The application control system segments security policies into manageable units organized by user roles, departments, or application categories. This segmentation allows complex security requirements to be broken down into simpler, reusable policy templates that can be easily configured and managed, reducing the burden of administering security in large organizations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal policy templates and centralized management capabilities that can be applied across multiple users and devices simultaneously. A single policy configuration can enforce security rules for entire user groups or application categories, reducing the complexity of managing diverse user needs while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If the system requires user interaction for each application launch to ensure security, then security control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidease of application launch
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies user interaction requirements selectively rather than universally. For authorized applications with verified safety profiles, the system allows automatic launch without user intervention. User interaction is only required for applications that trigger security policies, new applications, or those with elevated privileges, providing strong security control while maintaining ease of operation for legitimate use cases.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11537452B2Controlling applications by an application control system in a computer device
Publication Date: 2022.12.27 AVECTO
  • US11537452B2 patent drawing
  • US11537452B2 patent drawing
  • US11537452B2 patent drawing

AI summary

A computing device can intercept a request to launch a requested application. The request can be intercepted by a calling process executed by the computing device. The request can include information identifying the requested application. The computing device can determine that a user interaction is required before launching the requested application by consulting a set of application policies based on the information identifying the requested application. The computing device can establish that the calling process is associated with a controlling terminal provided by an operating system in response to determining that the user interaction is required. A process session group containing processes launched within a user session can be selectively associated with the controlling terminal by the operating system. The computing device can perform the user interaction using the controlling terminal in response to establishing that the calling process is associated with the controlling terminal.