Client-Side Security Threat Awareness via Local Application Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for protecting remotely connected devices from security threats, such as backhauling and intrusion detection systems, can overwhelm enterprise networks and are costly, while also potentially slowing down critical business applications, and rely on human vigilance that may lead to unintentional security risks.

Innovation Solution

A method that provides real-time security threat awareness to users by detecting open and active applications on client computing devices, assigning security scores, and visually indicating these scores through a graphical user interface, allowing users to take mitigating actions to reduce security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If backhauling policies are implemented to force network traffic from remote devices to pass through the enterprise, then security visibility and threat identification are improved, but network infrastructure stress and operational cost increase significantly

Engineering Contradiction:
Improvesecurity visibilityVSAvoidnetwork infrastructure stress
Core Design Contradiction:
ReliabilityVSStress or pressure

Solution Approach 1:

The patent extracts the security analysis function from the enterprise network infrastructure and relocates it to the remote client device. The client device independently performs IPS/IDS scanning on its own network traffic locally, eliminating the need for high-volume traffic backhauling through the enterprise network while maintaining security visibility and threat identification capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If IPS/IDS scanning is performed on high volume traffic, then security threat identification is improved, but operational cost increases

Engineering Contradiction:
Improvesecurity threat identificationVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The security scanning function is extracted from the enterprise infrastructure and embedded in the client device software. This allows security analysis to be performed locally on a minimal amount of traffic generated by the scanning process itself, rather than analyzing high-volume backhauled traffic, dramatically reducing operational costs while maintaining threat identification effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The client device performs self-diagnostic security scanning on its own network traffic. The locally installed software autonomously monitors and analyzes network packets generated by applications on the client device, enabling the system to self-identify security threats without requiring expensive enterprise infrastructure resources.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional security solutions are deployed to protect remote devices, then security protection is improved, but critical business applications are slowed down

Engineering Contradiction:
Improvesecurity protectionVSAvoidbusiness application speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The security scanning operation is extracted from the critical network path and performed locally on minimal diagnostic traffic. Since the client device scans its own independently generated traffic rather than having all business traffic routed through enterprise security infrastructure, business applications experience no slowdown while security protection is maintained.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11595428B2Application security threat awareness
Publication Date: 2023.02.28 CITRIX SYSTEMS INC
  • US11595428B2 patent drawing
  • US11595428B2 patent drawing
  • US11595428B2 patent drawing

AI summary

A method for providing a visual indication of the security threat awareness level is disclosed. Such a visual indication helps improve the security of a device or an enterprise by giving a user an indication of the security risks associated with currently open and active applications. In turn, the user can use the visual indication as a cue to take mitigating actions to reduce the security risk, such as by using the application more carefully or by exiting the application. Each application is assigned a security score and the system determines the security threat awareness level based on the security score(s) of the open and active applications.