Client-Side Security Threat Awareness via Local Application Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions for protecting remotely connected devices from security threats, such as backhauling and intrusion detection systems, can overwhelm enterprise networks and are costly, while also potentially slowing down critical business applications, and rely on human vigilance that may lead to unintentional security risks.
Innovation Solution
A method that provides real-time security threat awareness to users by detecting open and active applications on client computing devices, assigning security scores, and visually indicating these scores through a graphical user interface, allowing users to take mitigating actions to reduce security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If backhauling policies are implemented to force network traffic from remote devices to pass through the enterprise, then security visibility and threat identification are improved, but network infrastructure stress and operational cost increase significantly
Solution Approach 1:
The patent extracts the security analysis function from the enterprise network infrastructure and relocates it to the remote client device. The client device independently performs IPS/IDS scanning on its own network traffic locally, eliminating the need for high-volume traffic backhauling through the enterprise network while maintaining security visibility and threat identification capabilities.
2Reliability
If IPS/IDS scanning is performed on high volume traffic, then security threat identification is improved, but operational cost increases
Solution Approach 1:
The security scanning function is extracted from the enterprise infrastructure and embedded in the client device software. This allows security analysis to be performed locally on a minimal amount of traffic generated by the scanning process itself, rather than analyzing high-volume backhauled traffic, dramatically reducing operational costs while maintaining threat identification effectiveness.
Solution Approach 2:
The client device performs self-diagnostic security scanning on its own network traffic. The locally installed software autonomously monitors and analyzes network packets generated by applications on the client device, enabling the system to self-identify security threats without requiring expensive enterprise infrastructure resources.
3Reliability
If traditional security solutions are deployed to protect remote devices, then security protection is improved, but critical business applications are slowed down
Solution Approach 1:
The security scanning operation is extracted from the critical network path and performed locally on minimal diagnostic traffic. Since the client device scans its own independently generated traffic rather than having all business traffic routed through enterprise security infrastructure, business applications experience no slowdown while security protection is maintained.
Data Source
AI summary
A method for providing a visual indication of the security threat awareness level is disclosed. Such a visual indication helps improve the security of a device or an enterprise by giving a user an indication of the security risks associated with currently open and active applications. In turn, the user can use the visual indication as a cue to take mitigating actions to reduce the security risk, such as by using the application more carefully or by exiting the application. Each application is assigned a security score and the system determines the security threat awareness level based on the security score(s) of the open and active applications.


