Cloud Security Appliance for Ransomware Lateral Movement Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional enterprise security solutions are inadequate in preventing lateral movement of ransomware within shared VLAN environments, as firewalls provide limited protection for east-west communication, and endpoint protection methods are challenging to deploy and manage, especially on IoT devices.

Innovation Solution

A cloud-based security appliance is deployed as the default gateway with a subnet mask of 255.255.255.255 to monitor and control intra-VLAN communication, detecting and preventing lateral propagation of ransomware by forcing all traffic through the appliance and quarantining compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall is deployed to provide protection against ransomware attacks, then external attack protection is improved, but intra-VLAN communication monitoring capability deteriorates

Engineering Contradiction:
Improveprotection against external ransomware attacksVSAvoidvisibility of east-west communication
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based security appliance as an intermediary component that sits between endpoint devices and the network. This appliance receives copies of network traffic packets from endpoints, analyzes them for ransomware indicators, and can block malicious communications. The intermediary approach allows the firewall to maintain its external protection function while the security appliance provides the missing intra-VLAN monitoring capability without requiring the firewall itself to become more complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If endpoint protection agents are deployed on each device to detect malicious processes, then detection capability is improved, but deployment and management complexity deteriorates

Engineering Contradiction:
Improvedetection of malicious ransomware processesVSAvoiddeployment and management of protection agents
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent replaces the need for endpoint protection agents with a cloud-based security appliance that performs all detection functions centrally. The appliance receives network traffic packets from endpoints and analyzes them for ransomware indicators, eliminating the need to deploy, update, and manage protection agents on each individual device. This intermediary approach maintains precise detection capability while dramatically simplifying deployment and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security appliance operates autonomously in the cloud, automatically receiving network traffic packets from endpoints, analyzing them for ransomware indicators, and blocking malicious communications without requiring manual intervention for deployment or management. The system serves itself by autonomously performing detection and response functions that would otherwise require complex agent management across multiple devices.

Inventive Principle:
Principle #25Self-service

3Reliability

If VLAN segmentation is implemented by department to provide protection layers, then network segmentation protection is improved, but lateral movement prevention within VLAN deteriorates

Engineering Contradiction:
Improveprotection layers between departmentsVSAvoidlateral propagation of ransomware within VLAN
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based security appliance as an intermediary that monitors and analyzes all network traffic packets within the VLAN environment. The appliance receives copies of packets from all endpoints, analyzes them for ransomware indicators, and can block malicious communications before they propagate laterally within the VLAN. This intermediary approach maintains the existing VLAN segmentation structure while adding a layer of security that prevents lateral movement without requiring changes to the VLAN architecture itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11303669B1System and method for tunneling endpoint traffic to the cloud for ransomware lateral movement protection
Publication Date: 2022.04.12 ZSCALER INC
  • US11303669B1 patent drawing
  • US11303669B1 patent drawing
  • US11303669B1 patent drawing

AI summary

A technique to stop lateral movement of ransomware between endpoints in a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication. Message traffic from compromised endpoints is detected. Attributes of ransomware may be detected in the message traffic, as well as attempts to circumvent the security appliance. Compromised devices may be quarantined.