Dynamic Endpoint Modeling and Grouping for Edge Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems struggle to protect enterprise networks from both known and unknown malware, especially in elastic networks that extend beyond traditional firewalls, as they fail to continuously verify endpoint integrity and adapt to changing network conditions.

Innovation Solution

A dynamic endpoint-based edge networking system with agents installed on endpoint devices that continuously monitor and analyze operating system processes and network communications, using AI to identify anomalies and enforce security protocols, allowing for real-time adaptation and control of network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewall-based security systems are used to protect enterprise networks, then network security is maintained within fixed boundaries, but the system cannot protect elastic networks that extend beyond traditional firewalls including cloud computing facilities and mobile devices

Engineering Contradiction:
Improvenetwork security coverageVSAvoidsecurity system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the enterprise network into multiple elastic network segments, each with its own security boundaries defined by endpoint devices rather than physical firewalls. This allows security to be applied at the endpoint level across distributed networks including cloud and mobile devices, resolving the contradiction between extended coverage and system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security boundaries that adapt to changing network conditions and endpoint trust levels. Security perimeters are not fixed but dynamically adjusted based on continuous monitoring of endpoint behavior and network activity, enabling protection of elastic networks while maintaining manageable complexity through automated adaptation.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If security systems monitor all endpoint activities continuously to detect malware, then detection accuracy is improved, but system performance and resource consumption increase

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidendpoint system performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial monitoring by focusing security analysis on specific high-risk activities and endpoints rather than uniformly monitoring all activities on all devices. The system selectively intensifies monitoring based on threat indicators, maintaining high detection accuracy while reducing overall system resource consumption and preserving endpoint productivity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements self-service security where endpoint devices autonomously perform local security analysis and enforcement using embedded agents. This distributes the monitoring workload from centralized servers to individual endpoints, improving detection accuracy through local real-time analysis while avoiding the performance degradation that would result from centralized processing of all endpoint data.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If IT administrators manually manage security for each endpoint device, then security control precision is maintained, but administrative workload increases significantly

Engineering Contradiction:
Improvesecurity control precisionVSAvoidIT administrator workload
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements automated feedback loops where security agents continuously monitor endpoint behavior, compare it against established baselines and threat intelligence, and automatically adjust security controls in response. This closed-loop system maintains precise security control by dynamically responding to detected anomalies while eliminating the need for manual administrator intervention in routine security management tasks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables security systems to self-manage through automated policy enforcement and adaptive control mechanisms. Security agents on endpoint devices autonomously implement security decisions based on centralized policy guidance and local condition assessment, maintaining precise control over individual endpoints while dramatically reducing IT administrator workload through automation of routine security management functions.

Inventive Principle:
Principle #25Self-service

4Reliability

If security protocols are strictly enforced on all endpoint devices, then security reliability is improved, but network accessibility and user convenience decrease

Engineering Contradiction:
Improvenetwork security reliabilityVSAvoidnetwork access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different security control intensities to different endpoints based on their trust levels, roles, and behavior histories. Rather than uniformly enforcing strict security protocols on all devices, the system tailors security measures to local conditions, maintaining high reliability for critical endpoints while allowing greater convenience for trusted or low-risk devices, thus resolving the contradiction between security reliability and operational ease.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250267160A1Methods, systems, and devices for dynamically modeling and grouping endpoints for edge networking
Publication Date: 2025.08.21 SENTINEL LABS ISRAEL
  • US20250267160A1 patent drawing
  • US20250267160A1 patent drawing
  • US20250267160A1 patent drawing

AI summary

Various embodiments described herein disclose an endpoint modeling and grouping management system that can collect data from endpoint computer devices in a network. In some embodiments, agents installed on the endpoints can collect real-time information at the kernel level providing the system with deep visibility. In some embodiments, the endpoint modeling and grouping management system can identify similarities in behavior in response to assessing the data collected by the agents. In some embodiments, the endpoint modeling and grouping management system can dynamically model groups such as logical groups, and cluster endpoints based on the similarities and/or differences in behavior of the endpoints. In some embodiments, the endpoint modeling and grouping management system transmits the behavioral models to the agents to allow the agents to identify anomalies and/or security threats autonomously.