Dynamic Endpoint Modeling and Grouping for Edge Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The detection and prevention of malware, such as viruses and ransomware, in modern enterprise networks are challenging due to their elastic nature, which extends beyond traditional firewall boundaries, and existing systems struggle to protect against both known and unknown threats, especially when endpoints are outside the firewall.
Innovation Solution
A dynamic endpoint-based edge networking system with agents installed on endpoints to monitor operating system processes and network communications, utilizing artificial intelligence to identify anomalous indicators, and a central server to analyze network-wide patterns, enabling real-time security protocols and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall-based network security systems are used, then network perimeter protection is provided, but they cannot effectively protect endpoints outside the firewall boundary
Solution Approach 1:
The patent segments the network security architecture into multiple distributed agents deployed at different endpoints rather than a single centralized firewall. Each agent independently monitors and protects its local endpoint, enabling security coverage both inside and outside traditional firewall boundaries. This segmentation allows the system to adapt to elastic network configurations where endpoints may move between network perimeters.
Solution Approach 2:
The patent transitions from a single-dimension perimeter-based security model to a multi-dimensional approach by deploying security agents at the endpoint level across the entire network ecosystem. This includes endpoints both within and outside traditional firewall boundaries, creating a distributed security mesh that operates in multiple network dimensions simultaneously.
2Measurement precision
If centralized security monitoring is implemented, then network-wide threat detection is achieved, but real-time response at individual endpoints is delayed
Solution Approach 1:
The patent merges centralized security management capabilities with distributed endpoint execution. The central server provides comprehensive threat detection and analysis across the entire network, while local agents at each endpoint independently execute security protocols and respond to threats in real-time. This combination allows both network-wide monitoring accuracy and immediate local response actions.
Solution Approach 2:
The system implements continuous feedback loops where local agents collect endpoint data and transmit it to the central server for analysis. The central server processes this information, identifies threats, and sends back response instructions to the appropriate agents. This feedback mechanism enables both accurate centralized detection and rapid localized response through the iterative exchange of security information.
3Reliability
If distributed security agents are deployed at all endpoints, then real-time local security monitoring is achieved, but system complexity and resource consumption increase
Solution Approach 1:
The patent implements a universal agent architecture that can be deployed across diverse endpoint types (workstations, servers, mobile devices, IoT devices) with a single standardized software package. This universal agent provides multiple security functions including threat detection, data collection, protocol execution, and communication with the central server, reducing the need for different specialized security systems for different device types.
Solution Approach 2:
The system dynamically adjusts security monitoring parameters and agent behavior based on endpoint characteristics, threat levels, and network conditions. Agents can modify their data collection frequency, protocol execution intensity, and communication patterns to optimize resource consumption while maintaining effective security coverage, thereby reducing overall system complexity.
4Loss of information
If continuous monitoring of all endpoint activities is performed, then comprehensive security visibility is achieved, but processing workload and data transmission volume increase
Solution Approach 1:
The patent implements selective monitoring where agents continuously collect comprehensive endpoint data but only transmit information of security relevance to the central server. The system performs partial action by filtering and prioritizing data transmission based on threat indicators, anomaly detection, and configured security policies, thereby maintaining complete security visibility while reducing network bandwidth consumption.
Data Source
AI summary
Various embodiments described herein disclose an endpoint modeling and grouping management system that can collect data from endpoint computer devices in a network. In some embodiments, agents installed on the endpoints can collect real-time information at the kernel level providing the system with deep visibility. In some embodiments, the endpoint modeling and grouping management system can identify similarities in behavior in response to assessing the data collected by the agents. In some embodiments, the endpoint modeling and grouping management system can dynamically model groups such as logical groups, and cluster endpoints based on the similarities and/or differences in behavior of the endpoints. In some embodiments, the endpoint modeling and grouping management system transmits the behavioral models to the agents to allow the agents to identify anomalies and/or security threats autonomously.


