EDR Agent Context Sharing for NAC Compromised Device Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies operate in silos, failing to share information that could be mutually beneficial for efficient detection of compromised devices, leading to fragmented security responses.
Innovation Solution
The integration of multiple endpoint security agents, such as EDR, UEBA, NAC, and UTM agents, into a super-agent framework that communicates and collaborates to collect and share data across security services, enabling synergistic detection and response to security incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security agents (EDR, NAC, UTM) operate independently in silos, then each agent can maintain its own specialized security functions, but information sharing between agents is lost and detection efficiency decreases
Solution Approach 1:
The patent merges multiple independent security agents (EDR, NAC, UTM) into a unified security platform where they share a common data lake and correlation engine. This allows each agent to maintain its specialized detection capabilities while simultaneously sharing information through the common data structure, resolving the contradiction between operational independence and information sharing.
Solution Approach 2:
The patent creates a universal security platform that performs multiple security functions through a single integrated system. The common data lake and correlation engine serve as universal components that handle data from all agent types, enabling the system to provide EDR, NAC, and UTM functionalities while maintaining information sharing across all security operations.
2Productivity
If security agents share and integrate data from multiple sources, then detection efficiency and threat identification improve, but system complexity increases
Solution Approach 1:
The patent segments the security system into distinct modular components: individual security agents (EDR, NAC, UTM), a standardized data collection layer, a common data lake, and a correlation engine. This segmentation allows each component to be developed and maintained independently while working together through well-defined interfaces, reducing overall system complexity despite the multi-agent architecture.
Solution Approach 2:
The patent introduces a common data lake as an intermediary layer between the security agents and the correlation engine. This mediator standardizes data from diverse agent sources into a unified format, simplifying the integration process and reducing complexity by providing a single interface for data exchange rather than requiring direct peer-to-peer connections between all agents.
3Measurement precision
If security agents proactively collect and share data, then threat detection capability improves, but data processing overhead increases
Solution Approach 1:
The patent implements preliminary action by having security agents proactively collect and store security data in the common data lake before threats materialize. This advance data collection enables the correlation engine to perform real-time analysis without waiting for events to occur, improving detection capability while distributing the processing load across the proactive collection phase rather than concentrating it during threat response.
Data Source
AI summary
Systems and methods are provided for synergistically combining network security technologies to detect compromised devices. According to one embodiment, an endpoint detection and response (EDR) agent of multiple endpoint security agents running on an endpoint device detects an incident. A security incident alert is generated by the EDR agent by proactively collecting data regarding the incident. Identification of a device coupled to a private network as potentially being compromised by a security service of a Managed Security Service Provider (MSSP) protecting the private network is facilitated by the EDR agent transmitting the security incident alert to the security service via a security agent of the multiple endpoint security agents corresponding to the security service.


