EDR Agent Context Sharing for NAC Compromised Device Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies operate in silos, failing to share information that could be mutually beneficial for efficient detection of compromised devices, leading to fragmented security responses.

Innovation Solution

The integration of multiple endpoint security agents, such as EDR, UEBA, NAC, and UTM agents, into a super-agent framework that communicates and collaborates to collect and share data across security services, enabling synergistic detection and response to security incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security agents (EDR, NAC, UTM) operate independently in silos, then each agent can maintain its own specialized security functions, but information sharing between agents is lost and detection efficiency decreases

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidinformation sharing between agents
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges multiple independent security agents (EDR, NAC, UTM) into a unified security platform where they share a common data lake and correlation engine. This allows each agent to maintain its specialized detection capabilities while simultaneously sharing information through the common data structure, resolving the contradiction between operational independence and information sharing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security platform that performs multiple security functions through a single integrated system. The common data lake and correlation engine serve as universal components that handle data from all agent types, enabling the system to provide EDR, NAC, and UTM functionalities while maintaining information sharing across all security operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If security agents share and integrate data from multiple sources, then detection efficiency and threat identification improve, but system complexity increases

Engineering Contradiction:
Improvedetection efficiencyVSAvoidsystem integration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the security system into distinct modular components: individual security agents (EDR, NAC, UTM), a standardized data collection layer, a common data lake, and a correlation engine. This segmentation allows each component to be developed and maintained independently while working together through well-defined interfaces, reducing overall system complexity despite the multi-agent architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a common data lake as an intermediary layer between the security agents and the correlation engine. This mediator standardizes data from diverse agent sources into a unified format, simplifying the integration process and reducing complexity by providing a single interface for data exchange rather than requiring direct peer-to-peer connections between all agents.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If security agents proactively collect and share data, then threat detection capability improves, but data processing overhead increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddata processing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by having security agents proactively collect and store security data in the common data lake before threats materialize. This advance data collection enables the correlation engine to perform real-time analysis without waiting for events to occur, improving detection capability while distributing the processing load across the proactive collection phase rather than concentrating it during threat response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11856008B2Facilitating identification of compromised devices by network access control (NAC) or unified threat management (UTM) security services by leveraging context from an endpoint detection and response (EDR) agent
Publication Date: 2023.12.26 FORTINET INC
  • US11856008B2 patent drawing
  • US11856008B2 patent drawing
  • US11856008B2 patent drawing

AI summary

Systems and methods are provided for synergistically combining network security technologies to detect compromised devices. According to one embodiment, an endpoint detection and response (EDR) agent of multiple endpoint security agents running on an endpoint device detects an incident. A security incident alert is generated by the EDR agent by proactively collecting data regarding the incident. Identification of a device coupled to a private network as potentially being compromised by a security service of a Managed Security Service Provider (MSSP) protecting the private network is facilitated by the EDR agent transmitting the security incident alert to the security service via a security agent of the multiple endpoint security agents corresponding to the security service.