Endpoint Agent Selective Event Subscription for Security Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Endpoint devices face security risks due to various activities, and existing technologies lack effective methods to selectively monitor and control these activities, leading to potential security compromises.

Innovation Solution

A system and method for operating an endpoint agent that selectively subscribes to events, processes relevant messages from a message bus, and communicates information to a service, enabling enhanced security monitoring and control on endpoint devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an endpoint agent monitors all activities on an endpoint device, then security coverage is improved, but system performance and resource consumption deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The monitoring system is segmented into multiple specialized agents, each responsible for specific event types (process creation, network connections, file operations). This segmentation allows the system to monitor comprehensive security events while each agent processes only its designated subset, reducing individual agent overhead and improving overall system performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The endpoint agent selectively subscribes to and processes only specific events relevant to security monitoring rather than all possible system events. This partial action approach filters out unnecessary data, reducing processing load and resource consumption while maintaining effective security coverage for critical operations.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If an endpoint agent monitors all activities on an endpoint device, then security coverage is improved, but resource consumption deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The monitoring system is segmented into multiple specialized agents, each responsible for specific event types (process creation, network connections, file operations). This segmentation allows the system to monitor comprehensive security events while each agent processes only its designated subset, reducing individual agent overhead and improving overall system performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The endpoint agent selectively subscribes to and processes only specific events relevant to security monitoring rather than all possible system events. This partial action approach filters out unnecessary data, reducing processing load and resource consumption while maintaining effective security coverage for critical operations.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If an endpoint agent selectively subscribes to specific events, then system efficiency is improved, but security coverage may deteriorate

Engineering Contradiction:
Improvesystem efficiencyVSAvoidsecurity coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The endpoint agent architecture implements multi-functionality through a standardized event subscription and processing framework that can be configured for different security monitoring needs. The same agent infrastructure handles diverse event types (process, network, file, registry), ensuring comprehensive security coverage while maintaining system efficiency through selective event processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where the endpoint agent continuously monitors event streams, processes security-relevant events, and communicates findings to central management. This feedback loop ensures that selective event monitoring maintains adequate security coverage by dynamically adjusting monitoring based on detected threats and security policies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12169561B2System and method for operating an endpoint agent at an endpoint device
Publication Date: 2024.12.17 FORCEPOINT LLC
  • US12169561B2 patent drawing
  • US12169561B2 patent drawing
  • US12169561B2 patent drawing

AI summary

A method, system and computer-usable medium are disclosed for operating an endpoint agent at an endpoint device. Certain embodiments include a computer-implemented method for operating an endpoint agent at an endpoint device, including: operating the endpoint agent to selectively subscribe to events corresponding to activities occurring at an endpoint platform; processing events received from a message bus by the endpoint agent, where the events processed by the endpoint agent are events to which the endpoint agent has subscribed; and communicating, to a service, information corresponding to the events processed by the endpoint agent. Other embodiments of this aspect of the invention may include corresponding stand-alone and/or network computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform one or more of these actions.