Endpoint Agent Network Security with Dynamic Micro-Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security solutions fail to provide a comprehensive barrier against attackers, particularly in preventing data exfiltration, as they often rely on traditional methods that can be bypassed by sophisticated attackers, and internal network segmentation is costly and difficult to implement effectively.

Innovation Solution

A computer network security system that includes endpoint agents and a central controller to dynamically monitor and control network connections, enforcing granular, real-time policies and segmentation, allowing for dynamic micro-segmentation within existing networks, and supporting enhanced authentication and failover rules to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network segmentation is implemented, then security is improved, but cost and implementation difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements micro-segmentation by dividing the network into fine-grained segments based on individual host, service, or application levels rather than traditional broad network zones. Each segment is isolated through software-defined boundaries, enabling precise security control without requiring complex physical network reconfiguration. This resolves the contradiction by providing comprehensive security through segmentation while maintaining implementation simplicity through software-based approaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces traditional mechanical network segmentation using physical firewalls, routers, and VLAN configurations with a software-defined segmentation mechanism. The system uses virtualization and software-based policy enforcement to create network segments dynamically, eliminating the need for complex hardware reconfiguration and reducing implementation difficulty while maintaining security effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If real-time network monitoring is implemented, then visibility and control are improved, but system complexity increases

Engineering Contradiction:
ImprovevisibilityVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a unified security platform that performs multiple functions including real-time monitoring, policy enforcement, threat detection, and incident response through a single integrated system. The controller coordinates various security components and agents across the network, consolidating what would otherwise require multiple separate systems into one manageable platform that provides comprehensive visibility without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a centralized controller as an intermediary component that manages real-time monitoring activities. The controller receives data from network agents, processes information, and coordinates security responses across the network. This intermediary architecture distributes the monitoring burden and provides centralized intelligence, improving visibility while managing system complexity through coordinated control rather than requiring every network element to be fully monitored independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If dynamic policy control is implemented, then security responsiveness is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity responsivenessVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security policies that automatically adapt to changing network conditions, threats, and business requirements. The system continuously monitors network activity and adjusts access controls, segmentation boundaries, and security responses in real-time based on detected threats and policy rules. This dynamic approach improves security responsiveness by allowing the system to adapt to new threats without manual reconfiguration, while operational complexity is managed through automation and centralized policy management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3289476B1Computer network security system
Publication Date: 2022.01.26 FORTINET INC
  • EP3289476B1 patent drawingFigure 1
  • EP3289476B1 patent drawingFigure 2
  • EP3289476B1 patent drawingFigure 3

AI summary

A computer network security system includes a central controller in communication with software-based endpoint agents operating on individual host computers. The endpoint agents monitor new connection requests to and from their respective hosts, comparing the connections to cached rules obtained from the controller, and holding new connections while escalating requests for applicable rules and/or directives to the controller in real-time when no applicable rules are available in their caches. The endpoint agents can be configured to present a pop-up dialog requesting enhanced authentication credentials from a user on a host in response to a connection request from a restricted network-based application. The pop-up dialog enables enhanced or two-factor authentication functionality to be overlaid on any networked application regardless of the application's inherent authentication capability.