Endpoint Application Isolation via Secure Container

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current endpoint security solutions are resource-intensive and prone to false positives, as they rely on monitoring all applications for abnormal behavior, which can lead to ineffective protection against evolving malware threats that exploit known good applications.

Innovation Solution

Implementing a secure container to isolate applications with known or potential vulnerabilities, allowing them to run in a sandboxed environment, thereby reducing resource usage and minimizing disruptions to user productivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security solutions monitor the activities of all applications to identify abnormal behavior, then protection capability is improved, but resource consumption increases significantly

Engineering Contradiction:
Improveprotection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments applications into two groups: Group A (applications with known vulnerabilities or patches) and Group B (all other applications). This segmentation allows the security solution to apply different monitoring strategies to different groups, reducing overall resource consumption while maintaining protection capability. Group A applications are monitored for specific vulnerability-related behaviors, while Group B applications receive standard security treatment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing targeted monitoring only for applications with known vulnerabilities or patches, rather than uniformly monitoring all applications. This localized approach focuses security resources on high-risk applications, improving protection capability where needed most while reducing unnecessary resource consumption on low-risk applications.

Inventive Principle:
Principle #3Local quality

2Reliability

If security solutions monitor all applications for abnormal behavior, then protection capability is improved, but false positives increase leading to reduced user productivity

Engineering Contradiction:
Improveprotection capabilityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting applications into Group A (with known vulnerabilities/patches) and Group B (others), the patent reduces false positives by not applying abnormal behavior monitoring to all applications. This segmentation ensures that user productivity is maintained for applications that don't require intensive monitoring, while still providing protection for vulnerable applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing abnormal behavior monitoring only locally for Group A applications with known vulnerabilities or patches. This targeted approach minimizes false positives and interruptions to user workflow for applications in Group B, thereby maintaining user productivity while still providing protection where needed.

Inventive Principle:
Principle #3Local quality

3Reliability

If security solutions monitor core system parameters against all applications, then protection capability is improved, but resource consumption increases

Engineering Contradiction:
Improveprotection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments monitoring requirements by applying core system parameter monitoring only to Group A applications (those with known vulnerabilities or patches) rather than to all applications. This segmentation reduces resource consumption by eliminating unnecessary monitoring of applications that don't pose vulnerability risks, while maintaining protection capability for high-risk applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying core system parameter monitoring locally only to Group A applications with known vulnerabilities or patches. This targeted monitoring approach reduces overall resource consumption while maintaining protection capability where vulnerability risks exist.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If security solutions watch activities of all applications to identify abnormal behavior, then detection accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the detection approach by creating separate handling logic for Group A applications (with known vulnerabilities/patches) and Group B applications. This segmentation simplifies the overall system by providing clear, distinct monitoring rules for each group, reducing device complexity compared to a unified monitoring approach for all applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing detection logic tailored to specific application groups. Group A applications receive specialized monitoring for vulnerability-related behaviors, while Group B applications receive standard monitoring. This localized approach maintains detection accuracy for vulnerable applications while reducing system complexity through simplified, group-specific rules.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10951644B1Auto-containment of potentially vulnerable applications
Publication Date: 2021.03.16 COMODO SECURITY SOLUTIONS INC
  • US10951644B1 patent drawing
  • US10951644B1 patent drawing
  • US10951644B1 patent drawing

AI summary

There is provided a method and system for advanced endpoint protection. With this methodology, when a file is requested to be executed on any endpoint, all intelligence sources would be checked to decide if that file has any known or potential vulnerability associated with it. If there is any information about any known or potential vulnerability, it would be launched inside the secure container to isolate the all resource usage of that application from the rest of the known good and secure applications in order to achieve the securest computing environment on an endpoint.