Endpoint Flow Labeling for Enterprise Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in securing endpoints against malicious activities, particularly in preventing data leakage and other negative consequences due to the lack of effective monitoring and labeling of network flows.

Innovation Solution

Implementing a system that instruments endpoints to explicitly label network flows based on their sources, allowing for the extraction and processing of application reputations, and conditional routing of network messages, which includes cryptographically signing labels to verify endpoint identities and manage network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network flows are monitored and labeled at endpoints, then network security and detection precision are improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvenetwork flow detection precisionVSAvoidendpoint instrumentation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary labeling system where endpoints are instrumented with lightweight agents that attach security labels to network flows. These labels serve as intermediaries between the complex endpoint environment and the simplified network-level monitoring, allowing detailed application identification without burdening the network infrastructure with complex analysis capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security monitoring function is segmented into distributed endpoint agents that independently label their own network flows. This segmentation distributes the complexity across multiple simple agents rather than requiring a single complex centralized system, improving detection precision through local context while managing overall system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

2Reliability

If all network messages are inspected and routed conditionally, then security control and reliability are improved, but processing time and loss of time increase

Engineering Contradiction:
Improvenetwork security controlVSAvoidnetwork message processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-labeling network flows at the source endpoint before they traverse the network. This preliminary classification allows downstream network devices to make routing decisions based on pre-computed labels rather than performing complex analysis in real-time, maintaining security control while minimizing processing delays at each network hop.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Endpoints perform self-service by autonomously labeling their own outgoing network flows with application identifiers and security attributes. This self-labeling eliminates the need for external inspection of every message, reducing processing time while maintaining reliable security control through source-based authentication and labeling.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If endpoint instrumentation is implemented for labeling, then network security monitoring capability is improved, but ease of operation and deployment difficulty worsen

Engineering Contradiction:
Improveapplication identification capabilityVSAvoidendpoint deployment ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The endpoint agent is designed as a universal, multi-functional component that handles application identification, flow labeling, and cryptographic signing through a single integrated module. This universality simplifies deployment compared to implementing separate solutions for each function, as the single agent provides comprehensive security monitoring capabilities across multiple applications and protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages deployment complexity by allowing parameter changes in the labeling approach - supporting both cryptographic signing for high-security scenarios and simpler labeling for lower-security environments. This flexibility in parameters enables the same instrumentation to adapt to different operational requirements, easing deployment across diverse enterprise environments with varying security needs.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11277416B2Labeling network flows according to source applications
Publication Date: 2022.03.15 SOPHOS LTD
  • US11277416B2 patent drawing
  • US11277416B2 patent drawing
  • US11277416B2 patent drawing

AI summary

An enterprise security system is improved by instrumenting endpoints to explicitly label network flows according to sources of network traffic. When a network message from an endpoint is received at a gateway, firewall, or other network device/service, the network message may be examined to determine the application on the endpoint that originated the request, and this source information may be used to control routing or other handling of the network message.