Endpoint Management Network Access Control for Malware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network protection systems isolate infected computing devices, preventing them from receiving assistance from other network nodes to neutralize malware, which can lead to ineffective malware removal and network vulnerability.

Innovation Solution

Implementing an endpoint management system that provides a computing device with a first level of network access, determines if it is infected with malware and unable to autonomously neutralize it, and modifies the network access control policy to a second level, restricting access while maintaining a connection for assistance from the endpoint management system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If the network protection agent disables the computing device's network card to quarantine the device, then the device is isolated from potential malware transmission to other network nodes, but the device becomes unable to receive assistance from other network nodes for malware neutralization

Engineering Contradiction:
Improvemalware transmission to other nodesVSAvoidability to receive assistance for malware neutralization
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent segments network access into different levels: full access for healthy devices, restricted access for quarantined devices (allowing only connections to management server and specific assistance nodes), and complete isolation for confirmed malicious devices. This segmentation resolves the contradiction by allowing the infected device to maintain limited connections for receiving assistance while blocking transmissions to other network nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different network access policies to different parts of the network infrastructure. The infected device receives a customized firewall policy that allows connections to specific nodes (management server, assistance nodes) while blocking others. This local quality approach enables the device to receive necessary assistance from designated nodes while maintaining isolation from the broader network.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If the endpoint management system restricts the infected computing device's network access to a second level with more limited access, then the risk of further network infection is minimized, but the device loses access to nodes that could provide assistance in neutralizing the malware

Engineering Contradiction:
Improverisk of further network infectionVSAvoideffectiveness of malware neutralization
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism (the managed firewall policy) that mediates between the infected device and the network. This firewall acts as a smart gatekeeper, allowing legitimate assistance traffic from designated nodes while blocking malicious transmissions. The intermediary resolves the contradiction by enabling selective communication that supports malware neutralization while preventing further infection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic network access control that can be adjusted based on the device's infection status and the progress of malware neutralization. The firewall policy is not static but can be modified by the endpoint management system as the device transitions from infected to cleaned state, allowing flexibility in balancing security and assistance needs.

Inventive Principle:
Principle #15Dynamics

3Object-generated harmful factors

If the computing device is completely isolated from the network, then it cannot spread malware to other devices, but it also cannot obtain updated anti-malware definitions or diagnostic information from the endpoint management system

Engineering Contradiction:
Improvemalware spread to other devicesVSAvoidaccess to anti-malware definitions and diagnostic information
Core Design Contradiction:
Object-generated harmful factorsVSLoss of information

Solution Approach 1:

The patent segments network communication into allowed and blocked categories for the infected device. The firewall policy explicitly permits connections to the endpoint management system for receiving anti-malware definitions, diagnostic information, and neutralization tools, while simultaneously blocking connections to other network nodes that could be infected. This segmentation resolves the contradiction by enabling selective information flow.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8806638B1Systems and methods for protecting networks from infected computing devices
Publication Date: 2014.08.12 CA TECH INC
  • US8806638B1 patent drawing
  • US8806638B1 patent drawing
  • US8806638B1 patent drawing

AI summary

A computer-implemented method for protecting networks from infected computing devices may include providing a computing system with a first level of access to a network. The method may also include determining that the computing system is infected with malware. The method may further include determining that the computing system cannot autonomously neutralize the malware. The method may additionally include modifying by an endpoint management system a network access control policy that controls network access of the first computing system. Various other methods, systems, and computer-readable media are also disclosed.