Endpoint Management Network Access Control for Malware Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network protection systems isolate infected computing devices, preventing them from receiving assistance from other network nodes to neutralize malware, which can lead to ineffective malware removal and network vulnerability.
Innovation Solution
Implementing an endpoint management system that provides a computing device with a first level of network access, determines if it is infected with malware and unable to autonomously neutralize it, and modifies the network access control policy to a second level, restricting access while maintaining a connection for assistance from the endpoint management system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If the network protection agent disables the computing device's network card to quarantine the device, then the device is isolated from potential malware transmission to other network nodes, but the device becomes unable to receive assistance from other network nodes for malware neutralization
Solution Approach 1:
The patent segments network access into different levels: full access for healthy devices, restricted access for quarantined devices (allowing only connections to management server and specific assistance nodes), and complete isolation for confirmed malicious devices. This segmentation resolves the contradiction by allowing the infected device to maintain limited connections for receiving assistance while blocking transmissions to other network nodes.
Solution Approach 2:
The patent applies different network access policies to different parts of the network infrastructure. The infected device receives a customized firewall policy that allows connections to specific nodes (management server, assistance nodes) while blocking others. This local quality approach enables the device to receive necessary assistance from designated nodes while maintaining isolation from the broader network.
2Object-affected harmful factors
If the endpoint management system restricts the infected computing device's network access to a second level with more limited access, then the risk of further network infection is minimized, but the device loses access to nodes that could provide assistance in neutralizing the malware
Solution Approach 1:
The patent introduces an intermediary mechanism (the managed firewall policy) that mediates between the infected device and the network. This firewall acts as a smart gatekeeper, allowing legitimate assistance traffic from designated nodes while blocking malicious transmissions. The intermediary resolves the contradiction by enabling selective communication that supports malware neutralization while preventing further infection.
Solution Approach 2:
The patent implements dynamic network access control that can be adjusted based on the device's infection status and the progress of malware neutralization. The firewall policy is not static but can be modified by the endpoint management system as the device transitions from infected to cleaned state, allowing flexibility in balancing security and assistance needs.
3Object-generated harmful factors
If the computing device is completely isolated from the network, then it cannot spread malware to other devices, but it also cannot obtain updated anti-malware definitions or diagnostic information from the endpoint management system
Solution Approach 1:
The patent segments network communication into allowed and blocked categories for the infected device. The firewall policy explicitly permits connections to the endpoint management system for receiving anti-malware definitions, diagnostic information, and neutralization tools, while simultaneously blocking connections to other network nodes that could be infected. This segmentation resolves the contradiction by enabling selective information flow.
Data Source
AI summary
A computer-implemented method for protecting networks from infected computing devices may include providing a computing system with a first level of access to a network. The method may also include determining that the computing system is infected with malware. The method may further include determining that the computing system cannot autonomously neutralize the malware. The method may additionally include modifying by an endpoint management system a network access control policy that controls network access of the first computing system. Various other methods, systems, and computer-readable media are also disclosed.


