Endpoint-Network Security Task Allocation via Traffic Tagging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing and maintaining effective network security in dynamic and rapidly changing network environments is challenging due to the proliferation of devices, threats, and communication protocols.
Innovation Solution
Systems and methods that coordinate network security tasks between endpoint devices and network devices, such as firewalls, by receiving and analyzing tag information about traffic flows to identify and perform specific security tasks, including using hardware accelerators and dynamic adjustments based on endpoint device resources and security levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive security tasks are performed on all network traffic, then network security reliability is improved, but network device processing load and complexity increase
Solution Approach 1:
The patent segments security tasks between endpoint devices and network devices. Endpoint security agents perform local security functions (virus scanning, firewall rules) while network devices handle network-level security (intrusion detection, encryption). This segmentation distributes processing load and reduces the burden on any single device while maintaining comprehensive security coverage.
Solution Approach 2:
The patent implements preliminary security actions by having endpoint devices perform security checks and tagging before traffic reaches the network device. Security agents on endpoints analyze traffic, apply local security policies, and attach metadata tags indicating the security status and required processing level. This preliminary action reduces the workload for network devices since they receive pre-filtered and tagged traffic.
2Reliability
If security tasks are performed at the network device, then centralized security control is improved, but network latency and processing time increase
Solution Approach 1:
Endpoint security agents perform preliminary security analysis, classification, and tagging of traffic before it reaches the network device. This preliminary action includes identifying malicious traffic patterns, classifying traffic types, and attaching metadata that enables the network device to make rapid decisions without performing full analysis, thereby reducing latency while maintaining centralized control.
Solution Approach 2:
The patent uses security metadata tags as simplified copies or representations of the actual security state of traffic. Instead of the network device performing complete security analysis on all packets, it relies on the copied security information embedded in tags by endpoint agents. This copying mechanism allows rapid processing while maintaining security effectiveness.
3Reliability
If all security tasks are performed on the network device, then security policy enforcement is improved, but endpoint device resources are over-utilized
Solution Approach 1:
The patent segments security functionality into endpoint-based security agents and network-based security services. Endpoint agents handle local security tasks such as process monitoring, local firewall enforcement, and traffic tagging, reducing their resource requirements compared to running full security suites. Network devices handle centralized policy enforcement and complex analysis tasks, leveraging their greater processing power and shared resource pool.
4Adaptability or versatility
If dynamic security task allocation is implemented, then security adaptability is improved, but system complexity and coordination overhead increase
Solution Approach 1:
The patent implements feedback mechanisms where endpoint security agents continuously report traffic characteristics, security events, and resource status to the network device. The network device analyzes this feedback and dynamically adjusts security task allocation, policy enforcement levels, and resource distribution. This closed-loop feedback system enables adaptability while managing complexity through automated decision-making based on real-time conditions.
Solution Approach 2:
The patent changes operational parameters dynamically based on network conditions, threat levels, and resource availability. Security task allocation parameters, encryption levels, inspection depth, and resource distribution are adjusted as variables rather than fixed settings. This parameter-based approach enables flexible adaptation to changing conditions while maintaining systematic control through defined adjustment rules and thresholds.
Data Source
AI summary
Methods, systems, and computer readable media for network security are described. In some implementations, security tasks and roles can be allocated between an endpoint device and a firewall device based on tag information sent from the endpoint, the tag information including one or more characteristics of a traffic flow, information of resource availability, and/or reputation of a process associated with a traffic flow.


