Endpoint Protection via Segmented Memory Spaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malware infections in host computer systems compromise security and efficiency, allowing unauthorized access and data loss, as well as potential use for staging attacks on other network resources, often undetected by users or administrators.
Innovation Solution
Implementing endpoint protection and authentication schemes with segregated memory spaces, sandboxed computing environments, and firewalls to isolate untrusted network interactions, prevent unauthorized data transfer, and enforce strict authentication and encryption policies based on network trust levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a host computer system connects to untrusted network destinations, then network functionality and accessibility are improved, but security and vulnerability to malware attacks deteriorate
Solution Approach 1:
The patent segments the host computer system into a trusted workspace and an untrusted sandboxed computing environment. The sandbox container process creates separate memory spaces (first memory space for workspace, second memory space for sandbox) that are isolated from each other. This segmentation allows the system to access untrusted networks through the sandbox while protecting the trusted workspace from malware, resolving the contradiction between network accessibility and security.
2Productivity
If malware is allowed to execute on the host system, then system functionality and application execution are improved, but system integrity and security deteriorate
Solution Approach 1:
The sandbox container process acts as an intermediary between untrusted applications and the host operating system. It mediates all interactions by running applications in an isolated second memory space with restricted access to the first memory space containing sensitive data. The container process controls and filters all communication between the sandboxed environment and the trusted workspace, allowing application execution while maintaining system integrity through this intermediary layer.
3Ease of operation
If data communication between workspace and sandboxed environment is permitted, then data accessibility and functionality are improved, but data security and confidentiality deteriorate
Solution Approach 1:
The patent implements preliminary action by establishing strict access control policies before any data communication occurs. The sandbox container process is configured in advance to prevent data from being communicated between the sandboxed computing environment and the workspace without explicit user input. This preliminary configuration of security policies ensures that data confidentiality is maintained while still allowing controlled accessibility when users intentionally permit it.
Data Source
AI summary
Methods and systems are disclosed for endpoint protection and authentication schemes for a host computer system having an internet isolation system. A first host computer system may include a first memory space and a second memory space. The first memory space may be configured to enable storage and operation of a workspace configured to execute a first set of one or more applications and processes running on an operating system of the first host computer system. The second memory space may be configured to enable storage and operation of a second set of one or more applications and processes associated with an isolated computing environment (e.g., a sandboxed computing environment) configured to run on the operating system. When the first host computer system is connected to a network that is known or associated with a predetermined security policy, the first host computer system may instantiate a predetermined security policy configuration.


