Endpoint Ransomware Protection via Threat-Based Certificate Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current endpoint security solutions are inadequate in protecting against ransomware attacks, particularly in enterprise environments, as they fail to prevent lateral propagation and do not effectively manage browser authentication credentials, leading to potential data loss and exfiltration.

Innovation Solution

An extended enterprise browser is introduced, which selects a certificate for user authentication based on a ransomware threat level, using a secure store with multiple certificates for different threat levels, and integrates with a security appliance to provide point-to-point link protection, thereby controlling access to SaaS and private enterprise applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If agent-based endpoint security solutions are deployed on each endpoint device, then threat detection capability is improved, but device complexity and ease of operation deteriorate due to deployment and management challenges

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddeployment and management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security enforcement function from the endpoint device and relocates it to a network appliance positioned at the network perimeter. The endpoint device retains only minimal client functionality, while the complex security policies, threat detection logic, and authentication management are centralized in the network appliance, eliminating deployment and management complexity at the endpoint level.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network appliance serves as an intermediary between endpoint devices and enterprise resources. It mediates all authentication requests and security policy enforcement, allowing endpoint devices to remain simple while maintaining comprehensive security through the intermediary's intelligent processing and policy management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If endpoint security agents are deployed, then endpoint protection is improved, but adaptability deteriorates because agents are frequently not supported on older operating system versions

Engineering Contradiction:
Improveendpoint protectionVSAvoidoperating system compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security enforcement functionality is extracted from the endpoint device entirely and relocated to the network appliance. This eliminates the need for endpoint agents that require OS compatibility, as all security processing occurs on the network appliance which can run any supported operating system independently of the endpoint devices.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If endpoint security agents are deployed, then threat detection is improved, but ease of manufacture deteriorates due to frequent compromise by attackers

Engineering Contradiction:
Improvethreat detectionVSAvoidsecurity maintenance
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security enforcement function is extracted from vulnerable endpoint agents and centralized in a protected network appliance. This centralized architecture protects security logic from endpoint compromise, as the critical security functions reside in a hardened environment that is difficult to compromise, while maintaining full threat detection capability through the appliance's monitoring and policy enforcement.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If conventional endpoint protection solutions are used, then local endpoint security is improved, but loss of information worsens because agents do not provide protection against data loss and exfiltration from SaaS and private enterprise applications

Engineering Contradiction:
Improvelocal endpoint securityVSAvoiddata loss and exfiltration
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The network appliance provides universal security enforcement that covers multiple functions: authentication management, data loss prevention, application access control, and threat detection. By consolidating these diverse security functions into a single platform, the system protects both local endpoints and cloud-based SaaS/private enterprise applications uniformly, preventing data exfiltration across all access vectors.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11736520B1Rapid incidence agentless lateral movement protection from ransomware for endpoints deployed under a default gateway with point to point links
Publication Date: 2023.08.22 ZSCALER INC
  • US11736520B1 patent drawing
  • US11736520B1 patent drawing
  • US11736520B1 patent drawing

AI summary

A system and method for ransomware protection includes an extended browser in an endpoint device. The extended browser selects a certificate for user authentication with an identity provider based on the enterprise ransomware threat level. The selection of the certification may be used to aid in providing protection from ransomware attacks of SaaS and private enterprise applications. The endpoint device may be part of a larger VLAN environment in which endpoint devices are deployed under a default gateway with point-to-point links.