Endpoint Risk-Based Network Protection via Reputation Cache
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security approaches are inadequate in preventing malicious attacks, as they rely on manual intervention and blacklisting, which can be too late to prevent network compromise and affect legitimate traffic.
Innovation Solution
A method and system for endpoint risk-based protection that uses a reputation cache to determine the risk of network connections, allowing for automatic remedial actions based on security policies, thereby enhancing network security efficiency and effectiveness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual blacklisting of malicious executables is used, then network security can be maintained, but response time is too slow and entire networks may be compromised before reputation is set
Solution Approach 1:
The system performs preliminary actions by automatically establishing reputations for executables based on their network behavior patterns before malicious activity occurs. The reputation cache pre-evaluates executables against known good behavior profiles, enabling proactive blocking rather than reactive blacklisting after compromise occurs.
Solution Approach 2:
The system implements self-service by automatically monitoring, evaluating, and blocking suspicious executables without requiring manual administrator intervention. The automated reputation system continuously learns from network traffic patterns and autonomously updates blocking rules, eliminating the time delay inherent in manual blacklisting processes.
2Extent of automation
If automatic blacklisting based on IP addresses and ports is used, then automated response is possible, but legitimate traffic is affected and network productivity decreases
Solution Approach 1:
The system applies local quality by evaluating the reputation of individual executables rather than blocking all traffic from specific IP addresses or ports. Each executable is assessed based on its unique behavior patterns and reputation score, allowing differentiated treatment where legitimate executables maintain network access while malicious ones are blocked, thus preserving overall network productivity.
Solution Approach 2:
The system changes the parameter from static IP/ port-based blocking to dynamic executable-reputation-based blocking. By monitoring and evaluating executable behavior patterns over time, the system updates reputation scores and adjusts blocking decisions accordingly, enabling automated response that adapts to changing network conditions and preserves legitimate traffic.
3Reliability
If fine-grained capability to prevent bad executables is implemented, then network security improves, but system complexity increases requiring manual tagging and policy configuration
Solution Approach 1:
The system eliminates the need for manual tagging and policy configuration by implementing self-service automation. The reputation system automatically monitors executable behavior, evaluates patterns against established criteria, and updates blocking rules without administrator intervention, thereby reducing operational complexity while maintaining fine-grained security control.
Solution Approach 2:
The system simplifies configuration by changing from manual policy definition to automated parameter-based evaluation. Instead of requiring administrators to manually tag executables and define blocking policies, the system automatically evaluates executable reputations based on monitored parameters such as network behavior patterns, process creation rates, and communication characteristics, reducing operational complexity.
Data Source
AI summary
A method, system, and computer-usable medium are disclosed for managing network communication by, responsive to an attempted connection from a client to a server, receiving information regarding the connection from the client, determining if the information regarding the connection matches an entry of a reputation cache, and responsive to determining that the information regarding the connection matches an entry of the reputation cache, undertaking a remedial action in accordance with a security policy.


