Endpoint Risk-Based Network Protection via Reputation Cache

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security approaches are inadequate in preventing malicious attacks, as they rely on manual intervention and blacklisting, which can be too late to prevent network compromise and affect legitimate traffic.

Innovation Solution

A method and system for endpoint risk-based protection that uses a reputation cache to determine the risk of network connections, allowing for automatic remedial actions based on security policies, thereby enhancing network security efficiency and effectiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual blacklisting of malicious executables is used, then network security can be maintained, but response time is too slow and entire networks may be compromised before reputation is set

Engineering Contradiction:
Improvenetwork securityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically establishing reputations for executables based on their network behavior patterns before malicious activity occurs. The reputation cache pre-evaluates executables against known good behavior profiles, enabling proactive blocking rather than reactive blacklisting after compromise occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically monitoring, evaluating, and blocking suspicious executables without requiring manual administrator intervention. The automated reputation system continuously learns from network traffic patterns and autonomously updates blocking rules, eliminating the time delay inherent in manual blacklisting processes.

Inventive Principle:
Principle #25Self-service

2Extent of automation

If automatic blacklisting based on IP addresses and ports is used, then automated response is possible, but legitimate traffic is affected and network productivity decreases

Engineering Contradiction:
Improveautomated responseVSAvoidnetwork traffic flow
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The system applies local quality by evaluating the reputation of individual executables rather than blocking all traffic from specific IP addresses or ports. Each executable is assessed based on its unique behavior patterns and reputation score, allowing differentiated treatment where legitimate executables maintain network access while malicious ones are blocked, thus preserving overall network productivity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter from static IP/ port-based blocking to dynamic executable-reputation-based blocking. By monitoring and evaluating executable behavior patterns over time, the system updates reputation scores and adjusts blocking decisions accordingly, enabling automated response that adapts to changing network conditions and preserves legitimate traffic.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If fine-grained capability to prevent bad executables is implemented, then network security improves, but system complexity increases requiring manual tagging and policy configuration

Engineering Contradiction:
Improveexecution securityVSAvoidsystem configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system eliminates the need for manual tagging and policy configuration by implementing self-service automation. The reputation system automatically monitors executable behavior, evaluates patterns against established criteria, and updates blocking rules without administrator intervention, thereby reducing operational complexity while maintaining fine-grained security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system simplifies configuration by changing from manual policy definition to automated parameter-based evaluation. Instead of requiring administrators to manually tag executables and define blocking policies, the system automatically evaluates executable reputations based on monitored parameters such as network behavior patterns, process creation rates, and communication characteristics, reducing operational complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11374977B2Endpoint risk-based network protection
Publication Date: 2022.06.28 FORCEPOINT LLC
  • US11374977B2 patent drawing
  • US11374977B2 patent drawing
  • US11374977B2 patent drawing

AI summary

A method, system, and computer-usable medium are disclosed for managing network communication by, responsive to an attempted connection from a client to a server, receiving information regarding the connection from the client, determining if the information regarding the connection matches an entry of a reputation cache, and responsive to determining that the information regarding the connection matches an entry of the reputation cache, undertaking a remedial action in accordance with a security policy.