Endpoint Security Agent Dynamic Network Location Adjustment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint security solutions require manual intervention to adjust security behavior when a device moves between trusted and untrusted networks, leading to inefficiencies and potential security vulnerabilities.
Innovation Solution
An endpoint security agent that detects changes in network location and dynamically adjusts its security features by querying a cloud-based trusted network determination service to determine if the new network is trusted, thereby automatically configuring security settings accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an always-on SSL VPN tunnel is used to route traffic through cloud-based security service, then security protection is improved, but access to enterprise resources in trusted domain is blocked
Solution Approach 1:
The patent implements dynamic adjustment of security tunnel behavior based on network location detection. The endpoint security agent automatically detects whether the device is in a trusted or untrusted network and adjusts tunnel configuration accordingly - activating the tunnel in untrusted networks for security protection while deactivating it in trusted networks to enable local resource access without manual intervention
2Ease of operation
If manual pausing of SSL VPN tunnel or adding local firewall rules is required, then access to enterprise resources is enabled, but operational complexity and potential security vulnerabilities increase
Solution Approach 1:
The patent enables the endpoint security agent to automatically detect network location changes and self-adjust tunnel configuration without user intervention. The agent monitors network connectivity to the security service and autonomously activates or deactivates the SSL VPN tunnel based on whether the device is in a trusted or untrusted network, eliminating the need for manual pausing or firewall rule configuration
3Reliability
If security agent continuously routes all traffic through cloud service, then security monitoring is enhanced, but network performance and user experience deteriorate
Solution Approach 1:
The patent implements conditional traffic routing where the endpoint security agent dynamically switches between two modes: in untrusted networks, all traffic is routed through the cloud-based security service for comprehensive monitoring and protection; in trusted networks, the tunnel is deactivated allowing direct local network access for optimal performance while maintaining security through the agent's continued operation
Data Source
AI summary
Systems and methods for adjusting the behavior of an endpoint security agent based on a network location are provided. According to an embodiment, an agent of an endpoint device detects whether the endpoint has moved to a new network by monitoring for changes to an IP address associated with the endpoint. When the detecting is affirmative, the agent further determines whether a trusted network determination service associated with a cloud-based security service is reachable. When the determining is affirmative, the agent further identifies whether the new network is among a set of trusted networks that have been previously registered with the cloud-based security service by querying the trusted network determination service. When the identifying is affirmative, a particular security feature on the endpoint is configured for operation within a trusted network and when the identifying is negative, the particular security feature is configured for operation outside of a trusted networks.


