Endpoint Security App Auto-Configures for Network State

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a Bring Your Own Device (BYOD) environment, managing endpoint security configurations automatically based on the network environment is challenging, as users need to manually adjust settings when switching between on-net and off-net states, posing a risk to network security and user convenience.

Innovation Solution

A client security application determines the network connection state by retrieving identification information from a network appliance, selecting and launching appropriate configurations and functions based on whether the device is on-net or off-net, thereby automating security management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration changes are required when switching between on-net and off-net states, then security functions can be adjusted appropriately for each network environment, but user convenience deteriorates and the complexity of operation increases

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The client security application automatically detects the network connection state (on-net or off-net) and self-configures the appropriate security functions without requiring user intervention. The system monitors network status changes and autonomously launches or terminates security functions based on the detected environment, enabling the system to serve itself in configuration management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors the network connection state as feedback and uses this information to dynamically adjust security function configuration. When the network state changes (e.g., from on-net to off-net), the feedback triggers automatic reconfiguration of security functions to match the new environment, ensuring appropriate security measures are always active.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual configuration changes are required when switching between on-net and off-net states, then security functions can be adjusted appropriately for each network environment, but time consumption increases

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration adjustment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-configures multiple security function sets corresponding to different network states (on-net and off-net configurations). When a network state change is detected, the system can immediately switch to the pre-prepared configuration for that state, eliminating the time required to manually select and configure appropriate security functions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automatic detection and configuration mechanism eliminates the need for user intervention in configuration adjustments, thereby eliminating the time users would spend manually changing settings when switching between network environments.

Inventive Principle:
Principle #25Self-service

3Productivity

If automatic configuration based on network environment is implemented, then user convenience and productivity improve, but the complexity of the security application increases

Engineering Contradiction:
Improvesecurity management efficiencyVSAvoidclient security application
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The client security application is designed with multi-functionality to handle both on-net and off-net security requirements within a single unified system. The application incorporates network state detection, automatic configuration selection, and dynamic function launch/termination capabilities, making it a universal security solution that adapts to different network environments without requiring separate configuration tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9917814B2Automated configuration of endpoint security management
Publication Date: 2018.03.13 FORTINET INC
  • US9917814B2 patent drawing
  • US9917814B2 patent drawing
  • US9917814B2 patent drawing

AI summary

Systems and methods for managing configuration of a client security application based on a network environment in which the client device is operating are provided. According to one embodiment, a network connection state of a client device with respect to a private network is determined by a client security application running on the client device. The client security application, then selects a configuration based on the determined network connection state. Finally, the client security application launches one or more functions of the client security application that are designated by the selected configuration.