Endpoint Security On-Net Status Determination via Cloud IP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint security solutions face challenges in accurately determining the on-net/off-net status of client devices within enterprise networks, especially in large-scale environments with frequent network configuration changes and equipment movements, leading to inaccurate status determinations.

Innovation Solution

An endpoint security program maintains an enterprise public IP list and sends requests to a cloud-based service for the client device's public IP address, performing multiple connection status checks, including comparisons with the IP list, attempts to connect to an Enterprise Management Server, and a network security device, to determine the on-net/off-net status using logical OR or sequential combinations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the endpoint security solution uses administrator-configured subnet and MAC address information to determine on-net/off-net status, then the determination method is straightforward in local area networks, but the accuracy deteriorates in large-scale enterprise networks with frequent configuration changes and equipment movements

Engineering Contradiction:
Improveease of maintaining gateway MAC address informationVSAvoidaccuracy of on-net/off-net status determination
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces a cloud-based service as an intermediary between the endpoint security solution and the enterprise network. Instead of directly maintaining and querying local gateway MAC addresses, the system uses cloud-based IP address information as a mediator to determine on-net/off-net status. This resolves the contradiction by providing accurate network status determination without requiring continuous local maintenance of gateway information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from local, static gateway MAC address-based determination to cloud-based, dynamic IP address-based determination. By moving the determination logic to the cloud dimension, the system can access updated network information without requiring local configuration changes, thus maintaining accuracy in large-scale dynamic networks while simplifying local operation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If the endpoint security solution maintains local subnet and gateway information, then the determination process is simple, but the system cannot keep up with frequent network configuration changes and equipment movements

Engineering Contradiction:
Improvecomplexity of maintaining network configuration informationVSAvoidreliability of on-net/off-net status determination
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The cloud-based service acts as an intermediary that provides authoritative network status information. The endpoint security solution queries this intermediary for IP address information rather than maintaining local configuration data. This approach reduces device complexity by eliminating local configuration maintenance while ensuring reliability through access to centrally managed, up-to-date network information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where the endpoint security solution periodically queries the cloud-based service for current IP address information. This continuous feedback loop ensures that the system always has access to the latest network configuration data without requiring manual updates, thereby maintaining reliability while keeping the local system simple.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If the endpoint security solution performs multiple connection status checks including cloud-based service queries and comparisons with enterprise public IP lists, then the accuracy of status determination improves, but the complexity of the determination process increases

Engineering Contradiction:
Improveaccuracy of on-net/off-net status determinationVSAvoidcomplexity of connection status determination process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the connection status determination process into distinct, modular steps: obtaining cloud-based service information, comparing with enterprise public IP lists, and making the final determination. This segmentation allows each step to be independently implemented and managed, reducing overall complexity while maintaining high accuracy through systematic multi-step verification.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11153350B2Determining on-net/off-net status of a client device
Publication Date: 2021.10.19 FORTINET INC
  • US11153350B2 patent drawing
  • US11153350B2 patent drawing
  • US11153350B2 patent drawing

AI summary

Systems and methods are described for determining an on-net/off-set status of a client device. An endpoint security program running on the client device maintains an enterprise public Internet Protocol (IP) list containing one or more ranges of public IP addresses associated with an enterprise network. Further, the endpoint security program sends a request to a cloud-based service for information regarding a public IP address of the client device. In response to the request, the endpoint security program receives from the cloud-based service a response containing the public IP address and determines a connection status of the client device with respect to the enterprise network by comparing the public IP address to the enterprise public IP list.