Endpoint Security On-Net Status Determination via Cloud IP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint security solutions face challenges in accurately determining the on-net/off-net status of client devices within enterprise networks, especially in large-scale environments with frequent network configuration changes and equipment movements, leading to inaccurate status determinations.
Innovation Solution
An endpoint security program maintains an enterprise public IP list and sends requests to a cloud-based service for the client device's public IP address, performing multiple connection status checks, including comparisons with the IP list, attempts to connect to an Enterprise Management Server, and a network security device, to determine the on-net/off-net status using logical OR or sequential combinations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the endpoint security solution uses administrator-configured subnet and MAC address information to determine on-net/off-net status, then the determination method is straightforward in local area networks, but the accuracy deteriorates in large-scale enterprise networks with frequent configuration changes and equipment movements
Solution Approach 1:
The patent introduces a cloud-based service as an intermediary between the endpoint security solution and the enterprise network. Instead of directly maintaining and querying local gateway MAC addresses, the system uses cloud-based IP address information as a mediator to determine on-net/off-net status. This resolves the contradiction by providing accurate network status determination without requiring continuous local maintenance of gateway information.
Solution Approach 2:
The patent transitions from local, static gateway MAC address-based determination to cloud-based, dynamic IP address-based determination. By moving the determination logic to the cloud dimension, the system can access updated network information without requiring local configuration changes, thus maintaining accuracy in large-scale dynamic networks while simplifying local operation.
2Device complexity
If the endpoint security solution maintains local subnet and gateway information, then the determination process is simple, but the system cannot keep up with frequent network configuration changes and equipment movements
Solution Approach 1:
The cloud-based service acts as an intermediary that provides authoritative network status information. The endpoint security solution queries this intermediary for IP address information rather than maintaining local configuration data. This approach reduces device complexity by eliminating local configuration maintenance while ensuring reliability through access to centrally managed, up-to-date network information.
Solution Approach 2:
The system implements a feedback mechanism where the endpoint security solution periodically queries the cloud-based service for current IP address information. This continuous feedback loop ensures that the system always has access to the latest network configuration data without requiring manual updates, thereby maintaining reliability while keeping the local system simple.
3Measurement precision
If the endpoint security solution performs multiple connection status checks including cloud-based service queries and comparisons with enterprise public IP lists, then the accuracy of status determination improves, but the complexity of the determination process increases
Solution Approach 1:
The patent segments the connection status determination process into distinct, modular steps: obtaining cloud-based service information, comparing with enterprise public IP lists, and making the final determination. This segmentation allows each step to be independently implemented and managed, reducing overall complexity while maintaining high accuracy through systematic multi-step verification.
Data Source
AI summary
Systems and methods are described for determining an on-net/off-set status of a client device. An endpoint security program running on the client device maintains an enterprise public Internet Protocol (IP) list containing one or more ranges of public IP addresses associated with an enterprise network. Further, the endpoint security program sends a request to a cloud-based service for information regarding a public IP address of the client device. In response to the request, the endpoint security program receives from the cloud-based service a response containing the public IP address and determines a connection status of the client device with respect to the enterprise network by comparing the public IP address to the enterprise public IP list.


