Endpoint Security Policy Management for Information Leakage Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information leakage prevention techniques, such as those described in Patent Literature 1, are ineffective in networks without a firewall or relay device and cannot adapt security measures to individual client machines based on user attributes, leading to uniform and inflexible countermeasures.
Innovation Solution
An information leakage prevention system comprising a client terminal with a processing unit that implements network control according to a security policy and a management server with user and security policy databases, allowing for dynamic selection and application of security policies based on user attributes and time, enabling flexible security adjustments and isolation or blocking of connections to C&C servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall device and relay device are used to block information leakage, then network security is improved, but the system requires specific network infrastructure (firewall and relay devices) that not all networks possess
Solution Approach 1:
The patent extracts the security control function from centralized network infrastructure (firewall/relay devices) and relocates it to the endpoint device itself. The information leakage prevention program is installed directly on the terminal device, enabling security functions to operate independently of network infrastructure. This allows networks without firewalls or relay devices to achieve the same security效果.
Solution Approach 2:
The terminal device performs security control autonomously through the installed prevention program, which automatically detects malware communication attempts and blocks information leakage without requiring external firewall or relay device intervention. The system serves itself by implementing security functions locally at the endpoint.
2Ease of operation
If uniform security measures are applied to all client machines, then implementation simplicity is improved, but flexibility and adaptability to different user needs deteriorate
Solution Approach 1:
The security policy is designed to be dynamic and adaptable rather than static and uniform. The management server can deliver different security policies to different terminal devices based on user attributes, device state, and threat level. The security strength can be adjusted flexibly for each user, allowing the system to adapt to different needs while maintaining ease of centralized management.
Solution Approach 2:
Different security policies are applied to different terminal devices or users based on their specific characteristics. Instead of uniform security measures, each user can have customized security strength and policy settings tailored to their role, risk profile, or organizational requirements, enabling localized security optimization.
3Reliability
If strict security measures are applied to all users, then information leakage prevention is improved, but user convenience and productivity deteriorate due to excessive restrictions
Solution Approach 1:
The security policy parameters such as security strength, blocking rules, and monitoring intensity can be adjusted based on user attributes and device state. High-risk users or devices experiencing malware activity receive stricter controls, while low-risk users experience fewer restrictions, optimizing the balance between security and productivity.
Solution Approach 2:
Instead of applying uniform strict security to all users, the system applies security measures selectively and proportionally. Only the necessary level of security control is applied to each user based on their risk profile, avoiding excessive restrictions on low-risk users while maintaining strong protection for high-risk scenarios.
Data Source
AI summary
Provided is an information leakage prevention technique which does not require a dedicated device for access management on a network, and which offers excellent security policy flexibility. An information leakage prevention system comprises: a client terminal including a client processing unit which performs network control in accordance with an acquired security policy; and a management server including a user database in which information concerning a user of the client terminal is stored, a security policy database in which a security policy defining a network control content for each attribute of the user is stored, and a server processing unit which selects the security policy on the basis of the attribute of the user and a time of delivery of the security policy, and which transmits the selected security policy to the corresponding client terminal.


