Endpoint Security Policy Management for Information Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information leakage prevention techniques, such as those described in Patent Literature 1, are ineffective in networks without a firewall or relay device and cannot adapt security measures to individual client machines based on user attributes, leading to uniform and inflexible countermeasures.

Innovation Solution

An information leakage prevention system comprising a client terminal with a processing unit that implements network control according to a security policy and a management server with user and security policy databases, allowing for dynamic selection and application of security policies based on user attributes and time, enabling flexible security adjustments and isolation or blocking of connections to C&C servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall device and relay device are used to block information leakage, then network security is improved, but the system requires specific network infrastructure (firewall and relay devices) that not all networks possess

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork infrastructure requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security control function from centralized network infrastructure (firewall/relay devices) and relocates it to the endpoint device itself. The information leakage prevention program is installed directly on the terminal device, enabling security functions to operate independently of network infrastructure. This allows networks without firewalls or relay devices to achieve the same security效果.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The terminal device performs security control autonomously through the installed prevention program, which automatically detects malware communication attempts and blocks information leakage without requiring external firewall or relay device intervention. The system serves itself by implementing security functions locally at the endpoint.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If uniform security measures are applied to all client machines, then implementation simplicity is improved, but flexibility and adaptability to different user needs deteriorate

Engineering Contradiction:
Improvesecurity policy implementationVSAvoidsecurity policy flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The security policy is designed to be dynamic and adaptable rather than static and uniform. The management server can deliver different security policies to different terminal devices based on user attributes, device state, and threat level. The security strength can be adjusted flexibly for each user, allowing the system to adapt to different needs while maintaining ease of centralized management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different security policies are applied to different terminal devices or users based on their specific characteristics. Instead of uniform security measures, each user can have customized security strength and policy settings tailored to their role, risk profile, or organizational requirements, enabling localized security optimization.

Inventive Principle:
Principle #3Local quality

3Reliability

If strict security measures are applied to all users, then information leakage prevention is improved, but user convenience and productivity deteriorate due to excessive restrictions

Engineering Contradiction:
Improveinformation leakage preventionVSAvoiduser work efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security policy parameters such as security strength, blocking rules, and monitoring intensity can be adjusted based on user attributes and device state. High-risk users or devices experiencing malware activity receive stricter controls, while low-risk users experience fewer restrictions, optimizing the balance between security and productivity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of applying uniform strict security to all users, the system applies security measures selectively and proportionally. Only the necessary level of security control is applied to each user based on their risk profile, avoiding excessive restrictions on low-risk users while maintaining strong protection for high-risk scenarios.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10924492B2Information leakage prevention system and method
Publication Date: 2021.02.16 HITACHI SOFTWARE ENG
  • US10924492B2 patent drawing
  • US10924492B2 patent drawing
  • US10924492B2 patent drawing

AI summary

Provided is an information leakage prevention technique which does not require a dedicated device for access management on a network, and which offers excellent security policy flexibility. An information leakage prevention system comprises: a client terminal including a client processing unit which performs network control in accordance with an acquired security policy; and a management server including a user database in which information concerning a user of the client terminal is stored, a security policy database in which a security policy defining a network control content for each attribute of the user is stored, and a server processing unit which selects the security policy on the basis of the attribute of the user and a time of delivery of the security policy, and which transmits the selected security policy to the corresponding client terminal.