Endpoint Host Threat Tracking via Network Segment Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Threat remediation systems are inadequate in detecting and containing endpoint host threats that move laterally within a network, as they are limited to perimeter detection and fail to monitor and remediate threats effectively across the entire network, especially when threats change locations and gain access to new network segments.

Innovation Solution

A policy enforcer platform that tracks endpoint host threats by generating a data structure associating network segments with endpoint host sessions, updates this structure based on session changes and location movements, and determines and enforces threat policy actions to block malicious traffic at both perimeter and internal network layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security controls are placed only at the perimeter of the network, then the device complexity is reduced and ease of operation is improved, but the reliability of threat detection deteriorates when threats move laterally within the network

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidsecurity control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the network into multiple segments and places security controls at each segment boundary, not just at the perimeter. This segmentation allows the system to detect threats at multiple points throughout the network, improving detection reliability while distributing the complexity across multiple simpler control points rather than one complex perimeter control

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system that tracks endpoint hosts across network segments using persistent identifiers. This intermediary layer coordinates between different security control points, allowing simplified local controls to work together effectively without requiring complex centralized management at each control point

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If endpoint host threats are blocked at the perimeter, then the loss of time for threat containment is reduced, but the reliability of threat containment deteriorates when threats change network addresses and move laterally

Engineering Contradiction:
Improvethreat containment reliabilityVSAvoidthreat containment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by establishing persistent tracking of endpoint hosts before threats can move laterally. By creating a data structure that associates network segments with endpoint host sessions in advance, the system is prepared to quickly contain threats at any network segment without needing to re-establish tracking when threats move

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors and updates the data structure based on changes in endpoint host locations and sessions. This real-time feedback allows the system to maintain accurate threat information despite address changes, ensuring reliable containment while minimizing the time threats can propagate

Inventive Principle:
Principle #23Feedback

3Reliability

If network monitoring covers the entire network including internal segments, then the reliability of threat detection is improved, but the quantity of data to be processed increases

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential information needed for threat detection by focusing on persistent endpoint host identifiers and their associations with network segments. Rather than processing all network traffic data, the system selectively tracks specific host-session-segment relationships, reducing data volume while maintaining detection reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary data structuring by organizing network segment and endpoint host session information into a predefined data structure before analysis. This pre-organization filters and categorizes data in advance, making subsequent threat detection more efficient and reducing the effective data volume that requires detailed processing

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12261870B2Tracking host threats in a network and enforcing threat policy actions for the host threats
Publication Date: 2025.03.25 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12261870B2 patent drawing
  • US12261870B2 patent drawing
  • US12261870B2 patent drawing

AI summary

A device receives network segment information identifying network segments associated with a network, and receives endpoint host session information identifying sessions associated with endpoint hosts communicating with the network. The device generates, based on the network segment information and the endpoint host session information, a data structure that includes information associating the network segments with the sessions associated with the endpoint hosts. The device updates the data structure based on changes in the sessions associated with the endpoint hosts and based on changes in locations of the endpoint hosts within the network segments, and identifies, based on the data structure, a particular endpoint host, of the endpoint hosts, that changed locations within the network segments. The device determines a threat policy action to enforce for the particular endpoint host, and causes the threat policy action to be enforced, by the network, for the particular endpoint host.