Endpoint Host Threat Tracking via Network Segment Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Threat remediation systems are inadequate in detecting and containing endpoint host threats that move laterally within a network, as they are limited to perimeter detection and fail to monitor and remediate threats effectively across the entire network, especially when threats change locations and gain access to new network segments.
Innovation Solution
A policy enforcer platform that tracks endpoint host threats by generating a data structure associating network segments with endpoint host sessions, updates this structure based on session changes and location movements, and determines and enforces threat policy actions to block malicious traffic at both perimeter and internal network layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security controls are placed only at the perimeter of the network, then the device complexity is reduced and ease of operation is improved, but the reliability of threat detection deteriorates when threats move laterally within the network
Solution Approach 1:
The patent divides the network into multiple segments and places security controls at each segment boundary, not just at the perimeter. This segmentation allows the system to detect threats at multiple points throughout the network, improving detection reliability while distributing the complexity across multiple simpler control points rather than one complex perimeter control
Solution Approach 2:
The patent introduces an intermediary system that tracks endpoint hosts across network segments using persistent identifiers. This intermediary layer coordinates between different security control points, allowing simplified local controls to work together effectively without requiring complex centralized management at each control point
2Reliability
If endpoint host threats are blocked at the perimeter, then the loss of time for threat containment is reduced, but the reliability of threat containment deteriorates when threats change network addresses and move laterally
Solution Approach 1:
The patent performs preliminary actions by establishing persistent tracking of endpoint hosts before threats can move laterally. By creating a data structure that associates network segments with endpoint host sessions in advance, the system is prepared to quickly contain threats at any network segment without needing to re-establish tracking when threats move
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously monitors and updates the data structure based on changes in endpoint host locations and sessions. This real-time feedback allows the system to maintain accurate threat information despite address changes, ensuring reliable containment while minimizing the time threats can propagate
3Reliability
If network monitoring covers the entire network including internal segments, then the reliability of threat detection is improved, but the quantity of data to be processed increases
Solution Approach 1:
The patent extracts only the essential information needed for threat detection by focusing on persistent endpoint host identifiers and their associations with network segments. Rather than processing all network traffic data, the system selectively tracks specific host-session-segment relationships, reducing data volume while maintaining detection reliability
Solution Approach 2:
The patent performs preliminary data structuring by organizing network segment and endpoint host session information into a predefined data structure before analysis. This pre-organization filters and categorizes data in advance, making subsequent threat detection more efficient and reducing the effective data volume that requires detailed processing
Data Source
AI summary
A device receives network segment information identifying network segments associated with a network, and receives endpoint host session information identifying sessions associated with endpoint hosts communicating with the network. The device generates, based on the network segment information and the endpoint host session information, a data structure that includes information associating the network segments with the sessions associated with the endpoint hosts. The device updates the data structure based on changes in the sessions associated with the endpoint hosts and based on changes in locations of the endpoint hosts within the network segments, and identifies, based on the data structure, a particular endpoint host, of the endpoint hosts, that changed locations within the network segments. The device determines a threat policy action to enforce for the particular endpoint host, and causes the threat policy action to be enforced, by the network, for the particular endpoint host.


