Endpoint Trust Rating for Dynamic Security Policy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint compliance solutions face challenges in managing client security due to the difficulty in configuring and updating compliance policies as new applications are deployed or updated, and in controlling arbitrary applications on endpoints, leading to over-management or inadequate security.
Innovation Solution
A method for dynamic endpoint management that involves querying a content provider service for trust ratings of applications, generating security rules based on these ratings, and updating compliance policies dynamically, allowing endpoints to self-report changes and enabling managers to enforce security settings without static white-lists or black-lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators manually configure compliance policies for each application, then security control is improved, but device complexity and administrative burden increase significantly
Solution Approach 1:
The system enables self-service by having endpoints automatically report their application inventory and receiving automated policy generation from the compliance server. The server queries content providers to obtain trust ratings for applications and automatically generates compliance policies without requiring manual administrator configuration for each application, thereby reducing administrative burden while maintaining security control.
Solution Approach 2:
The system implements feedback mechanisms where endpoints periodically report their application state to the compliance server, which then updates policies based on current application information. The server queries content providers for updated trust ratings and automatically adjusts compliance policies, creating a continuous feedback loop that maintains security without manual reconfiguration.
2Ease of operation
If static application lists are preset on endpoints, then security policy enforcement is simplified, but adaptability to new applications deteriorates
Solution Approach 1:
The system transitions from static to dynamic policy enforcement by continuously updating application lists and trust ratings through automated queries to content providers. The compliance server maintains an updated database of applications and their trust ratings, automatically generating policies that adapt to new applications without requiring manual updates to static lists on endpoints.
Solution Approach 2:
The system performs preliminary actions by proactively querying content providers for trust ratings of applications before they are deployed on endpoints. The compliance server pre-evaluates applications and generates compliance policies in advance, so when applications are installed, the policies are already ready to be enforced without delay.
3Ease of operation
If administrators grant administrative privileges to users, then ease of operation is improved, but security control over arbitrary applications deteriorates
Solution Approach 1:
The system introduces an intermediary layer in the form of a compliance server that mediates between user operational needs and security requirements. The server receives application reports from endpoints, queries content providers for trust ratings, and generates compliance policies that determine what applications can run. This intermediary handles the security decision-making, allowing users to operate applications legally without requiring administrative privileges while maintaining security control.
Data Source
AI summary
Techniques are disclosed for implementing dynamic endpoint management. In accordance with one embodiment, whenever an endpoint joins a managed network for the first time, or rejoins that network, a local security module submits a list of applications (e.g., all or incremental) to a security server. The server validates the list and sends back a rule set (e.g., allow/block rules and/or required application security settings) for those applications. If the server has no information for a given application, it may further subscribe to content from a content provider or service. When the server is queried regarding an unknown application, the server sends a query to the service provider to obtain a trust rating for that unknown application. The trust rating can then be used to generate a rule set for the unknown application. Functionality can be shifted from server to client, and vice-versa if so desired.


