Endpoint Trust Rating for Dynamic Security Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint compliance solutions face challenges in managing client security due to the difficulty in configuring and updating compliance policies as new applications are deployed or updated, and in controlling arbitrary applications on endpoints, leading to over-management or inadequate security.

Innovation Solution

A method for dynamic endpoint management that involves querying a content provider service for trust ratings of applications, generating security rules based on these ratings, and updating compliance policies dynamically, allowing endpoints to self-report changes and enabling managers to enforce security settings without static white-lists or black-lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators manually configure compliance policies for each application, then security control is improved, but device complexity and administrative burden increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by having endpoints automatically report their application inventory and receiving automated policy generation from the compliance server. The server queries content providers to obtain trust ratings for applications and automatically generates compliance policies without requiring manual administrator configuration for each application, thereby reducing administrative burden while maintaining security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where endpoints periodically report their application state to the compliance server, which then updates policies based on current application information. The server queries content providers for updated trust ratings and automatically adjusts compliance policies, creating a continuous feedback loop that maintains security without manual reconfiguration.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If static application lists are preset on endpoints, then security policy enforcement is simplified, but adaptability to new applications deteriorates

Engineering Contradiction:
Improvepolicy enforcement simplicityVSAvoidadaptability to new applications
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system transitions from static to dynamic policy enforcement by continuously updating application lists and trust ratings through automated queries to content providers. The compliance server maintains an updated database of applications and their trust ratings, automatically generating policies that adapt to new applications without requiring manual updates to static lists on endpoints.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by proactively querying content providers for trust ratings of applications before they are deployed on endpoints. The compliance server pre-evaluates applications and generates compliance policies in advance, so when applications are installed, the policies are already ready to be enforced without delay.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If administrators grant administrative privileges to users, then ease of operation is improved, but security control over arbitrary applications deteriorates

Engineering Contradiction:
Improveuser operational flexibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces an intermediary layer in the form of a compliance server that mediates between user operational needs and security requirements. The server receives application reports from endpoints, queries content providers for trust ratings, and generates compliance policies that determine what applications can run. This intermediary handles the security decision-making, allowing users to operate applications legally without requiring administrative privileges while maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8763076B1Endpoint management using trust rating data
Publication Date: 2014.06.24 CA TECH INC
  • US8763076B1 patent drawing
  • US8763076B1 patent drawing
  • US8763076B1 patent drawing

AI summary

Techniques are disclosed for implementing dynamic endpoint management. In accordance with one embodiment, whenever an endpoint joins a managed network for the first time, or rejoins that network, a local security module submits a list of applications (e.g., all or incremental) to a security server. The server validates the list and sends back a rule set (e.g., allow/block rules and/or required application security settings) for those applications. If the server has no information for a given application, it may further subscribe to content from a content provider or service. When the server is queried regarding an unknown application, the server sends a query to the service provider to obtain a trust rating for that unknown application. The trust rating can then be used to generate a rule set for the unknown application. Functionality can be shifted from server to client, and vice-versa if so desired.