Extended Enterprise Browser Ransomware Lateral Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current endpoint security solutions are inadequate in protecting against ransomware attacks, particularly in enterprise environments, as they fail to prevent lateral propagation and do not effectively manage browser-based credentials, leading to potential data loss and exfiltration.

Innovation Solution

An extended enterprise browser is installed on endpoint devices, which monitors for alternate browsers and takes actions to block ransomware spread by generating alerts, blocking access to sensitive applications, and using multiple client certificates based on ransomware risk levels to authenticate securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional endpoint protection solutions are deployed, then endpoint devices are protected from ransomware attacks, but lateral propagation of ransomware to SaaS and private enterprise applications cannot be prevented

Engineering Contradiction:
Improveendpoint protectionVSAvoidlateral propagation protection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments protection by introducing a browser extension that operates independently within the web browser environment, separate from conventional endpoint protection agents. This extension specifically monitors and controls browser-based authentication processes to SaaS and private enterprise applications, creating a specialized protection layer that addresses lateral propagation without requiring changes to the entire endpoint security architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The browser extension acts as an intermediary between the endpoint device and SaaS/private enterprise applications. It intercepts and monitors authentication credentials in the browser, controlling the flow of information between the compromised endpoint and external applications, thereby preventing lateral propagation while maintaining normal application functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If endpoint protection agents are deployed on each endpoint device, then ransomware detection capability is improved, but deployment and management complexity increases

Engineering Contradiction:
Improveransomware detectionVSAvoidagent deployment and management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The browser extension leverages the existing browser infrastructure and authentication mechanisms to provide protection. Instead of requiring a separate agent with full system access, the extension uses the browser's built-in credential management and authentication flows, allowing it to function with minimal system resources and simpler deployment through standard browser extension installation procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The browser extension provides multiple security functions within a single component: monitoring authentication credentials, detecting ransomware attempts, blocking lateral propagation, and generating alerts. This multi-functionality consolidates what would otherwise require multiple separate tools into one unified solution that operates within the existing browser environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If endpoint protection agents are used, then threat posture reporting is enabled, but direct protection against data loss and exfiltration through browser credentials is not provided

Engineering Contradiction:
Improvedata loss preventionVSAvoidcredential protection
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The browser extension performs preliminary monitoring and validation of authentication credentials before they are used to access SaaS and private enterprise applications. By intercepting and verifying credentials in advance, it prevents ransomware from exploiting them for lateral propagation and data exfiltration, providing proactive protection rather than reactive detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The extension continuously monitors browser authentication processes and provides real-time feedback on credential usage. When ransomware or unauthorized processes attempt to use browser credentials, the extension detects these attempts and immediately responds by blocking the authentication, creating a closed-loop protection system that adapts to threats as they emerge.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11711396B1Extended enterprise browser blocking spread of ransomware from alternate browsers in a system providing agentless lateral movement protection from ransomware for endpoints deployed under a default gateway with point to point links
Publication Date: 2023.07.25 ZSCALER INC
  • US11711396B1 patent drawing
  • US11711396B1 patent drawing
  • US11711396B1 patent drawing

AI summary

An extended enterprise browser installed on an endpoint device provides protection from ransomware attacks to SaaS and private enterprise applications. The extended enterprise browser monitors for alternate browser installed on the endpoint device. The extended enterprise browser may take one or more actions to block the spread of ransomware by the alternate browser.