Global Host Isolation Across Network Devices for Threat Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network administrators face challenges in promptly disseminating threat information across various network devices to isolate compromised endpoints, requiring manual intervention on each device to block access.
Innovation Solution
A cloud-based threat management system automatically identifies threats and propagates global isolation commands across network devices, using device or user identifiers to restrict access, including quarantine, blacklisting, or walled garden access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If manual intervention is used to block endpoints on each network device individually, then network administrators can precisely control isolation on each device, but the time and effort required to isolate threats across the entire network increases significantly
Solution Approach 1:
The system segments the isolation task by identifying specific network devices (switches, wireless access points) that need to be updated, then propagates the threat information to each device individually through their respective management interfaces, resolving the contradiction between comprehensive coverage and operational efficiency
Solution Approach 2:
The patent introduces an intermediary system that acts as a bridge between the threat detection source and individual network devices. This intermediary receives threat information, processes it, and automatically distributes isolation commands to relevant network devices, eliminating the need for manual intervention while maintaining precise control
2Productivity
If automatic propagation of isolation commands is implemented across all network devices, then the speed of threat response improves, but the system complexity and potential for errors increases
Solution Approach 1:
The system performs preliminary actions by pre-establishing communication channels and management interfaces with all network devices before threats occur. When a threat is detected, the isolation commands can be propagated immediately through these pre-configured channels, achieving rapid response without ad-hoc system complexity
Solution Approach 2:
The patent implements a universal management approach where a single threat information format can be propagated to multiple types of network devices (switches, wireless access points, routers) through standardized interfaces, reducing system complexity while maintaining broad compatibility and fast response
Data Source
AI summary
A method for responding to a threat with host isolation includes receiving, by one or more processors of a threat management computer system, endpoint health information for a plurality of endpoints of a monitored network system managed by the threat management computer system, identifying a threat associated with the monitored network system, identifying a known device identifier or user identification associated with an endpoint of the plurality of endpoints that is responsible for the threat and propagating a global isolation of the endpoint across network devices of the monitored network system. The global isolation is configured to block the device identifier or user identification associated with the endpoint that is responsible for the threat.


