Global Host Isolation Across Network Devices for Threat Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in promptly disseminating threat information across various network devices to isolate compromised endpoints, requiring manual intervention on each device to block access.

Innovation Solution

A cloud-based threat management system automatically identifies threats and propagates global isolation commands across network devices, using device or user identifiers to restrict access, including quarantine, blacklisting, or walled garden access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If manual intervention is used to block endpoints on each network device individually, then network administrators can precisely control isolation on each device, but the time and effort required to isolate threats across the entire network increases significantly

Engineering Contradiction:
Improvetime to isolate threatVSAvoidoperational complexity
Core Design Contradiction:
Loss of timeVSEase of operation

Solution Approach 1:

The system segments the isolation task by identifying specific network devices (switches, wireless access points) that need to be updated, then propagates the threat information to each device individually through their respective management interfaces, resolving the contradiction between comprehensive coverage and operational efficiency

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system that acts as a bridge between the threat detection source and individual network devices. This intermediary receives threat information, processes it, and automatically distributes isolation commands to relevant network devices, eliminating the need for manual intervention while maintaining precise control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automatic propagation of isolation commands is implemented across all network devices, then the speed of threat response improves, but the system complexity and potential for errors increases

Engineering Contradiction:
Improvethreat response speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-establishing communication channels and management interfaces with all network devices before threats occur. When a threat is detected, the isolation commands can be propagated immediately through these pre-configured channels, achieving rapid response without ad-hoc system complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a universal management approach where a single threat information format can be propagated to multiple types of network devices (switches, wireless access points, routers) through standardized interfaces, reducing system complexity while maintaining broad compatibility and fast response

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260006065A1Active threat response with host isolation
Publication Date: 2026.01.01 SOPHOS LTD
  • US20260006065A1 patent drawing
  • US20260006065A1 patent drawing
  • US20260006065A1 patent drawing

AI summary

A method for responding to a threat with host isolation includes receiving, by one or more processors of a threat management computer system, endpoint health information for a plurality of endpoints of a monitored network system managed by the threat management computer system, identifying a threat associated with the monitored network system, identifying a known device identifier or user identification associated with an endpoint of the plurality of endpoints that is responsible for the threat and propagating a global isolation of the endpoint across network devices of the monitored network system. The global isolation is configured to block the device identifier or user identification associated with the endpoint that is responsible for the threat.