Dynamic Health-Based Network Access Control System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anti-malware and web filtering technologies are either overly restrictive or insufficiently dynamic, failing to effectively protect computer systems from malicious resources due to static URL-based blocking and inadequate consideration of machine health and resource reputation.
Innovation Solution
A protection system that dynamically determines access to resources based on the health state of the computer system and the reputation of the resource, intercepting requests to assess and balance both factors in real-time, allowing administrators to define policies for varying levels of access based on health scores and reputation scores.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If URL-based blocking is used to protect computer systems from malicious resources, then protection coverage is improved, but the system becomes unnecessarily restrictive and blocks legitimate resources
Solution Approach 1:
The patent implements dynamic access control by transitioning from static URL blocking lists to a real-time evaluation system that assesses machine health state and resource reputation scores. The system continuously updates access decisions based on current health metrics and reputation data, allowing legitimate resources to be accessed when the machine is healthy while blocking malicious resources when the machine is vulnerable.
Solution Approach 2:
The patent changes the protection parameter from binary URL blocking to a multi-factor evaluation system incorporating machine health state parameters (patch levels, antivirus status, firewall configuration) and resource reputation parameters (trust scores, categorization). This parameter transformation enables nuanced access decisions that balance security and usability.
2Reliability
If static URL blocking lists are maintained to identify malicious websites, then known threats are blocked, but the system fails to identify newly created malicious domains
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously monitors machine health state changes and resource reputation updates. Reputation services provide ongoing feedback about resource safety, and health monitoring services provide feedback about system vulnerability levels. This continuous feedback loop enables the system to adapt to new threats dynamically without relying solely on static blocking lists.
Solution Approach 2:
The patent performs preliminary assessment of machine health state and resource reputation before allowing access. By evaluating trust scores and health metrics in advance of resource access attempts, the system can proactively identify and block potential threats before they compromise the system, rather than waiting for static lists to be updated.
3Reliability
If machine health checks are enforced before network access, then security is improved, but legitimate users are blocked when their machines are temporarily unhealthy
Solution Approach 1:
The patent applies partial health checking by evaluating specific health parameters dynamically rather than requiring all checks to pass. The system assesses relevant health metrics at the time of resource access requests and makes decisions based on the specific risk profile of both the machine state and the requested resource, rather than applying blanket access denial.
Solution Approach 2:
The patent implements dynamic access control that adjusts restrictions based on real-time health state evaluation. When a machine temporarily fails health checks, the system dynamically modifies access policies based on the specific health deficiencies and the reputation of the requested resource, allowing access to high-trust resources while blocking access to low-trust resources.
Data Source
AI summary
A protection system is described herein that dynamically determines whether a computer system can access a particular resource based on a combination of a dynamic health state of the computer system and a dynamic reputation of the resource. When a user attempts to access a resource, the protection system intercepts the request. The protection system determines the reputation of the resource that the user is attempting to access and the health of the computer system through which the user is attempting to access the resource. Based on the determined resource reputation and the determined computer system health, the protection system determines whether to allow the requested access to the resource.


