Host Isolation Control for Rapid Network-Wide Threat Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network administrators face challenges in promptly disseminating threat information across various network devices to isolate a flagged endpoint, requiring manual intervention on each device to block access, which is inefficient and prone to errors.
Innovation Solution
A cloud-based threat management system automatically identifies threats and propagates global isolation across network devices by blocking device or user identifiers, leveraging a centralized control plane to enforce isolation measures on switches and wireless access points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual intervention is used to block endpoint access on each network device individually, then network administrators can control access to specific devices, but the process becomes inefficient and time-consuming
Solution Approach 1:
The patent introduces a centralized threat management system as an intermediary that automatically propagates endpoint isolation commands to multiple network devices simultaneously. This mediator receives threat information, identifies the responsible endpoint, and distributes blocking commands across switches and wireless access points, eliminating the need for manual intervention on each device while maintaining comprehensive control.
Solution Approach 2:
The system segments the endpoint isolation process into distinct functional components: threat detection, endpoint identification, command generation, and device execution. By dividing the overall task into these manageable segments that can be executed independently and in parallel across different system components, the patent achieves rapid comprehensive isolation without manual coordination.
2Ease of operation
If administrators manually configure each network device to block a threat, then precise control over each device is achieved, but the complexity of the operation increases significantly
Solution Approach 1:
The patent merges multiple individual device configuration tasks into a single centralized operation. By combining the functions of threat analysis, endpoint identification, and device configuration into one unified threat management system, the patent simplifies the operator's task while maintaining precise control over each network device through automated command distribution.
Solution Approach 2:
The threat management system performs self-service by automatically generating and propagating isolation commands without requiring manual configuration on each device. The system autonomously identifies threats, determines appropriate blocking actions, and executes configurations across network devices, reducing operational complexity while maintaining control precision.
3Reliability
If a centralized system automatically propagates isolation commands across all network devices, then endpoint isolation speed and consistency are improved, but the system complexity increases
Solution Approach 1:
The centralized threat management system is designed with universal functionality to handle multiple network device types (switches, wireless access points, firewalls) through a single interface. This multi-functional approach ensures consistent endpoint isolation across diverse devices while managing system complexity through standardized protocols and unified command structures that can adapt to different device configurations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for responding to a threat with host isolation includes receiving, by one or more processors of a threat management computer system, endpoint health information for a plurality of endpoints of a monitored network system managed by the threat management computer system, identifying a threat associated with the monitored network system, identifying a known device identifier or user identification associated with an endpoint of the plurality of endpoints that is responsible for the threat and propagating a global isolation of the endpoint across network devices of the monitored network system. The global isolation is configured to block the device identifier or user identification associated with the endpoint that is responsible for the threat.