Host Isolation Control for Rapid Network-Wide Threat Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in promptly disseminating threat information across various network devices to isolate a flagged endpoint, requiring manual intervention on each device to block access, which is inefficient and prone to errors.

Innovation Solution

A cloud-based threat management system automatically identifies threats and propagates global isolation across network devices by blocking device or user identifiers, leveraging a centralized control plane to enforce isolation measures on switches and wireless access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual intervention is used to block endpoint access on each network device individually, then network administrators can control access to specific devices, but the process becomes inefficient and time-consuming

Engineering Contradiction:
Improveendpoint isolation speedVSAvoidtime required to block endpoint across multiple devices
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent introduces a centralized threat management system as an intermediary that automatically propagates endpoint isolation commands to multiple network devices simultaneously. This mediator receives threat information, identifies the responsible endpoint, and distributes blocking commands across switches and wireless access points, eliminating the need for manual intervention on each device while maintaining comprehensive control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the endpoint isolation process into distinct functional components: threat detection, endpoint identification, command generation, and device execution. By dividing the overall task into these manageable segments that can be executed independently and in parallel across different system components, the patent achieves rapid comprehensive isolation without manual coordination.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If administrators manually configure each network device to block a threat, then precise control over each device is achieved, but the complexity of the operation increases significantly

Engineering Contradiction:
Improveease of endpoint isolationVSAvoidcomplexity of blocking process across multiple devices
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple individual device configuration tasks into a single centralized operation. By combining the functions of threat analysis, endpoint identification, and device configuration into one unified threat management system, the patent simplifies the operator's task while maintaining precise control over each network device through automated command distribution.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The threat management system performs self-service by automatically generating and propagating isolation commands without requiring manual configuration on each device. The system autonomously identifies threats, determines appropriate blocking actions, and executes configurations across network devices, reducing operational complexity while maintaining control precision.

Inventive Principle:
Principle #25Self-service

3Reliability

If a centralized system automatically propagates isolation commands across all network devices, then endpoint isolation speed and consistency are improved, but the system complexity increases

Engineering Contradiction:
Improveconsistency of endpoint isolationVSAvoidcomplexity of centralized threat management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized threat management system is designed with universal functionality to handle multiple network device types (switches, wireless access points, firewalls) through a single interface. This multi-functional approach ensures consistent endpoint isolation across diverse devices while managing system complexity through standardized protocols and unified command structures that can adapt to different device configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4672056A1Active threat response with host isolation
Publication Date: 2025.12.31 SOPHOS LTD
  • EP4672056A1 patent drawingFigure 1
  • EP4672056A1 patent drawingFigure 2
  • EP4672056A1 patent drawingFigure 3

AI summary

A method for responding to a threat with host isolation includes receiving, by one or more processors of a threat management computer system, endpoint health information for a plurality of endpoints of a monitored network system managed by the threat management computer system, identifying a threat associated with the monitored network system, identifying a known device identifier or user identification associated with an endpoint of the plurality of endpoints that is responsible for the threat and propagating a global isolation of the endpoint across network devices of the monitored network system. The global isolation is configured to block the device identifier or user identification associated with the endpoint that is responsible for the threat.