Imposter Security Client and Service for Endpoint Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity and access management (IAM) systems fail to effectively protect endpoints and remote servers from unauthorized users, as they often allow imposters to access systems without detection, leading to potential data breaches and security risks.

Innovation Solution

The implementation of an Imposter Security Client (ISC) and a subscription-based Imposter Security Service (ISS) within the IAM system, which automatically exchanges information to protect endpoints from unauthorized users by using predefined policies and AI/ML models to detect and respond to malicious activities, thereby securing connected computing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IAM systems are used, then user access management is maintained, but endpoints and remote servers are vulnerable to unauthorized access by imposters

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security functionality into two parts: an Imposter Security Client (ISC) deployed on individual endpoints to perform local monitoring and detection, and a centralized Imposter Security Service (ISS) that coordinates responses. This segmentation allows distributed security monitoring without requiring complete system redesign, thereby improving reliability while managing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Imposter Security Client acts as an intermediary between the endpoint and the centralized IAM system, providing local intelligence for imposter detection. This intermediary layer enables endpoints to respond to security threats autonomously while still integrating with the broader IAM infrastructure, enhancing security protection without proportionally increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If imposter detection and response mechanisms are implemented, then unauthorized access is prevented, but system performance and user experience may be degraded

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The Imposter Security Client monitors only specific security-relevant activities and behaviors rather than all system operations. By focusing detection efforts on partial aspects of system activity that are most indicative of imposter behavior, the system achieves effective security protection while minimizing the performance overhead associated with comprehensive monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system enables endpoints to autonomously detect and respond to imposter activities using local intelligence and pre-configured policies. This self-service capability allows security responses to be executed without constant centralized coordination, reducing latency and maintaining system performance while preventing unauthorized access.

Inventive Principle:
Principle #25Self-service

3Reliability

If covert monitoring of user activities is performed, then imposter activities are detected, but user privacy and system transparency are compromised

Engineering Contradiction:
Improvedetection accuracyVSAvoidprivacy intrusion
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The monitoring system applies different levels of observation and analysis to different types of user activities based on their security relevance. Sensitive personal activities receive minimal monitoring, while security-critical behaviors are scrutinized more closely. This local quality approach maintains detection accuracy for imposter identification while reducing privacy intrusion in unrelated areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12021897B2Endpoint and remote server protection
Publication Date: 2024.06.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12021897B2 patent drawing
  • US12021897B2 patent drawing
  • US12021897B2 patent drawing

AI summary

A processor may install an imposter security client (ISC) at an endpoint. The processor may install a subscription based imposter security service (ISS). The ISS may be part of an identity and access management (IAM) system. The processor may exchange information between the ISC and the ISS. The exchange may be automatically triggered when the ISS receives an imposter identification (ID) from the IAM system. The imposter ID may be associated with an unauthorized endpoint user. The processor may protect the endpoint from the unauthorized endpoint user.