Kernel Security Agent Network Containment for Malware Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firewalls are ineffective in preventing malware propagation from compromised host machines to network-adjacent devices, despite security software installations, due to lack of configuration to address compromised states and user sophistication in modifying firewall policies.
Innovation Solution
A kernel-level security agent is installed on computing devices to monitor and analyze events, sending data to a remote security system for detection, and upon malware detection, remotely enabling network containment by implementing a firewall policy to disconnect the device from the network, using a user-mode component to invoke the necessary API for firewall configuration on Mac OS and similar systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing firewalls are enabled to restrict incoming and outgoing traffic, then network security is improved, but they fail to address compromised host machines and allow malware propagation to network-adjacent devices
Solution Approach 1:
The system performs preliminary detection of compromised host machines by monitoring security events and malware behavior before malware can propagate to network-adjacent devices. Once compromise is detected, containment actions are immediately triggered to isolate the affected machine, preventing harmful factors from spreading further in the network.
Solution Approach 2:
The invention introduces a specialized containment mechanism that acts as an intermediary between existing firewall systems and compromised devices. This intermediary component specifically targets and isolates compromised host machines while allowing normal network traffic to continue flowing through non-compromised devices, thus addressing malware propagation without disrupting overall network operations.
2Object-affected harmful factors
If firewall policies are customized to address compromised machines, then malware propagation is prevented, but user sophistication in creating and modifying firewall policies is required which most users lack
Solution Approach 1:
The system implements self-service functionality by automatically detecting compromised host machines and autonomously applying appropriate containment policies. The system monitors security events, identifies malware infections, and automatically isolates affected devices without requiring user intervention. This eliminates the need for users to possess sophisticated knowledge of firewall configuration while still achieving effective malware propagation prevention.
Solution Approach 2:
The invention dynamically changes firewall parameters and containment settings based on the detected threat level and compromise state of host machines. Rather than requiring users to manually configure complex policies, the system automatically adjusts network isolation parameters, traffic filtering rules, and containment intensity based on real-time security conditions, making the solution both effective and easy to operate.
3Productivity
If a compromised host machine remains connected to the Internet after malware intrusion, then normal network operations are maintained, but malware can spread to network-adjacent host machines
Solution Approach 1:
The system implements dynamic network containment that adapts connectivity status based on compromise detection. Non-compromised host machines maintain full Internet connectivity for normal operations, while compromised machines are dynamically isolated when threats are detected. This dynamic approach allows the system to balance productivity and security by adjusting network access rights in real-time based on the actual security state of each device.
Solution Approach 2:
The invention applies different network access qualities to different host machines based on their compromise status. Non-compromised devices receive full network access with no restrictions, while compromised devices are subjected to localized containment measures that restrict their network communications. This local quality differentiation allows normal network operations to continue uninterrupted for healthy devices while preventing malware spread from infected machines.
Data Source
AI summary
A computing device can install and execute a kernel-level security agent that interacts with a remote security system as part of a detection loop aimed at defeating malware attacks. The kernel-level security agent can be installed with a firewall policy that can be remotely enabled by the remote security system in order to “contain” the computing device. Accordingly, when the computing device is being used, and a malware attack is detected on the computing device, the remote security system can send an instruction to contain the computing device, which causes the implementation, by an operating system (e.g., a Mac™ operating system) of the computing device, of the firewall policy accessible to the kernel-level security agent. Upon implementation and enforcement of the firewall policy, outgoing data packets from, and incoming data packets to, the computing device that would have been allowed prior to the implementation of the firewall policy are denied.


