Kernel Security Agent Network Containment for Malware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewalls are ineffective in preventing malware propagation from compromised host machines to network-adjacent devices, despite security software installations, due to lack of configuration to address compromised states and user sophistication in modifying firewall policies.

Innovation Solution

A kernel-level security agent is installed on computing devices to monitor and analyze events, sending data to a remote security system for detection, and upon malware detection, remotely enabling network containment by implementing a firewall policy to disconnect the device from the network, using a user-mode component to invoke the necessary API for firewall configuration on Mac OS and similar systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing firewalls are enabled to restrict incoming and outgoing traffic, then network security is improved, but they fail to address compromised host machines and allow malware propagation to network-adjacent devices

Engineering Contradiction:
Improvenetwork securityVSAvoidmalware propagation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection of compromised host machines by monitoring security events and malware behavior before malware can propagate to network-adjacent devices. Once compromise is detected, containment actions are immediately triggered to isolate the affected machine, preventing harmful factors from spreading further in the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces a specialized containment mechanism that acts as an intermediary between existing firewall systems and compromised devices. This intermediary component specifically targets and isolates compromised host machines while allowing normal network traffic to continue flowing through non-compromised devices, thus addressing malware propagation without disrupting overall network operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If firewall policies are customized to address compromised machines, then malware propagation is prevented, but user sophistication in creating and modifying firewall policies is required which most users lack

Engineering Contradiction:
Improvemalware propagationVSAvoidfirewall configuration
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system implements self-service functionality by automatically detecting compromised host machines and autonomously applying appropriate containment policies. The system monitors security events, identifies malware infections, and automatically isolates affected devices without requiring user intervention. This eliminates the need for users to possess sophisticated knowledge of firewall configuration while still achieving effective malware propagation prevention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention dynamically changes firewall parameters and containment settings based on the detected threat level and compromise state of host machines. Rather than requiring users to manually configure complex policies, the system automatically adjusts network isolation parameters, traffic filtering rules, and containment intensity based on real-time security conditions, making the solution both effective and easy to operate.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If a compromised host machine remains connected to the Internet after malware intrusion, then normal network operations are maintained, but malware can spread to network-adjacent host machines

Engineering Contradiction:
Improvenetwork operationsVSAvoidmalware spread
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system implements dynamic network containment that adapts connectivity status based on compromise detection. Non-compromised host machines maintain full Internet connectivity for normal operations, while compromised machines are dynamically isolated when threats are detected. This dynamic approach allows the system to balance productivity and security by adjusting network access rights in real-time based on the actual security state of each device.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention applies different network access qualities to different host machines based on their compromise status. Non-compromised devices receive full network access with no restrictions, while compromised devices are subjected to localized containment measures that restrict their network communications. This local quality differentiation allows normal network operations to continue uninterrupted for healthy devices while preventing malware spread from infected machines.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11368432B2Network containment of compromised machines
Publication Date: 2022.06.21 CROWDSTRIKE
  • US11368432B2 patent drawing
  • US11368432B2 patent drawing
  • US11368432B2 patent drawing

AI summary

A computing device can install and execute a kernel-level security agent that interacts with a remote security system as part of a detection loop aimed at defeating malware attacks. The kernel-level security agent can be installed with a firewall policy that can be remotely enabled by the remote security system in order to “contain” the computing device. Accordingly, when the computing device is being used, and a malware attack is detected on the computing device, the remote security system can send an instruction to contain the computing device, which causes the implementation, by an operating system (e.g., a Mac™ operating system) of the computing device, of the firewall policy accessible to the kernel-level security agent. Upon implementation and enforcement of the firewall policy, outgoing data packets from, and incoming data packets to, the computing device that would have been allowed prior to the implementation of the firewall policy are denied.