Local Security Agents for Distributed Network Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing host-based network security technologies have limited visibility and decision-making capabilities due to restricted information, making them vulnerable to IP spoofing and unauthorized communications.
Innovation Solution
A two-stage validation process using local security agents on each system to enforce policies without a backend system, where a policy enforcement engine distributes trusted public certificates to validate connections based on local policies, enhancing security by preventing policy violations undetected by traditional systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If host-based firewalls monitor connections at egress or ingress points, then basic access control is achieved, but visibility into application identity and ability to detect policy violations is limited
Solution Approach 1:
The patent introduces local security agents as intermediary components that sit between applications and network infrastructure. These agents collect detailed information about application identity, connection parameters, and policy compliance, then relay this information to centralized policy enforcement points. This intermediary layer enables comprehensive visibility into application identity without requiring modifications to the applications themselves, resolving the contradiction between limited visibility and reliable policy violation detection.
2Device complexity
If existing security technologies operate in relative isolation with limited information, then system complexity is maintained, but vulnerability to IP spoofing and unauthorized communications increases
Solution Approach 1:
The patent merges the functionality of multiple isolated security components into a unified security architecture where local security agents operate in coordination with centralized policy enforcement. By combining information gathering, policy evaluation, and enforcement functions into an integrated system, the architecture maintains manageable complexity while eliminating vulnerabilities to IP spoofing through comprehensive identity verification and bidirectional connection validation.
Solution Approach 2:
The patent implements feedback mechanisms where local security agents continuously monitor connection parameters and application identity, then provide feedback to centralized policy enforcement points. This feedback loop enables real-time detection of IP spoofing attempts and unauthorized communications, allowing the system to adapt its security responses dynamically while maintaining architectural simplicity through automated decision-making.
3Ease of manufacture
If traditional firewalls only monitor network-related information like IP address and port, then implementation simplicity is maintained, but ability to validate application identity and enforce policies is insufficient
Solution Approach 1:
The patent segments the security function into separate components: local security agents that collect application identity information and network connection data, and centralized policy enforcement points that make authorization decisions. This segmentation allows each component to focus on specific tasks, maintaining implementation simplicity while enabling precise application identity validation through comprehensive information gathering and centralized policy evaluation.
Data Source
AI summary
A system validates the establishment and/or continuation of a connection between two applications over a network using a two-stage process: (1) a local security agent executing on the same source system as the source application validates the connection against a set of policies stored locally on the source system; and (2) a local security agent executing on the same destination system as the destination application validates the connection against a set of policies stored locally on the destination system. The connection is allowed or blocked depending on the outcome of the two-stage validation. Before the validation process, a policy enforcement engine distributes copies of a trusted public certificate to the source and destination local security agents, which extend their local copies of the certificate to enable them to enforce policies without the use of a backend system.


