NDIS Firewall VPN Enforcement for Mobile Endpoints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate computing assets face challenges in enforcing secure internet connections, especially in public or insecure locations, as existing tools lack the ability to confirm and enforce VPN usage, leading to security risks when devices move between locations.
Innovation Solution
Implementing a security policy that enforces a full VPN tunnel connection through an NDIS firewall, monitors packet traffic for compliance, and quarantines devices if policies are not met, with automatic remediation measures to ensure secure internet access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing tools launch VPN connections, then VPN connection capability is provided, but enforcement and confirmation of correct VPN usage is not achieved
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors network traffic to verify VPN connection status and compliance. The policy enforcement module receives feedback about connection state and takes corrective actions (blocking traffic, alerting users) when compliance is not achieved, thereby ensuring reliable VPN usage enforcement without requiring complex manual verification procedures
Solution Approach 2:
The system performs self-verification by automatically monitoring its own network traffic and compliance state. The policy enforcement module autonomously detects whether VPN connections are properly established and maintained, and automatically blocks non-compliant traffic without requiring external verification, simplifying the overall system architecture while ensuring reliable enforcement
2Adaptability or versatility
If corporate assets connect in public locations, then mobility and accessibility are improved, but security risks increase
Solution Approach 1:
The patent introduces a policy enforcement module as an intermediary between the corporate network and public networks. This module acts as a security gatekeeper that inspects all network traffic, enforces VPN connection requirements, and blocks unauthorized access attempts, thereby enabling location flexibility while maintaining security by filtering harmful factors before they reach the corporate network
Solution Approach 2:
The system applies preliminary anti-action by proactively blocking potentially harmful network traffic before it can compromise security. The policy enforcement module pre-establishes security policies that automatically prevent connections to known malicious networks and block traffic from unsecured locations, countering security risks before they materialize while allowing legitimate mobile access
3Reliability
If VPN tunnel connections are established, then secure communication is achieved, but packet traffic monitoring and compliance verification become complex
Solution Approach 1:
The patent applies preliminary action by pre-configuring the policy enforcement module with compliance criteria and monitoring rules before VPN connections are established. The system proactively sets up traffic filtering policies and compliance verification mechanisms in advance, making it easier to detect and measure compliance status without requiring complex real-time analysis of encrypted VPN traffic
Data Source
AI summary
Methods and apparatus enforce a secure internet connection from a mobiles endpoint computing device. A security policy for the endpoint is defined based on its location. From that location, an internet connection is established and detected. This event triggers the launching of a full VPN tunnel connection including an NDIS firewall forcing packet traffic through a port of the endpoint computing device assigned by the security policy and/or MAC/IP addresses of a VPN concentrator. Thereafter, the packet traffic is monitored for compliance with the security policy. This includes determining whether packet traffic over the assigned port is observed within a given time or packet traffic is attempted over other ports. Monitoring occurs whether or not the protocol of the VPN tunnel connection is known. Other features contemplate quarantining for improper operation of the VPN tunnel, undertaking remediation, and computer program products, to name a few.


