Network Access Policy Management for Endpoint Threat Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security threat management systems struggle to effectively mitigate security threats on network-accessible devices without disrupting core network functions, as they often require endpoints to be taken offline, which can be detrimental to business operations.
Innovation Solution
A threat management system that includes a network-access policy management facility to implement network-level elevated security measures, such as isolating affected endpoints while allowing partial functionality to maintain network integrity and prevent malicious code spread, using a combination of security agents, policy management, and remediation tools to detect and remediate threats without disconnecting endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security threat mitigation is implemented, then security threats are effectively blocked, but network accessibility and core functions are disrupted
Solution Approach 1:
The patent segments network access by implementing application-layer filtering that distinguishes between different applications and data flows. Instead of blocking all traffic from an affected endpoint, the system selectively blocks only malicious applications or specific data flows while allowing legitimate traffic to continue, thus maintaining network accessibility while ensuring security threat mitigation.
Solution Approach 2:
The system applies different security measures to different parts of the network traffic based on local characteristics. By analyzing application-type fields and packet characteristics, the system tailors security responses to specific applications or data flows rather than applying uniform blocking, enabling selective mitigation that preserves essential network functions.
2Reliability
If endpoints are isolated to prevent malicious code spread, then security is improved, but business operations are disrupted
Solution Approach 1:
Instead of implementing complete endpoint isolation, the system applies partial measures that selectively block only the extent necessary to contain malicious code spread. By blocking only specific malicious applications or data flows rather than all traffic, the system achieves sufficient security containment while preserving legitimate business operations.
Solution Approach 2:
The patent introduces an intermediary application-layer filtering mechanism between the affected endpoint and the rest of the network. This intermediary selectively inspects and filters traffic based on application-type fields, allowing legitimate traffic to pass while blocking only malicious content, thus containing security threats without completely isolating the endpoint.
3Reliability
If network-level security measures are implemented, then threat detection and blocking are enhanced, but system complexity increases
Solution Approach 1:
The system implements a universal application-layer filtering mechanism that handles multiple security functions through a single integrated approach. By using application-type fields and packet characteristic analysis, the same filtering infrastructure supports threat detection, traffic classification, and selective blocking, reducing overall system complexity compared to multiple separate security systems.
Solution Approach 2:
The patent embeds multiple security analysis functions within a nested structure where application-layer filtering operates within the existing network infrastructure. The system nests packet inspection, application identification, and threat blocking within a hierarchical processing model that leverages existing network protocols and data structures, minimizing additional complexity.
Data Source
AI summary
Various aspects related to methods, systems, and computer readable media for detection and blocking of security threats for network-accessible devices. Methods may include receiving an indication of a security threat to a user device of the plurality of user devices, the indication of security threat associated with a device threat type, determining that the device threat type is a threat type that requires elevated security measures, responsive to the determining that the device threat type requires elevated security measures, elevating security measures associated with the user device for a first time period, and, after the elevating, automatically remediating the security threat on the user device within the first time period.


