Network Appliance Group Policy Application via User Agent Token Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks face challenges in identifying and mitigating risks from deprecated or malicious software, as existing security protocols struggle to effectively monitor and respond to user agent strings that indicate potential security vulnerabilities or malware.

Innovation Solution

A network appliance monitors user agent strings and applies corrective group policies by matching tokens in these strings with stored signatures, allowing for real-time identification and mitigation of risks, including blocking messages from reaching intended destinations or updating software to remove vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security protocols are used to monitor user agent strings, then basic network communication is maintained, but the ability to identify and respond to deprecated or malicious software is insufficient

Engineering Contradiction:
Improvesecurity risk identification capabilityVSAvoidsecurity protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the user agent string into individual tokens and compares each token against a signature database. This segmentation allows the system to identify specific software components (browsers, plugins, operating systems) independently, improving security detection capability without requiring analysis of the entire user agent string as a single complex unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary signature database that stores known patterns of deprecated or malicious software. The comparison engine acts as a mediator between the user agent string and security policies, matching tokens against signatures and translating these matches into actionable group policy decisions, thereby simplifying the overall security monitoring process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time monitoring and analysis of user agent strings is implemented, then security risks can be identified promptly, but network appliance processing load increases

Engineering Contradiction:
Improvereal-time security detectionVSAvoidnetwork appliance processing load
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by focusing analysis only on specific tokens within the user agent string that are relevant to security concerns (such as browser version, plugin types, and operating system identifiers). Rather than processing the entire user agent string uniformly, the system selectively analyzes only the portions that contain security-relevant information, reducing overall processing load while maintaining real-time detection capability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by performing signature matching only on extracted tokens rather than analyzing the complete user agent string. This selective approach processes only the necessary portions of the data (individual software identifiers) while skipping unnecessary processing, thereby achieving real-time security detection with reduced computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Extent of automation

If group policies are applied based on signature matching, then corrective actions can be automatically enforced, but network management complexity increases

Engineering Contradiction:
Improveautomated corrective action enforcementVSAvoidnetwork management complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent creates universal group policies that can be applied to multiple devices simultaneously based on their software signatures. A single policy definition can enforce security requirements across all devices running identified deprecated or vulnerable software, regardless of device type or location in the network. This multi-functionality reduces network management complexity by allowing administrators to manage security at a policy level rather than individually configuring each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the network appliance continuously monitors user agent strings, compares them against signatures, and automatically adjusts group policy assignments based on the results. This closed-loop feedback system enables automated corrective actions (such as blocking devices with malicious software or prompting updates for deprecated browsers) without requiring manual intervention, thereby increasing automation while managing complexity through policy-based control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9705898B2Applying group policies
Publication Date: 2017.07.11 IBOSS INC
  • US9705898B2 patent drawing
  • US9705898B2 patent drawing
  • US9705898B2 patent drawing

AI summary

Information corresponding to a set of signatures is maintained, and for each signature in the set, an associated group policy of a network is maintained. A message from a device on the network is intercepted, and the message includes a header. At least a portion of the header matches a signature in the set of signatures. Responsive to determining that the portion of the header matches the signature, the matched signature's associated group policy of the network is applied to the device on the network.