Network-Aware Endpoint Security Agent for Trusted Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint security agents require manual intervention to adjust security behavior when transitioning between trusted and untrusted networks, leading to inefficiencies and user inconvenience.

Innovation Solution

An endpoint security agent dynamically adjusts its behavior based on network location by querying a cloud-based trusted network determination service, enabling or disabling security features like secure Internet tunnels and micro-segmentation, and using local caches when the service is unreachable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an always-on SSL VPN tunnel is used to route traffic through a cloud-hosted firewall, then the device is protected when outside the trusted domain, but the device cannot access enterprise resources when inside a trusted domain

Engineering Contradiction:
Improvedevice protectionVSAvoidaccess to enterprise resources
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The SSL VPN tunnel is made dynamic by automatically enabling it when the device is outside the trusted domain and disabling it when inside the trusted domain. The system monitors network location and adjusts the tunnel state accordingly, eliminating the need for manual intervention while resolving the contradiction between protection and resource access.

Inventive Principle:
Principle #15Dynamics

2Reliability

If manual pausing of the SSL VPN tunnel or adding local firewall rules is required to access enterprise resources in a trusted domain, then security is maintained outside the trusted domain, but user convenience is reduced

Engineering Contradiction:
Improvesecurity outside trusted domainVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically detecting when the device is inside or outside the trusted domain and adjusting the SSL VPN tunnel state accordingly. The endpoint security agent monitors network location and autonomously enables or disables the tunnel without requiring user action, thereby maintaining security while improving convenience.

Inventive Principle:
Principle #25Self-service

3Reliability

If security features are continuously enabled, then security is maintained at all times, but system performance and user experience deteriorate in trusted networks

Engineering Contradiction:
Improvecontinuous securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of continuous operation, the SSL VPN tunnel operates periodically based on network location detection. The system continuously monitors whether the device is inside or outside the trusted domain and adjusts the tunnel state accordingly, maintaining security when needed while improving performance when the device is in a trusted domain.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12463979B2Adjusting behavior of an endpoint security agent based on network location
Publication Date: 2025.11.04 FORTINET INC
  • US12463979B2 patent drawing
  • US12463979B2 patent drawing
  • US12463979B2 patent drawing

AI summary

Systems and methods for adjusting the behavior of an endpoint security agent based on a network location are provided. According to an embodiment, an agent of an endpoint device identifies whether a security service of a cloud-based security service is not reachable or is unresponsive. The security service is associated with a particular security function implemented by the agent. When the security service is not reachable or is unresponsive, the agent further determines whether the endpoint device is within a trusted network of multiple trusted networks that have been previously registered with the cloud-based security service by querying a trusted network determination service associated with the cloud-based security service. When the determination is affirmative, the particular security feature is configured for operating inside a trusted network. When the determination is negative, the particular security feature is configured for operating outside a trusted network.