Network-Aware Endpoint Security Agent for Trusted Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint security agents require manual intervention to adjust security behavior when transitioning between trusted and untrusted networks, leading to inefficiencies and user inconvenience.
Innovation Solution
An endpoint security agent dynamically adjusts its behavior based on network location by querying a cloud-based trusted network determination service, enabling or disabling security features like secure Internet tunnels and micro-segmentation, and using local caches when the service is unreachable.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an always-on SSL VPN tunnel is used to route traffic through a cloud-hosted firewall, then the device is protected when outside the trusted domain, but the device cannot access enterprise resources when inside a trusted domain
Solution Approach 1:
The SSL VPN tunnel is made dynamic by automatically enabling it when the device is outside the trusted domain and disabling it when inside the trusted domain. The system monitors network location and adjusts the tunnel state accordingly, eliminating the need for manual intervention while resolving the contradiction between protection and resource access.
2Reliability
If manual pausing of the SSL VPN tunnel or adding local firewall rules is required to access enterprise resources in a trusted domain, then security is maintained outside the trusted domain, but user convenience is reduced
Solution Approach 1:
The system performs self-service by automatically detecting when the device is inside or outside the trusted domain and adjusting the SSL VPN tunnel state accordingly. The endpoint security agent monitors network location and autonomously enables or disables the tunnel without requiring user action, thereby maintaining security while improving convenience.
3Reliability
If security features are continuously enabled, then security is maintained at all times, but system performance and user experience deteriorate in trusted networks
Solution Approach 1:
Instead of continuous operation, the SSL VPN tunnel operates periodically based on network location detection. The system continuously monitors whether the device is inside or outside the trusted domain and adjusts the tunnel state accordingly, maintaining security when needed while improving performance when the device is in a trusted domain.
Data Source
AI summary
Systems and methods for adjusting the behavior of an endpoint security agent based on a network location are provided. According to an embodiment, an agent of an endpoint device identifies whether a security service of a cloud-based security service is not reachable or is unresponsive. The security service is associated with a particular security function implemented by the agent. When the security service is not reachable or is unresponsive, the agent further determines whether the endpoint device is within a trusted network of multiple trusted networks that have been previously registered with the cloud-based security service by querying a trusted network determination service associated with the cloud-based security service. When the determination is affirmative, the particular security feature is configured for operating inside a trusted network. When the determination is negative, the particular security feature is configured for operating outside a trusted network.


