Proxy Server Isolating Unauthorized Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized applications, known as 'shadow IT,' can be deployed on company servers without compliance checks, leading to security breaches, liability risks, and unreliable services due to lack of oversight and auditing.

Innovation Solution

A system comprising a proxy server and a remediation framework that identifies and quarantines unauthorized applications by monitoring HTTP requests, assigning weights based on predefined conditions, and taking remedial actions such as blocking or redirecting traffic to a shadow account to isolate and disable these applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If technicians manually monitor and approve applications before deployment, then security and compliance are improved, but deployment time and operational efficiency deteriorate

Engineering Contradiction:
Improvesecurity and complianceVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Applications are pre-registered and vetted before deployment. The system maintains a registry of authorized applications with predefined security and compliance attributes, allowing applications to be approved in advance rather than requiring manual review at deployment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors running applications and compares them against the authorized registry. When unauthorized applications are detected, the system automatically responds by isolating them, creating feedback loops that maintain security without requiring constant manual intervention.

Inventive Principle:
Principle #23Feedback

2Reliability

If technicians conduct thorough auditing and approval processes for applications, then compliance and security are improved, but productivity and deployment speed deteriorate

Engineering Contradiction:
Improvecompliance and securityVSAvoiddeployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security and compliance checks are performed in advance during the application registration phase. Once registered, authorized applications can be deployed immediately without repeated auditing, thus maintaining compliance while improving deployment speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically manages application authorization and monitoring without requiring continuous technician intervention. The automated monitoring and isolation capabilities enable the system to self-regulate, improving productivity while maintaining security standards.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If unauthorized applications are allowed to run without detection, then operational flexibility and ease of use are improved, but security and reliability deteriorate

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsecurity and reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces an intermediary monitoring layer that operates transparently between applications and system resources. This intermediary automatically detects and isolates unauthorized applications without requiring users to manually report them, thus maintaining ease of operation while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If manual monitoring of all applications is performed, then detection accuracy is improved, but device complexity and resource requirements deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses automated feedback mechanisms where monitoring data is continuously analyzed and compared against the authorized registry. This automated feedback loop maintains high detection accuracy without requiring complex manual monitoring processes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The monitoring system operates autonomously, automatically detecting, identifying, and isolating unauthorized applications without requiring technician intervention. This self-service capability reduces system complexity while maintaining accurate detection through automated comparison against predefined authorization criteria.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11134062B1Isolating and disabling unauthorized applications
Publication Date: 2021.09.28 BANK OF AMERICA CORP
  • US11134062B1 patent drawing
  • US11134062B1 patent drawing
  • US11134062B1 patent drawing

AI summary

Typically, a business desires to track and monitor all applications run on its servers. Nonetheless, one or more unauthorized applications may be running on the business's servers, exposing the business to potential regulatory liability and security breaches. Apparatus and methods are provided for isolating and disabling one or more unauthorized applications running on a server. The apparatus may comprise a system including a content-filtering web proxy server configured to filter outgoing requests and data associated with the requests. The system may also include a remediation framework configured to monitor request data in a proxy log stored by the proxy server. The remediation framework may be triggered to perform remedial action when the remediation framework determines that a request and associated data, as stored in the proxy log, meets predetermined conditions. The remediation framework, when triggered, may execute steps to truncate functionality of the unauthorized applications.