Proxy Server Isolating Unauthorized Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unauthorized applications, known as 'shadow IT,' can be deployed on company servers without compliance checks, leading to security breaches, liability risks, and unreliable services due to lack of oversight and auditing.
Innovation Solution
A system comprising a proxy server and a remediation framework that identifies and quarantines unauthorized applications by monitoring HTTP requests, assigning weights based on predefined conditions, and taking remedial actions such as blocking or redirecting traffic to a shadow account to isolate and disable these applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If technicians manually monitor and approve applications before deployment, then security and compliance are improved, but deployment time and operational efficiency deteriorate
Solution Approach 1:
Applications are pre-registered and vetted before deployment. The system maintains a registry of authorized applications with predefined security and compliance attributes, allowing applications to be approved in advance rather than requiring manual review at deployment time.
Solution Approach 2:
The system continuously monitors running applications and compares them against the authorized registry. When unauthorized applications are detected, the system automatically responds by isolating them, creating feedback loops that maintain security without requiring constant manual intervention.
2Reliability
If technicians conduct thorough auditing and approval processes for applications, then compliance and security are improved, but productivity and deployment speed deteriorate
Solution Approach 1:
Security and compliance checks are performed in advance during the application registration phase. Once registered, authorized applications can be deployed immediately without repeated auditing, thus maintaining compliance while improving deployment speed.
Solution Approach 2:
The system automatically manages application authorization and monitoring without requiring continuous technician intervention. The automated monitoring and isolation capabilities enable the system to self-regulate, improving productivity while maintaining security standards.
3Ease of operation
If unauthorized applications are allowed to run without detection, then operational flexibility and ease of use are improved, but security and reliability deteriorate
Solution Approach 1:
The system introduces an intermediary monitoring layer that operates transparently between applications and system resources. This intermediary automatically detects and isolates unauthorized applications without requiring users to manually report them, thus maintaining ease of operation while improving security.
4Measurement precision
If manual monitoring of all applications is performed, then detection accuracy is improved, but device complexity and resource requirements deteriorate
Solution Approach 1:
The system uses automated feedback mechanisms where monitoring data is continuously analyzed and compared against the authorized registry. This automated feedback loop maintains high detection accuracy without requiring complex manual monitoring processes.
Solution Approach 2:
The monitoring system operates autonomously, automatically detecting, identifying, and isolating unauthorized applications without requiring technician intervention. This self-service capability reduces system complexity while maintaining accurate detection through automated comparison against predefined authorization criteria.
Data Source
AI summary
Typically, a business desires to track and monitor all applications run on its servers. Nonetheless, one or more unauthorized applications may be running on the business's servers, exposing the business to potential regulatory liability and security breaches. Apparatus and methods are provided for isolating and disabling one or more unauthorized applications running on a server. The apparatus may comprise a system including a content-filtering web proxy server configured to filter outgoing requests and data associated with the requests. The system may also include a remediation framework configured to monitor request data in a proxy log stored by the proxy server. The remediation framework may be triggered to perform remedial action when the remediation framework determines that a request and associated data, as stored in the proxy log, meets predetermined conditions. The remediation framework, when triggered, may execute steps to truncate functionality of the unauthorized applications.


