Remote Desktop Access Risk Assessment via Client Environment Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for detecting unauthorized access via Remote Desktop Protocol (RDP) are inadequate, as they rely on network traffic analysis which can be evaded by attackers, leading to undetected malicious activities.
Innovation Solution
A system that establishes a remote desktop access connection to acquire and analyze information about the client machine's system environment, comparing it to defined usage patterns to assess the risk level and apply control actions based on the analysis, without requiring additional connections or software on the client machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network traffic analysis is used to detect unauthorized access, then detection capability is provided, but attackers can evade detection by disguising malicious activities
Solution Approach 1:
Instead of analyzing network traffic packets to detect attacks, the patent inverts the approach by having the target machine actively query and analyze the client machine's system environment information through the RDP connection. This reversal allows detection of the client's true identity and status, making evasion ineffective.
Solution Approach 2:
The patent introduces an intermediary assessment mechanism that operates through the existing RDP connection. The target machine acts as an intermediary to evaluate client machine information (OS version, screen resolution, hardware details) without requiring additional connections, thereby detecting disguised attacks while maintaining protocol compatibility.
2Measurement precision
If additional connections or software are deployed on the client machine for security monitoring, then detection accuracy is improved, but system complexity and client burden increase
Solution Approach 1:
The target machine performs self-service security assessment by actively querying the client machine through existing RDP protocols. No additional software or agents are installed on the client; the client's own system information (OS, hardware, screen resolution) is utilized to assess its identity and detect spoofing, thereby maintaining simplicity while improving accuracy.
Solution Approach 2:
The RDP connection serves multiple functions: it enables both legitimate remote access and security assessment simultaneously. The same connection channel is used for both operational purposes and detection purposes, eliminating the need for separate monitoring infrastructure and reducing overall system complexity.
3Speed
If real-time analysis of client machine information is performed, then malicious behavior is identified promptly, but processing resources are consumed
Solution Approach 1:
The target machine performs preliminary assessment of client machine information immediately upon connection establishment. By evaluating system environment details (OS version, screen resolution, hardware configuration) at the outset, the patent enables real-time detection without continuous heavy processing, thereby balancing speed with resource consumption.
Data Source
AI summary
A method for assessing a risk level of a remote desktop access connection includes establishing a remote desktop access connection session between a target machine and the client machine over a network. The remote desktop access connection is established in response to a request received from the client machine. The remote desktop access connection is used acquire, from the client machine, information pertaining to a system environment of the client machine during the connection session. The acquired information is analyzed by comparing the acquired information to information indicative of a defined use of the client machine. Based on the analysis, an assessment is generated of the risk level of the connection session and/or to identify suspicious use of the remote desktop access connection by the client machine.


