Remote Access Monitoring via Session Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Monitoring and controlling remote access to enterprise networks is complicated by the creation of multiple security associations when remote clients connect, making it difficult for administrators to track and manage which resources are accessed by which entities.

Innovation Solution

The technique aggregates multiple security associations into a single 'connection' using session identifiers, allowing administrators to view and manage resources accessed by remote clients through a secure remote network connection, such as DirectAccess, by grouping security associations into entity sessions based on the remote client's identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security associations are formed for remote client connections, then secure access to enterprise network resources is improved, but monitoring and controlling remote access becomes complicated

Engineering Contradiction:
Improvesecure accessVSAvoidmonitoring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security associations into a single aggregated view represented by a connection object. This connection object consolidates multiple security associations that would otherwise be separate and difficult to track, providing a unified perspective for monitoring and controlling remote access while maintaining the security benefits of multiple associations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the monitoring function by introducing a connection object that represents a specific remote client's access session. This segmentation allows the system to track and manage multiple security associations individually at the connection level, making monitoring more manageable despite the complexity introduced by multiple associations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple security associations are created for remote client connections, then resource access control is improved, but tracking which resources are accessed by which entities becomes difficult

Engineering Contradiction:
Improveaccess controlVSAvoidaccess tracking information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The connection object serves as an intermediary that links remote clients to their accessed resources. It acts as a mediator between the multiple security associations and the resources, providing a clear tracking mechanism that shows which resources are accessed by which entities without losing the detailed control provided by multiple security associations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The connection object is a universal structure that can represent any remote client's access session, regardless of the number or type of resources accessed. This multi-functional object can track various combinations of security associations and resources, making the system flexible and comprehensive in its tracking capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9332017B2Monitoring remote access to an enterprise network
Publication Date: 2016.05.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9332017B2 patent drawing
  • US9332017B2 patent drawing
  • US9332017B2 patent drawing

AI summary

Techniques to provide an improved representation of remote network access for a network administrator managing and controlling access to resources on an enterprise network. The representation indicates resources accessed by a remote computer or by a user of that computer and provides associated information useful for managing remote network access. To create the representation, multiple security associations formed between a remote client computer and resources on the enterprise network are associated with entity sessions, based on identical session identifiers generated for each security association within an entity session. The entity sessions may be aggregated into a DirectAccess “connection” between the remote client computer and the enterprise network, based on an identity of the remote client computer. Resources accessed over the connection may be identified using a session identifier of each entity session so that security associations in that entity session may be matched with the resources.