Secure Browser Isolation for BYOD Cyberattack Risk
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increased vulnerability of communications networks and digital resources to cyberattacks due to the proliferation of personal devices and cloud-based services complicates the provision of cyber protection and confidentiality, especially for enterprises with remote workers using Bring Your Own Device (BYOD) equipment.
Innovation Solution
A cyber secure communications system, CyberSafe, which includes a data and processing security hub and a secure web browser (SWB) operating within an isolated secure environment, monitors and controls data ingress and egress, enforces security policies, and provides enhanced visibility and protection against cyber threats by integrating with an Identity Provider (IDP) for authorized access to digital resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If personal devices and cloud-based services are proliferated to enable remote work and democratized information access, then ease of operation and adaptability are improved, but vulnerability to cyberattacks and device complexity increase
Solution Approach 1:
The patent introduces a secure gateway and isolated secure environment as intermediary components between the personal device and enterprise resources. The secure gateway acts as a mediator that filters and controls all communications, while the isolated secure environment serves as a sandboxed intermediary space where enterprise applications run without direct access to the device's operating system or personal data, thus enabling remote work while mitigating cyberattack vulnerability
Solution Approach 2:
The patent segments the device environment into distinct isolated zones: the personal device environment, the isolated secure environment for enterprise applications, and the secure gateway layer. This segmentation ensures that compromise in one segment does not propagate to others, allowing ease of remote operation while containing potential cyber threats within isolated boundaries
2Reliability
If secure isolation environments are implemented to protect against cyberattacks, then cyber protection is improved, but device complexity and processing overhead increase
Solution Approach 1:
The isolated secure environment is designed to be self-contained and self-managing, with its own virtualized resources and controlled access mechanisms. The secure gateway automatically manages isolation policies and communication filtering without requiring extensive manual configuration or complex external management systems, thus improving cyber protection while limiting the increase in device complexity
3Reliability
If comprehensive monitoring and control of data ingress and egress are implemented, then cyber protection is improved, but loss of information and processing time increase
Solution Approach 1:
The system performs preliminary actions by pre-establishing secure communication channels and pre-configuring isolation policies before data transfer occurs. The secure gateway pre- validates access requests and sets up encrypted tunnels in advance, allowing comprehensive monitoring and control of data flow while minimizing real-time processing delays and information loss during actual data transfer operations
Data Source
AI summary
A method for providing secure access to digital resources, the method comprising: monitoring communications between a website and a user using a web browser comprised in a user equipment (UE) that is useable to access the digital resources; processing the monitored communications to determine: a set (WVF) of website vulnerability features comprising features which as a result of the user connecting to the website render a digital resource of the digital resources with which the user communicates vulnerable to cyber damage; and a set of user browsing behaviour features (BHF) comprising features that characterize the user browsing behaviour and internet use pattern which render the digital resource vulnerable to cyber damage; determining based on the website vulnerability factors and the user profile a security risk indicator (SRI) having a value that provides an estimate of a cyber damage risk to the digital resource resulting from the user connecting to the website and the digital resource; and based on the SRI value determining whether or not to permit the user to access the website.


