Security Appliance Default Gateway for Ransomware Lateral Movement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional enterprise security solutions are inadequate in protecting against ransomware attacks, particularly in shared VLAN environments, as they fail to prevent lateral movement of ransomware within the network, and existing solutions are challenging to deploy on IoT devices and older operating systems.

Innovation Solution

A security appliance is deployed as a default gateway with point-to-point links between endpoint devices, using a DHCP relay function to set a subnet mask of 255.255.255.255, forcing all traffic through the appliance and allowing only authorized communication, while monitoring for ransomware attributes and quarantining compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional enterprise security solutions are deployed in shared VLAN environments, then network segmentation by department is achieved, but lateral movement of ransomware within the VLAN domain cannot be prevented

Engineering Contradiction:
Improveprotection against external attacksVSAvoidlateral propagation of ransomware
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the shared VLAN broadcast domain into multiple isolated point-to-point virtual networks. Each endpoint device is assigned its own virtual network interface connected exclusively to the security appliance, eliminating the shared broadcast domain that enables lateral ransomware propagation while maintaining departmental VLAN segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security appliance acts as an intermediary between endpoint devices and the external network. All traffic from endpoint devices is forced to pass through the security appliance's point-to-point virtual interfaces, enabling centralized security control and monitoring while blocking direct peer-to-peer communication that ransomware exploits for lateral movement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If endpoint protection agents are deployed on each device, then ransomware detection capability is improved, but deployment and management complexity increases and IoT devices cannot be protected

Engineering Contradiction:
Improveransomware detection capabilityVSAvoidagent deployment and management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security appliance serves as a centralized intermediary that performs ransomware detection and security enforcement for all endpoint devices. Instead of deploying agents on each device, the security appliance intercepts and inspects all traffic from endpoint devices through point-to-point virtual interfaces, providing unified protection including ransomware detection, blocking, and incident response without requiring device-specific agents.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security appliance automatically performs security functions including traffic inspection, ransomware detection, threat blocking, and incident response without requiring manual agent deployment or configuration on endpoint devices. The system self-manages security policies and automatically responds to threats, eliminating the need for complex agent management across diverse devices including IoT.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple security appliances are deployed for high availability, then system reliability is improved, but traffic load distribution and failure recovery complexity increases

Engineering Contradiction:
Improvehigh availabilityVSAvoidload balancing and failure recovery
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple security appliances are merged into a unified high-availability cluster that presents a single logical gateway to endpoint devices. The cluster uses virtual IP addressing and state synchronization to combine the capabilities of multiple appliances, providing load distribution and automatic failover while maintaining a simplified single-gateway interface that reduces configuration and management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The high-availability cluster implements automatic health monitoring and failure detection through feedback mechanisms. Each security appliance continuously monitors the status of cluster members and automatically redistributes traffic away from failed appliances. When a failure is detected, the system automatically triggers failover procedures to maintain service continuity without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12057969B1System and method for load balancing endpoint traffic to multiple security appliances acting as default gateways with point-to-point links between endpoints
Publication Date: 2024.08.06 ZSCALER INC
  • US12057969B1 patent drawing
  • US12057969B1 patent drawing
  • US12057969B1 patent drawing

AI summary

A technique to stop lateral movement of ransomware between endpoints in a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication by overwriting the DHCP responses. A high availability cluster of the gateways is utilized to distribute traffic and implement load balancing amongst the gateways.