Unified Access Control Device Proactive Endpoint Quarantine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control systems, such as those using the 802.1X protocol, often fail to prevent the spread of malware across enterprise networks in a timely manner, as they typically quarantine infected devices only after detection, allowing malicious traffic to infect other devices before quarantine can be enforced.
Innovation Solution
A unified access control (UAC) device aggregates health status information from endpoint devices to identify potentially infected devices that have not yet been infected, using this data to proactively quarantine a set of devices sharing common infection criteria, thereby preventing the spread of malicious agents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network access control systems quarantine infected devices only after detection, then the system complexity is reduced, but the malware spread prevention capability deteriorates
Solution Approach 1:
The system performs preliminary actions by proactively quarantining devices before malware infection occurs. The NAC device monitors health status information of endpoint devices and identifies devices that are likely to be infected based on common characteristics with currently infected devices, then quarantines them in advance to prevent malware spread.
Solution Approach 2:
The system implements feedback mechanisms where the NAC device continuously monitors health status information from endpoint devices, detects malware infections, and adjusts quarantine decisions based on the monitored data. This feedback loop enables dynamic response to changing network security conditions.
2Measurement precision
If the system aggregates health status information from all endpoint devices, then the proactive infection detection capability is improved, but the information processing complexity increases
Solution Approach 1:
The system extracts only the necessary health status information from endpoint devices that is relevant for infection detection. Instead of processing all device data, the NAC device focuses on extracting specific characteristics (such as operating system version, patch level, antivirus status) that are indicative of malware infection risk.
Solution Approach 2:
The system segments the health status information into categories and processes it in manageable portions. The NAC device divides the monitoring task into separate functions: collecting health status data, analyzing for common characteristics with infected devices, and making quarantine decisions, thereby reducing overall processing complexity.
3Speed
If the system quarantines devices based on common characteristics with infected devices, then the response time is improved, but the false positive rate increases
Solution Approach 1:
The system applies local quality by tailoring quarantine decisions to specific devices based on their individual health status characteristics. Rather than applying a blanket quarantine to all devices with certain characteristics, the NAC device evaluates each device's specific attributes (software versions, patch levels, security software status) to determine if quarantine is appropriate.
Solution Approach 2:
The system uses parameter changes by monitoring variations in health status parameters over time. The NAC device tracks changes in device characteristics such as software updates, patch installations, and security software status to identify devices that are becoming vulnerable to malware infection.
Data Source
AI summary
In one example, a network device may store health status information specifying a current security status for each of a plurality of authenticated endpoint devices in accordance with an authorization data model. The network device may update the current security status of each of at least two of the plurality of authenticated endpoint devices connected to an enterprise network to indicate that each of the at least two of the plurality of authenticated endpoint devices has a compromised security status, and identify a characteristic common to both of the authenticated endpoint devices having the compromised security status. The network device may interface with one or more policy enforcement devices to quarantine a set of endpoint devices associated with the identified characteristic. The current security status of at least one of the quarantined endpoint devices may indicate that the quarantined endpoint device does not have a compromised security status.


