Managing Unpatched User Devices via Virtual Machine Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users with outdated browsers or unpatched devices are susceptible to malware, posing a security risk for both themselves and financial institution networks when attempting to access their accounts.
Innovation Solution
A management system that checks the security status of user devices before granting access, offering updates or redirecting to a virtual machine to protect against malware, ensuring the device is up to date and secure before allowing network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users access networks without security checks, then ease of access is improved, but network security deteriorates
Solution Approach 1:
The system performs preliminary security checks of user devices before granting network access. The management system checks whether user devices are up to date with security patches and browser updates, and only allows access if the device passes the security check or if the user consents to the security risk
Solution Approach 2:
The management system acts as an intermediary between users and the network. It mediates by checking device security status, offering updates, and controlling access rights based on the security assessment results
2Reliability
If users are forced to update software, then network security is improved, but user convenience deteriorates
Solution Approach 1:
The system provides self-service update mechanisms where users can voluntarily update their browsers and software through the management system. Users are notified of security updates and can choose to install them without manual intervention from the system administrator
Solution Approach 2:
The access control policy is dynamic rather than static. The system adjusts access rights based on real-time security status of user devices, allowing flexible adaptation to different user situations and security levels
3Adaptability or versatility
If unpatched devices are allowed access, then user accessibility is improved, but malware transfer risk increases
Solution Approach 1:
The system takes preliminary anti-action by detecting unpatched devices and unsecured browsers before they can access the network. The management system identifies security vulnerabilities and prevents access or offers remediation measures to eliminate the harmful factors
Solution Approach 2:
The management system serves as a protective intermediary that sits between unsecured user devices and the network. It monitors device security status and controls access to prevent malware from transferring to the network while still allowing legitimate users to access services
Data Source
AI summary
The innovation disclosed and claimed herein, in one aspect thereof, comprises a management system and method of handling unpatched users. When a user requests to access their user account or a network, the user is checked for type of browser the user is being used and which version of the browser is being used. If the user is using an unsecured or unpatched browser, the system offers to update the browser software or provide a virtual machine through the browser so that malware cannot transfer from the user computer to the network. The virtual machine can provide a virtual keyboard to protect the user's login credentials from a key logger. The user logs into the user account within the virtual machine.


