Untyped Network Traffic Management via Endpoint Application Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint security techniques are inadequate for effectively managing network flows and controlling interprocess communications, particularly in enterprise networks, where malicious actors target valuable information.

Innovation Solution

Implementing a method to determine application types for network messages by querying endpoints, applying security policies based on application types, and using kernel-based endpoint protection drivers to secure interprocess communications and manage network traffic flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing endpoint security techniques are used to manage network flows, then basic network security is maintained, but the ability to effectively control interprocess communications and identify application types is insufficient

Engineering Contradiction:
Improveendpoint securityVSAvoidapplication type identification
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary component (endpoint security agent or kernel driver) that acts as a mediator between the network traffic and the security management system. This intermediary captures network messages, extracts identifying information, and queries the endpoint to determine application types, thereby enabling effective network flow management without requiring changes to existing endpoint security infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/network-layer traffic management with application-layer intelligence by using kernel-based endpoint protection drivers and security agents that can identify and classify traffic based on application type, providing more granular and effective security control

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If network traffic flows are monitored and managed at the network device, then network security is improved, but the precision of identifying unknown application types decreases without endpoint querying

Engineering Contradiction:
Improveapplication type determinationVSAvoidendpoint querying mechanism
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having endpoints continuously report their running processes and applications to the network device before network traffic analysis is needed. This pre-collection of endpoint state information enables the network device to accurately identify application types when analyzing network messages without requiring complex real-time endpoint querying

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The endpoint security agent performs self-service by autonomously monitoring local processes, extracting identifying information from network messages, and reporting this information to the network device. This self-service mechanism reduces the complexity of centralized endpoint querying while maintaining high measurement precision for application type determination

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If security policies are applied based on application types, then network security control is enhanced, but the complexity of implementing application-type-based management increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidapplication-type-based policy management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal security policy framework where a single policy structure can handle multiple application types and security requirements. The network device applies security policies based on determined application types using a unified mechanism that works across different applications and traffic patterns, reducing the complexity of implementing separate management systems for different security scenarios

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250252181A1Managing untyped network traffic flows
Publication Date: 2025.08.07 SOPHOS LTD
  • US20250252181A1 patent drawing
  • US20250252181A1 patent drawing
  • US20250252181A1 patent drawing

AI summary

An enterprise security system is improved by managing network flows based on an application type. When a network message having an unknown application type is received at a gateway, firewall, or other network device/service from an endpoint, the endpoint that originated the network message may be queried for identifying information for the source of the network message and the application type may be determined, or the endpoint may periodically communicate application type information to the network device in a heartbeat or other periodic communication or the like. The network message may be managed along with other network traffic according to the application type.