Adaptive Network Security Modules for Secure Communication Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures, such as firewalls and anti-virus software, are inadequate in preventing the spread of unknown computer exploits and do not adapt to specific device needs, leading to restricted network activities that can disrupt business operations and expose networks to infection risks.

Innovation Solution

A system and method that employs network security modules interposed between communication networks and devices, which can receive a relaxed set of security measures from a federated security service to enable specific network devices to resume secure network activities while maintaining protection from vulnerabilities, allowing for controlled communication within a VLAN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security modules implement strict security measures to block all network activities, then network protection from computer exploits is improved, but network device functionality and business operations deteriorate

Engineering Contradiction:
Improvenetwork protectionVSAvoidnetwork device functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by providing different security measure sets to different network security modules based on their specific needs and security assessments. Instead of uniformly blocking all network activities across the entire network, the system evaluates each network device's security status and applies tailored security measures - allowing some devices to maintain full functionality while others receive restricted access, thus resolving the contradiction between network protection and device functionality.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements dynamics by making security measures adaptive and changeable over time. Network security modules can transition between different security measure sets based on security assessments, threat levels, and device behavior. This dynamic approach allows the system to tighten security when threats are detected while maintaining normal operations during safe periods, balancing protection and functionality.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If network security modules block all network activities to prevent infection spread, then network security against unknown exploits is improved, but network device operations and business continuity deteriorate

Engineering Contradiction:
Improveinfection riskVSAvoidbusiness operation disruption
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent applies segmentation by dividing the network into isolated segments or virtual LANs when infections are detected. Instead of blocking all network activities across the entire network, the system quarantines only the affected devices or segments, allowing the rest of the network to continue operating normally. This segmented approach minimizes business disruption while maintaining security by preventing infection spread to other parts of the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary security service that mediates between security concerns and operational needs. This intermediary evaluates security threats and determines appropriate security measure sets, allowing the system to maintain business operations while implementing necessary security restrictions. The intermediary acts as a bridge that balances infection prevention with business continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional firewalls and anti-virus software are used to protect against computer exploits, then known exploit protection is improved, but adaptability to unknown exploits and device-specific needs deteriorates

Engineering Contradiction:
Improveknown exploit protectionVSAvoidresponse to unknown exploits
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the security system adaptive and flexible rather than static. Network security modules can dynamically adjust their security measures based on real-time security assessments, threat intelligence, and device behavior. The system can transition between different security measure sets, allowing it to adapt to unknown exploits and device-specific requirements while maintaining protection against known threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements parameter changes by modifying security measure parameters based on device needs and threat levels. Different network security modules can receive different security configurations, allowing the system to adapt to various device types, security requirements, and threat scenarios. This parameter-based approach enables both traditional protection and adaptability to new threats.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7353390B2Enabling network devices within a virtual network to communicate while the network's communications are restricted due to security threats
Publication Date: 2008.04.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7353390B2 patent drawing
  • US7353390B2 patent drawing
  • US7353390B2 patent drawing

AI summary

A system and method for enabling a network device to resume network activities in a secure manner on a communication network when network activities are generally blocked by protective security measures implemented by network security modules is presented. During its periodic update request, a network security module blocking the network activities of the network device requests updated security measures from an administrator-configurable security service. The security service determines whether the network security module/network device may receive a relaxed set of security measures that, when implemented by the network security module, enable the network device to resume some network activities. If the security service determines that the network security module/network device may receive a relaxed set of security measures, the relaxed set of security measures are returned to and implemented on the network security module, thereby enabling the network device to resume some network activities.