Adaptive Network Security Modules for Secure Communication Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures, such as firewalls and anti-virus software, are inadequate in preventing the spread of unknown computer exploits and do not adapt to specific device needs, leading to restricted network activities that can disrupt business operations and expose networks to infection risks.
Innovation Solution
A system and method that employs network security modules interposed between communication networks and devices, which can receive a relaxed set of security measures from a federated security service to enable specific network devices to resume secure network activities while maintaining protection from vulnerabilities, allowing for controlled communication within a VLAN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security modules implement strict security measures to block all network activities, then network protection from computer exploits is improved, but network device functionality and business operations deteriorate
Solution Approach 1:
The patent applies local quality by providing different security measure sets to different network security modules based on their specific needs and security assessments. Instead of uniformly blocking all network activities across the entire network, the system evaluates each network device's security status and applies tailored security measures - allowing some devices to maintain full functionality while others receive restricted access, thus resolving the contradiction between network protection and device functionality.
Solution Approach 2:
The system implements dynamics by making security measures adaptive and changeable over time. Network security modules can transition between different security measure sets based on security assessments, threat levels, and device behavior. This dynamic approach allows the system to tighten security when threats are detected while maintaining normal operations during safe periods, balancing protection and functionality.
2Object-affected harmful factors
If network security modules block all network activities to prevent infection spread, then network security against unknown exploits is improved, but network device operations and business continuity deteriorate
Solution Approach 1:
The patent applies segmentation by dividing the network into isolated segments or virtual LANs when infections are detected. Instead of blocking all network activities across the entire network, the system quarantines only the affected devices or segments, allowing the rest of the network to continue operating normally. This segmented approach minimizes business disruption while maintaining security by preventing infection spread to other parts of the network.
Solution Approach 2:
The system introduces an intermediary security service that mediates between security concerns and operational needs. This intermediary evaluates security threats and determines appropriate security measure sets, allowing the system to maintain business operations while implementing necessary security restrictions. The intermediary acts as a bridge that balances infection prevention with business continuity.
3Reliability
If traditional firewalls and anti-virus software are used to protect against computer exploits, then known exploit protection is improved, but adaptability to unknown exploits and device-specific needs deteriorates
Solution Approach 1:
The patent applies dynamics by making the security system adaptive and flexible rather than static. Network security modules can dynamically adjust their security measures based on real-time security assessments, threat intelligence, and device behavior. The system can transition between different security measure sets, allowing it to adapt to unknown exploits and device-specific requirements while maintaining protection against known threats.
Solution Approach 2:
The system implements parameter changes by modifying security measure parameters based on device needs and threat levels. Different network security modules can receive different security configurations, allowing the system to adapt to various device types, security requirements, and threat scenarios. This parameter-based approach enables both traditional protection and adaptability to new threats.
Data Source
AI summary
A system and method for enabling a network device to resume network activities in a secure manner on a communication network when network activities are generally blocked by protective security measures implemented by network security modules is presented. During its periodic update request, a network security module blocking the network activities of the network device requests updated security measures from an administrator-configurable security service. The security service determines whether the network security module/network device may receive a relaxed set of security measures that, when implemented by the network security module, enable the network device to resume some network activities. If the security service determines that the network security module/network device may receive a relaxed set of security measures, the relaxed set of security measures are returned to and implemented on the network security module, thereby enabling the network device to resume some network activities.


