ARP Control for Ransomware Prevention in VLANs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional enterprise security solutions are inadequate in preventing lateral movement of ransomware within shared VLAN environments, as firewalls cannot inspect east-west communication within VLANs, leading to propagation of malware and compromised devices, and endpoint protection solutions face challenges in managing agents on IoT devices and older operating systems.

Innovation Solution

A security appliance is set as the default gateway for intra-LAN communication, configured to drop ARP response packets from all but the port connected to the appliance, forcing all traffic to traverse the appliance and allowing only authorized communication, with features like proxy ARP responses and traffic monitoring to detect and prevent ransomware propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a shared VLAN architecture is used to enable east-west communication between endpoints, then network connectivity and communication efficiency are improved, but lateral propagation of ransomware within the VLAN is enabled

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidlateral propagation of ransomware
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security appliance as an intermediary device that all ARP traffic must pass through. The appliance intercepts ARP requests and responses, inspects them for malicious activity, and controls the mapping between IP addresses and MAC addresses. This mediator approach maintains the shared VLAN architecture for efficient communication while blocking ransomware propagation by preventing infected endpoints from establishing unauthorized connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewalls are deployed to protect against external attacks, then perimeter security is improved, but east-west communication within VLANs cannot be inspected

Engineering Contradiction:
Improveperimeter securityVSAvoidinspection of intra-VLAN communication
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent shifts the security inspection from the traditional north-south dimension (external to internal traffic through firewalls) to the east-west dimension (internal lateral traffic within VLANs). By deploying the security appliance within the VLAN to inspect ARP traffic between endpoints, the solution addresses the blind spot in firewall architecture without compromising perimeter security. This dimensional shift enables detection of lateral ransomware movement that firewalls cannot see.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If endpoint protection agents are deployed to detect ransomware, then detection capability is improved, but deployment complexity increases and IoT devices cannot be protected

Engineering Contradiction:
Improveransomware detection capabilityVSAvoidagent management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a network-layer solution where the security appliance performs automatic detection and blocking of ransomware traffic without requiring agents on individual endpoints. The appliance monitors ARP traffic patterns, identifies malicious communication behaviors, and blocks infected devices at the network level. This self-service approach eliminates the need for complex agent deployment and management across diverse devices including IoT systems that cannot run traditional security software.

Inventive Principle:
Principle #25Self-service

4Extent of automation

If ARP broadcast is allowed for automatic endpoint discovery, then network automation is improved, but ransomware can exploit ARP for lateral propagation

Engineering Contradiction:
Improveautomatic endpoint discoveryVSAvoidARP exploitation by ransomware
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The security appliance acts as an intermediary that captures and inspects all ARP broadcast traffic before it reaches endpoints. It validates ARP requests and responses, blocks spoofed ARP packets from ransomware-infected devices, and maintains accurate ARP tables. This intermediary approach preserves the automation benefits of ARP-based endpoint discovery while neutralizing the security risk by filtering malicious ARP traffic at the network level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11979431B1System and method for prevention of lateral propagation of ransomware using ARP control on network switches to create point-to-point links between endpoints
Publication Date: 2024.05.07 ZSCALER INC
  • US11979431B1 patent drawing
  • US11979431B1 patent drawing
  • US11979431B1 patent drawing

AI summary

A technique to improve security for a VLAN is disclosed. A security appliance is set as the gateway for intra-LAN communication. Message traffic is analyzed and anomalies are detected relative to normal message traffic that correspond to device health problems that may require service by a field technician. A network switch may be configured to drop certain types of Address Resolution Protocol messages from selected ports to aid in setting a security appliance as the gateway.