ARP Control for Ransomware Prevention in VLANs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional enterprise security solutions are inadequate in preventing lateral movement of ransomware within shared VLAN environments, as firewalls cannot inspect east-west communication within VLANs, leading to propagation of malware and compromised devices, and endpoint protection solutions face challenges in managing agents on IoT devices and older operating systems.
Innovation Solution
A security appliance is set as the default gateway for intra-LAN communication, configured to drop ARP response packets from all but the port connected to the appliance, forcing all traffic to traverse the appliance and allowing only authorized communication, with features like proxy ARP responses and traffic monitoring to detect and prevent ransomware propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a shared VLAN architecture is used to enable east-west communication between endpoints, then network connectivity and communication efficiency are improved, but lateral propagation of ransomware within the VLAN is enabled
Solution Approach 1:
The patent introduces a security appliance as an intermediary device that all ARP traffic must pass through. The appliance intercepts ARP requests and responses, inspects them for malicious activity, and controls the mapping between IP addresses and MAC addresses. This mediator approach maintains the shared VLAN architecture for efficient communication while blocking ransomware propagation by preventing infected endpoints from establishing unauthorized connections.
2Reliability
If firewalls are deployed to protect against external attacks, then perimeter security is improved, but east-west communication within VLANs cannot be inspected
Solution Approach 1:
The patent shifts the security inspection from the traditional north-south dimension (external to internal traffic through firewalls) to the east-west dimension (internal lateral traffic within VLANs). By deploying the security appliance within the VLAN to inspect ARP traffic between endpoints, the solution addresses the blind spot in firewall architecture without compromising perimeter security. This dimensional shift enables detection of lateral ransomware movement that firewalls cannot see.
3Measurement precision
If endpoint protection agents are deployed to detect ransomware, then detection capability is improved, but deployment complexity increases and IoT devices cannot be protected
Solution Approach 1:
The patent implements a network-layer solution where the security appliance performs automatic detection and blocking of ransomware traffic without requiring agents on individual endpoints. The appliance monitors ARP traffic patterns, identifies malicious communication behaviors, and blocks infected devices at the network level. This self-service approach eliminates the need for complex agent deployment and management across diverse devices including IoT systems that cannot run traditional security software.
4Extent of automation
If ARP broadcast is allowed for automatic endpoint discovery, then network automation is improved, but ransomware can exploit ARP for lateral propagation
Solution Approach 1:
The security appliance acts as an intermediary that captures and inspects all ARP broadcast traffic before it reaches endpoints. It validates ARP requests and responses, blocks spoofed ARP packets from ransomware-infected devices, and maintains accurate ARP tables. This intermediary approach preserves the automation benefits of ARP-based endpoint discovery while neutralizing the security risk by filtering malicious ARP traffic at the network level.
Data Source
AI summary
A technique to improve security for a VLAN is disclosed. A security appliance is set as the gateway for intra-LAN communication. Message traffic is analyzed and anomalies are detected relative to normal message traffic that correspond to device health problems that may require service by a field technician. A network switch may be configured to drop certain types of Address Resolution Protocol messages from selected ports to aid in setting a security appliance as the gateway.


