Network Protection Device ARP Table Modulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network protection methods fail to effectively prevent the spread of malicious codes within internal networks and between networks, leading to increased damage and risk of data theft.

Innovation Solution

A network protection device that modulates ARP tables using ARP packets to control communication flows, blocks unauthorized terminals, and employs a CAPTCHA process to authenticate legitimate communication, while referencing white and black lists to manage access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network protection methods are used, then network connectivity is maintained, but malicious codes can spread between terminals

Engineering Contradiction:
Improvenetwork securityVSAvoidmalicious code spread
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network protection device acts as an intermediary by injecting itself into the ARP tables of terminal devices. When terminal devices need to communicate, their ARP tables redirect traffic through the protection device's MAC address, enabling the device to monitor and control all network communications without disrupting connectivity. This intermediary position allows the system to maintain network functionality while blocking malicious code propagation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-establishing white lists of authorized terminals and black lists of malicious sources before attacks occur. The network protection device proactively modulates ARP tables to route traffic through itself, enabling real-time inspection and filtering of communications. This preliminary configuration ensures that when malicious codes attempt to spread, the infrastructure is already in place to prevent propagation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If communication flows are blocked to prevent malicious code spread, then security is improved, but legitimate communication is disrupted

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication flow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network protection device applies different quality controls to different communication flows based on local characteristics. White list terminals receive permissive treatment with direct communication paths, while black list terminals undergo strict filtering and blocking. This localized quality differentiation ensures that legitimate communications experience minimal disruption while malicious flows are effectively blocked, resolving the contradiction between security and operational ease.

Inventive Principle:
Principle #3Local quality

3Reliability

If ARP table modulation is used to control communication flows, then malicious code spread is prevented, but network complexity increases

Engineering Contradiction:
Improvemalicious code preventionVSAvoidnetwork protection mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network protection device employs self-service mechanisms by automatically modulating ARP tables of terminal devices without requiring manual configuration. The device autonomously injects its MAC address into terminal ARP tables, dynamically updates white and black lists based on detected threats, and automatically adjusts communication routing. This self-service capability reduces operational complexity while maintaining effective malicious code prevention through automated ARP table management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250030693A1Device and method for protecting network
Publication Date: 2025.01.23 VIASCOPE INC
  • US20250030693A1 patent drawing
  • US20250030693A1 patent drawing
  • US20250030693A1 patent drawing

AI summary

According to the present disclosure, a network protection device includes: a communication device; a storage device configured to store a white list that defines access rights between a plurality of first terminals belonging to a target network; and a control device configured to modulate an address resolution protocol (ARP) table of each of the plurality of first terminals using an ARP packet so that a first communication flow generated between the plurality of first terminals is received by the communication device, and block the first communication flow or transmit the first communication flow to a destination based on the white list when the first communication flow is received.