Distributed Firewall Gateway Host-Based Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network gateway security systems are limited in controlling malicious behavior on mobile devices, as they only provide network-based protection, while host-based systems consume significant resources and are inefficient in detecting coordinated threats across multiple devices.
Innovation Solution
A distributed firewall system that monitors network traffic between a network gateway and clients, activates host-based protection measures when threat levels exceed a predetermined range, combining network-based and host-based security measures to obstruct undesired behavior and gather additional information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If host-based security systems are implemented on network clients, then security protection effectiveness is improved, but device resource consumption (memory, computing time, power) increases significantly
Solution Approach 1:
The security system is divided into two segments: a lightweight network-based monitoring component at the gateway and a host-based protection component on the client device. The network gateway performs initial traffic analysis and threat level assessment, while host-based measures are only activated when threats are detected, segmenting the security functions to optimize resource usage.
Solution Approach 2:
The security system dynamically adjusts its operation mode based on threat levels. The network gateway continuously monitors traffic and adjusts the client threat-level metric in real-time. Host-based protection measures are dynamically activated or deactivated based on whether the threat-level exceeds predetermined thresholds, allowing the system to adapt resource consumption to actual security needs.
2Reliability
If host-based security systems are implemented on network clients, then security protection effectiveness is improved, but battery life on mobile devices decreases
Solution Approach 1:
Instead of continuous host-based monitoring, the system uses periodic network-based monitoring at the gateway and only activates host-based measures periodically when threat levels indicate a need. This periodic activation pattern reduces continuous power consumption while maintaining security effectiveness.
Solution Approach 2:
The network gateway autonomously monitors network traffic and independently determines when host-based protection should be activated based on detected traffic patterns and calculated threat levels. This self-service approach eliminates the need for continuous client-side resource consumption while maintaining security.
3Use of energy by moving object
If network gateway security systems are used, then resource consumption on client devices is reduced, but control over malicious behavior on client devices is limited
Solution Approach 1:
The network gateway acts as an intermediary that bridges network-based monitoring and host-based protection. It analyzes network traffic, calculates threat levels, and mediates between the network environment and the client device by transmitting action commands to activate host-based measures when needed, combining the advantages of both approaches.
Solution Approach 2:
The system implements a feedback loop where the network gateway continuously monitors network traffic, calculates client threat-levels based on detected patterns, and transmits action commands back to client devices when threats are detected. This feedback mechanism ensures continuous control and adaptation without requiring constant client-side resource consumption.
4Reliability
If host-based security systems are implemented, then detection of local threats is improved, but coordinated threat detection across multiple devices is not achieved
Solution Approach 1:
The system merges network-based monitoring at the gateway with host-based protection on individual devices. The gateway aggregates traffic data from multiple clients, calculates threat levels, and coordinates activation of host-based measures across devices, achieving both local detection capability and coordinated multi-device threat response.
Data Source
AI summary
A method and system comprising a network gateway for monitoring a network traffic between a network client and the network gateway, and at least one network client connected to said network gateway and comprising means for applying host-based protection measures are provided, wherein the network gateway evaluates the monitored traffic for indications of undesired behaviour and has control of the means for applying host-based protection measures of the at least one network client. Optionally network-based protection measures activated at the network gateway may be combined with the host-based protection measures and/or suspicious device events observed at the network client may be accounted for when assessing suitable protection measures in addition to the traffic monitored at the network gateway.


