Dual-Mode Network Blocking for Unauthorized Device Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security systems lack flexibility in blocking network access from external devices, leading to inefficient data packet loss and potential network attacks, as they cannot adapt blocking operations to diverse types of information devices.
Innovation Solution
A dual-modes switching method that collects and analyzes data packets to identify network nodes, determines their type, and switches between two blocking modes to effectively block network connections from external devices, using MAC addresses, OUI data, ARP firewall data, and static ARP data to prevent unauthorized access without triggering ARP firewalls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a data security system completely blocks data access from external information devices to the company's internal network, then security protection is improved, but the system lacks flexibility to adapt to different types of information devices and causes enormous information packets to be lost
Solution Approach 1:
The patent implements dynamic adaptability by automatically identifying different types of external information devices and switching between two blocking modes based on device characteristics. The system transitions from a static complete blocking approach to a dynamic selective blocking approach, improving adaptability while maintaining security.
Solution Approach 2:
The patent applies different blocking strategies to different types of external devices. Instead of uniform complete blocking, the system identifies specific device types and applies appropriate blocking modes locally, allowing legitimate devices to communicate while blocking unauthorized access, thus resolving the contradiction between security and adaptability.
2Reliability
If a data security system completely blocks data access from external information devices, then security is improved, but the blocking operation efficiency deteriorates causing enormous information packets to be lost
Solution Approach 1:
The system dynamically adjusts blocking operations based on real-time device identification. By switching between first blocking mode (for devices requiring complete blocking) and second blocking mode (for devices allowing selective communication), the system improves blocking efficiency while maintaining security, preventing unnecessary packet loss.
3Device complexity
If the system applies a single complete blocking mode to all external devices, then security protection is simplified, but the system cannot achieve complete blocking effectiveness due to diverse device types
Solution Approach 1:
The patent implements automatic switching between two blocking modes based on device type identification. This dynamic approach maintains operational simplicity through automation while achieving effective blocking across diverse device types, resolving the contradiction between simplicity and effectiveness.
Data Source
AI summary
The invention discloses a dual-modes switching method for blocking a network connection, comprising: a data packet collecting step of collecting data packets transmitting from all network nodes in a network segment, a data packet analyzing step of analyzing the data packets collected to obtain network node identification data, a list comparing step of comparing the network node identification data with identification data registered in an information device list to determine an illegal network node, an illegal-network-node-type determining step of determining what kind of type the illegal network node is, and a network connection blocking step of switching a first network connection blocking mode and a second network connection blocking mode according to the type of the illegal network node, thereby blocking the network connection of the illegal network.


