Dynamic Firewall Isolation via Virtual Service Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures in computer networks are inadequate for quickly identifying and isolating security threats, as they often require manual intervention and may allow viruses to spread before detection and mitigation can occur.

Innovation Solution

The creation of a Virtual Service Network (VSN) that dynamically isolates communication devices suspected of posing a security risk, accompanied by the instantiation of a firewall to block data transfer and the use of a forensic gateway to monitor and analyze security events, enabling automatic corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security measures (anti-virus software) are used to detect and clean viruses on individual computers, then security can be maintained on that device, but the response time is slow and the virus may spread to other devices before detection

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the network into isolated virtual groups when security threats are detected. Instead of treating the entire network as one unit, affected devices are separated into distinct segments, allowing targeted security responses without impacting the whole network. This enables faster containment of threats while maintaining security across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by proactively monitoring network traffic and device behavior to detect security threats before they can spread widely. Security events are detected and responded to automatically in advance, preventing viral propagation before it occurs, rather than waiting for manual detection and response.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional firewalls are used to detect unwanted port usage, then some security protection is provided, but the system lacks the ability to quickly identify security issues and automatically isolate affected devices

Engineering Contradiction:
Improvesecurity protectionVSAvoidspeed of identification and isolation
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security system performs self-service by automatically detecting security events, identifying affected devices, and isolating them without requiring administrator intervention. The system monitors its own network environment, makes autonomous decisions about which devices to quarantine, and executes isolation actions automatically, thereby speeding up the response process while maintaining security protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where security events are monitored, analyzed, and responded to in real-time. The automatic isolation mechanism provides immediate feedback when security threats are detected, and the system continuously adjusts its security posture based on ongoing monitoring of network traffic and device behavior, enabling rapid identification and isolation of affected devices.

Inventive Principle:
Principle #23Feedback

3Reliability

If the entire network is isolated to prevent virus spread, then security is maintained, but normal network operations are disrupted and productivity is reduced

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidnetwork operations continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies segmentation by creating isolated virtual groups only for affected devices rather than isolating the entire network. This allows the network to be divided into secure segments, where only compromised devices are quarantined while the rest of the network continues to operate normally, thereby maintaining both security and productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by implementing security measures only where needed - specifically on affected devices and their immediate network segments - rather than applying blanket isolation across the entire network. This localized approach maintains security at the point of threat while preserving normal operations in unaffected areas of the network.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10848465B2Dynamic firewalls and forensic gateways
Publication Date: 2020.11.24 EXTREME NETWORKS INC
  • US10848465B2 patent drawing
  • US10848465B2 patent drawing
  • US10848465B2 patent drawing

AI summary

A security event that is associated with one or more communication devices is detected. For example, the security event may be an unexpected change in data being sent from a communication device outside an enterprise. In response to detecting the security event, a Virtual Service Network (VSN) is created that isolates one or more communication devices that may pose a security risk. A corrective action to mitigate the security event is then implemented. For example, the corrective action may be to dynamically instantiate a firewall on the VSN that blocks the transfer of data from the communication device outside the enterprise. This allows an administrator to review the security event and take further action if necessary. Because the VSN with the firewall is created dynamically, the network remains secure while the security event is investigated.