Inline Security Dongle with Air Gap for Network Threat Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions face challenges in effectively detecting and mitigating cyber threats due to limitations in processing power and bandwidth, with onboard analytics being unaware of new threats and cloud-based solutions experiencing lag times and high bandwidth requirements.

Innovation Solution

A computer-implemented method and system that employs a security device connected inline between network hardware and computer systems, utilizing both onboard analytics and cloud-based analytics to assess threat levels, with onboard analytics performing initial threat detection and cloud-based analytics providing further analysis for ambiguous threats, and a physical or logical gate to control network traffic flow, creating an air gap when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If cloud-based analytics are used for threat detection, then measurement precision is improved, but loss of time increases due to lag times

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system segments threat detection into two parts: onboard analytics for immediate assessment and cloud-based analytics for detailed analysis. This segmentation allows the system to achieve both fast initial response and accurate comprehensive analysis by dividing the detection process between local and remote components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The onboard analytics perform preliminary threat assessment before involving cloud-based analytics. This preliminary action filters out obvious threats locally, reducing the time-critical response delay while still allowing comprehensive cloud analysis for ambiguous cases.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If cloud-based analytics are used for threat detection, then measurement precision is improved, but loss of substance increases due to high bandwidth requirements

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidbandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of substance

Solution Approach 1:

The system extracts and processes obvious threat patterns locally using onboard analytics, removing the need to transmit all network traffic data to the cloud. Only ambiguous or uncertain threats are extracted for further cloud-based analysis, significantly reducing bandwidth consumption while maintaining detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of analyzing all traffic in the cloud, the system applies partial analysis locally and only sends a subset of ambiguous cases to cloud-based analytics. This partial action approach reduces bandwidth usage while maintaining sufficient detection precision for the majority of threats.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of time

If onboard analytics are used for threat detection, then loss of time is reduced, but measurement precision deteriorates due to limited processing power

Engineering Contradiction:
Improveresponse timeVSAvoidthreat detection accuracy
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The onboard analytics act as an intermediary between network traffic and cloud-based analytics. They perform initial filtering and assessment, providing a preliminary judgment that guides whether further cloud analysis is needed. This intermediary role enables fast initial response while maintaining accurate final detection through selective cloud involvement.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If a gate is opened to allow network traffic, then productivity is improved, but object-affected harmful factors increase due to security threats

Engineering Contradiction:
Improvenetwork traffic flowVSAvoidsecurity threats
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors network traffic and dynamically adjusts gate status based on real-time threat assessment feedback. When threats are detected, the gate is automatically closed or restricted; when traffic is safe, the gate remains open. This feedback mechanism maintains productivity while protecting against threats.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The gate is not static but dynamically adjusted based on threat levels. The system transitions between open, closed, and restricted states depending on real-time security conditions. This dynamic approach allows maximum productivity during safe periods while providing immediate protection when threats emerge.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11310206B2In-line cognitive network security plugin device
Publication Date: 2022.04.19 KYNDRYL INC
  • US11310206B2 patent drawing
  • US11310206B2 patent drawing
  • US11310206B2 patent drawing

AI summary

Systems, methods, and computer program products providing network security leveraging analytics and physical separation between computer systems and a network to prevent threats from infecting network devices. A specialized pluggable dongle like security device is inserted between ports of computer system(s) connecting to the network and port(s) of network hardware facilitating connections between the computer system and computer network. The security device uses a combination of onboard analytics and cloud-based analytic services to detect incoming threats from network traffic and whether to allow network traffic to pass through the security device and/or prevent network traffic from entering the computer system. In response to detected network threats, an out of band management network communicating with the security device can open or close a physical gate onboard the security device, which, when opened introduces an air gap between the network and computer system, preventing harmful network traffic from entering the computer system.