Inline Security Dongle with Air Gap for Network Threat Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions face challenges in effectively detecting and mitigating cyber threats due to limitations in processing power and bandwidth, with onboard analytics being unaware of new threats and cloud-based solutions experiencing lag times and high bandwidth requirements.
Innovation Solution
A computer-implemented method and system that employs a security device connected inline between network hardware and computer systems, utilizing both onboard analytics and cloud-based analytics to assess threat levels, with onboard analytics performing initial threat detection and cloud-based analytics providing further analysis for ambiguous threats, and a physical or logical gate to control network traffic flow, creating an air gap when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If cloud-based analytics are used for threat detection, then measurement precision is improved, but loss of time increases due to lag times
Solution Approach 1:
The system segments threat detection into two parts: onboard analytics for immediate assessment and cloud-based analytics for detailed analysis. This segmentation allows the system to achieve both fast initial response and accurate comprehensive analysis by dividing the detection process between local and remote components.
Solution Approach 2:
The onboard analytics perform preliminary threat assessment before involving cloud-based analytics. This preliminary action filters out obvious threats locally, reducing the time-critical response delay while still allowing comprehensive cloud analysis for ambiguous cases.
2Measurement precision
If cloud-based analytics are used for threat detection, then measurement precision is improved, but loss of substance increases due to high bandwidth requirements
Solution Approach 1:
The system extracts and processes obvious threat patterns locally using onboard analytics, removing the need to transmit all network traffic data to the cloud. Only ambiguous or uncertain threats are extracted for further cloud-based analysis, significantly reducing bandwidth consumption while maintaining detection accuracy.
Solution Approach 2:
Instead of analyzing all traffic in the cloud, the system applies partial analysis locally and only sends a subset of ambiguous cases to cloud-based analytics. This partial action approach reduces bandwidth usage while maintaining sufficient detection precision for the majority of threats.
3Loss of time
If onboard analytics are used for threat detection, then loss of time is reduced, but measurement precision deteriorates due to limited processing power
Solution Approach 1:
The onboard analytics act as an intermediary between network traffic and cloud-based analytics. They perform initial filtering and assessment, providing a preliminary judgment that guides whether further cloud analysis is needed. This intermediary role enables fast initial response while maintaining accurate final detection through selective cloud involvement.
4Productivity
If a gate is opened to allow network traffic, then productivity is improved, but object-affected harmful factors increase due to security threats
Solution Approach 1:
The system continuously monitors network traffic and dynamically adjusts gate status based on real-time threat assessment feedback. When threats are detected, the gate is automatically closed or restricted; when traffic is safe, the gate remains open. This feedback mechanism maintains productivity while protecting against threats.
Solution Approach 2:
The gate is not static but dynamically adjusted based on threat levels. The system transitions between open, closed, and restricted states depending on real-time security conditions. This dynamic approach allows maximum productivity during safe periods while providing immediate protection when threats emerge.
Data Source
AI summary
Systems, methods, and computer program products providing network security leveraging analytics and physical separation between computer systems and a network to prevent threats from infecting network devices. A specialized pluggable dongle like security device is inserted between ports of computer system(s) connecting to the network and port(s) of network hardware facilitating connections between the computer system and computer network. The security device uses a combination of onboard analytics and cloud-based analytic services to detect incoming threats from network traffic and whether to allow network traffic to pass through the security device and/or prevent network traffic from entering the computer system. In response to detected network threats, an out of band management network communicating with the security device can open or close a physical gate onboard the security device, which, when opened introduces an air gap between the network and computer system, preventing harmful network traffic from entering the computer system.


