Intranet Security via Customer Edge Router Access Control Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Virtual Private Network (VPN) security measures are inadequate in preventing malicious activities originating from within the intranet network, as they primarily focus on protecting against external threats, leaving internal servers and devices vulnerable to attacks and unauthorized access.
Innovation Solution
Implementing inbound and outbound access control lists at Customer Edge Routers to identify and protect specific servers within the intranet network, blocking unsolicited sessions and preventing compromised servers from accessing external networks, while allowing legitimate return traffic and monitoring for potential Denial of Service attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If security measures are implemented at gateways to protect against external threats, then protection against external attacks is improved, but vulnerability to internal threats remains
Solution Approach 1:
The patent segments the intranet network into multiple Virtual Private Networks (VPNs) with different security levels and access policies. By dividing the network into separate segments, internal threats are contained within specific VPNs and cannot propagate across the entire network. This segmentation allows security measures to be applied differently to external and internal threats, resolving the contradiction between external protection and internal security.
2Reliability
If access control is applied to all packets, then security against malicious activities is improved, but network performance deteriorates
Solution Approach 1:
The patent applies access control selectively rather than universally. Inbound access control lists are applied only to packets destined for servers in protected server groups, and outbound access control lists are applied only to packets from these protected servers. This partial application of security measures provides adequate protection against malicious activities while minimizing the performance overhead that would result from inspecting every packet in the network.
3Reliability
If multiple access control lists are applied to packets, then protection against unauthorized access is improved, but device complexity increases
Solution Approach 1:
The patent creates protected server groups that serve multiple security functions simultaneously. A single protected server group definition enables both inbound access control (filtering packets destined for the group) and outbound access control (filtering packets from the group). This multi-functionality approach provides comprehensive protection against unauthorized access while reducing device complexity compared to configuring separate access control lists for each direction and server.
Data Source
AI summary
A method and an apparatus for providing security in an intranet network are disclosed. For example, the method receives a packet at a customer edge router, and applies an inbound access control list by the customer edge router to the packet if the packet is destined to a server in a protected server group, wherein said protected server group identifies one or more servers within the intranet network to be protected. The method applies an outbound access control list by the customer edge router to the packet if the packet is from a server in the protected server group.


