Intranet Security via Customer Edge Router Access Control Lists

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Virtual Private Network (VPN) security measures are inadequate in preventing malicious activities originating from within the intranet network, as they primarily focus on protecting against external threats, leaving internal servers and devices vulnerable to attacks and unauthorized access.

Innovation Solution

Implementing inbound and outbound access control lists at Customer Edge Routers to identify and protect specific servers within the intranet network, blocking unsolicited sessions and preventing compromised servers from accessing external networks, while allowing legitimate return traffic and monitoring for potential Denial of Service attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If security measures are implemented at gateways to protect against external threats, then protection against external attacks is improved, but vulnerability to internal threats remains

Engineering Contradiction:
Improveexternal attacksVSAvoidinternal security
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent segments the intranet network into multiple Virtual Private Networks (VPNs) with different security levels and access policies. By dividing the network into separate segments, internal threats are contained within specific VPNs and cannot propagate across the entire network. This segmentation allows security measures to be applied differently to external and internal threats, resolving the contradiction between external protection and internal security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control is applied to all packets, then security against malicious activities is improved, but network performance deteriorates

Engineering Contradiction:
Improvesecurity against malicious activitiesVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies access control selectively rather than universally. Inbound access control lists are applied only to packets destined for servers in protected server groups, and outbound access control lists are applied only to packets from these protected servers. This partial application of security measures provides adequate protection against malicious activities while minimizing the performance overhead that would result from inspecting every packet in the network.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multiple access control lists are applied to packets, then protection against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidrouter configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates protected server groups that serve multiple security functions simultaneously. A single protected server group definition enables both inbound access control (filtering packets destined for the group) and outbound access control (filtering packets from the group). This multi-functionality approach provides comprehensive protection against unauthorized access while reducing device complexity compared to configuring separate access control lists for each direction and server.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9049172B2Method and apparatus for providing security in an intranet network
Publication Date: 2015.06.02 AT&T INTELLECTUAL PROPERTY I L P
  • US9049172B2 patent drawing
  • US9049172B2 patent drawing
  • US9049172B2 patent drawing

AI summary

A method and an apparatus for providing security in an intranet network are disclosed. For example, the method receives a packet at a customer edge router, and applies an inbound access control list by the customer edge router to the packet if the packet is destined to a server in a protected server group, wherein said protected server group identifies one or more servers within the intranet network to be protected. The method applies an outbound access control list by the customer edge router to the packet if the packet is from a server in the protected server group.