Intra-LAN Network Device Isolation via ARP Spoofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions fail to protect devices within a Local Area Network (LAN) from malicious activity originating from other devices on the same network, such as infected systems that can spread malware or steal data.

Innovation Solution

A network security device uses Internet Protocol spoofing, specifically Address Resolution Protocol (ARP) spoofing, to insert itself between suspected infected or untrusted devices and other local network devices, selectively blocking traffic to isolate the suspicious device and intercept network traffic for screening and filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall is used to restrict communication between internal and external networks, then external network security is improved, but devices within the LAN remain vulnerable to each other

Engineering Contradiction:
Improveexternal network securityVSAvoidinternal network threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the LAN into isolated segments using virtual switching techniques. Each device is placed in its own virtual switch instance, creating logical segmentation that prevents direct communication between devices while allowing controlled access to external networks through the firewall.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a intermediary virtual switch between LAN devices that acts as a mediator. This virtual switch intercepts and inspects all communication between devices, allowing the firewall to control internal traffic just as it controls external traffic, thereby extending security protection to intra-LAN communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ARP spoofing is used to intercept external network traffic for security screening, then external traffic filtering is improved, but the solution does not protect against internal device threats

Engineering Contradiction:
Improveexternal traffic filteringVSAvoidinternal threat protection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends the ARP spoofing capability to serve multiple functions: it not only intercepts external traffic for security screening but also intercepts internal traffic between LAN devices. The same virtual switching mechanism handles both external and internal traffic inspection, making the security system universal against both external and internal threats.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If all LAN devices are allowed to communicate freely, then network functionality and ease of operation are improved, but security risks from infected devices increase

Engineering Contradiction:
Improvenetwork communication freedomVSAvoidmalware spread risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The virtual switch acts as an intermediary that maintains the appearance of free communication while actually controlling all traffic flows. Devices can operate without configuration changes, but the virtual switch inspects and controls traffic between them, blocking malicious communications while allowing legitimate ones, thus maintaining ease of operation while reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20220231990A1Intra-LAN network device isolation
Publication Date: 2022.07.21 GEN DIGITAL INC
  • US20220231990A1 patent drawing
  • US20220231990A1 patent drawing
  • US20220231990A1 patent drawing

AI summary

A private network device such as a security device is inserted in a local network and is operable to isolate networked devices on the local network. The networked security device uses Internet Protocol spoofing to intercept network traffic between at least two networked devices on the same local network as the networked security device, and selectively blocks intercepted network traffic between the at least two networked devices on the local network.