Host-Based LAN Isolation via ARP and Route Poisoning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for isolating devices on a local area network are inadequate in preventing peer-to-peer communications, especially in IPv4 networks, which are vulnerable to malware spread and lateral movement due to the lack of effective tools to manage traffic within these networks, particularly with the increasing number of IoT devices.

Innovation Solution

A host-based solution that utilizes ARP poisoning, route poisoning, and firewall blocking to prevent communications at various OSI layers, integrating with AI and machine learning for automated responses, allowing for granular control of network traffic without relying on hardware firewalls or network architecture adaptations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware firewalls or network architecture adaptations are used for device isolation, then network security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvenetwork securityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces hardware-based firewalls and network architecture adaptations with software-based isolation mechanisms. Specifically, it uses host-based software agents that implement ARP poisoning, route poisoning, and firewall blocking techniques to isolate devices. This substitution eliminates the need for expensive hardware firewalls and complex network architecture changes, reducing both cost and complexity while maintaining security effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces software-based intermediaries in the form of host-based isolation agents that mediate network communications. These agents run on individual host devices and intercept, inspect, and control network traffic locally, serving as intermediaries between devices without requiring hardware firewalls or complex network infrastructure. This intermediary approach simplifies the overall system while providing effective device isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If existing firewall or software applications are used for traffic control, then ease of operation is improved, but the ability to block peer-to-peer communications effectively deteriorates

Engineering Contradiction:
Improveconfiguration easeVSAvoidcommunication blocking effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network isolation function into multiple independent techniques that can be applied at different OSI layers: ARP poisoning at the data link layer, route poisoning at the network layer, and firewall blocking at higher layers. This segmentation allows each technique to target specific communication paths, making the overall system more effective at blocking peer-to-peer communications while maintaining ease of operation through centralized policy management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal isolation platform that can implement multiple isolation techniques (ARP poisoning, route poisoning, firewall blocking) through a single software framework. This multi-functional approach allows the same software application to provide various forms of network isolation and traffic control, improving both ease of operation and communication blocking effectiveness by combining multiple mechanisms rather than relying on a single approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11985109B1Systems, methods and apparatus for local area network isolation
Publication Date: 2024.05.14 R&D INDUSTRIES INC
  • US11985109B1 patent drawing
  • US11985109B1 patent drawing
  • US11985109B1 patent drawing

AI summary

The disclosed apparatus, systems and methods relate to methods, systems, and devices for the isolation of devices on a LAN network. Route poisoning, ARP poisoning null routing, blackhole and/or firewall blocking are employed to prevent peer-to-peer network communications within the local area network.