Network Access Control Appliance Dynamic Node Quarantining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems in networks lack effective mechanisms to dynamically manage and enforce security policies, particularly in identifying and quarantining unauthorized or vulnerable nodes, which poses risks to network security and compliance.

Innovation Solution

A network access control appliance (NACA) is employed to manage dynamic network access at the switch port level, utilizing mechanisms like VLANs, 802.1x authentication, and ARP spoofing to quarantine and remediate nodes, ensuring only authorized devices connect to the network and adhere to security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems are used, then network connectivity is maintained, but network security is compromised due to inability to dynamically quarantine unauthorized nodes

Engineering Contradiction:
Improvenetwork securityVSAvoiddynamic access management
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts network access control by transitioning nodes between authorized and quarantined states based on real-time security assessments. The NACA appliance continuously monitors network traffic and can dynamically update access control lists to isolate suspicious nodes without manual intervention, making the security system adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The NACA appliance acts as an intermediary between the network switch and unauthorized nodes. It intercepts traffic from suspicious devices, performs security assessments, and mediates access control decisions by updating switch ACLs. This intermediary function allows the system to maintain network connectivity for authorized devices while isolating threats without requiring direct control at the switch level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual access control methods are used, then system complexity is reduced, but productivity in managing network security decreases

Engineering Contradiction:
Improvesecurity policy enforcement efficiencyVSAvoidaccess control system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs self-service security assessments by automatically analyzing traffic patterns, device behaviors, and security policy compliance without requiring manual administrator intervention. The NACA appliance autonomously identifies suspicious nodes, assesses their security posture, and enforces quarantine decisions, significantly improving security management productivity while maintaining manageable complexity through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes operational parameters dynamically by adjusting access control list rules, VLAN assignments, and traffic routing based on real-time security assessments. Instead of requiring manual reconfiguration of complex switch settings, the NACA appliance automatically modifies these parameters to enforce security policies, reducing the operational burden on administrators while maintaining sophisticated security control.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive security assessments are performed on all nodes, then measurement precision of security threats improves, but loss of time in network operations increases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidnetwork operation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs security assessments selectively rather than universally by focusing intensive analysis only on nodes exhibiting suspicious behavior or failing initial access control checks. The NACA appliance monitors all network traffic but applies comprehensive security assessments only to targeted nodes, maintaining high threat identification accuracy while minimizing the time overhead on normal network operations through this partial action approach.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8520512B2Network appliance for customizable quarantining of a node on a network
Publication Date: 2013.08.27 MCAFEE LLC
  • US8520512B2 patent drawing
  • US8520512B2 patent drawing
  • US8520512B2 patent drawing

AI summary

A system, method, and apparatus are directed to managing access to a network. An agent may intercept a network packet transmitted by an enforcement point in response to a request from a device to join the network. The agent identifies, based on the network packet, a port number on the enforcement point at which the request is received. The agent may transmit the port number to a NACA to enable security enforcement operations to be performed on the device. Another device may reside outside the quarantined network and be enabled by the NACA to direct a remediation measure to be performed on the device using at least the port number. The NACA may spoof an ARP response with an address of the NACA to restrict access to resources. The NACA may also place the device into one of a plurality of quarantined networks.