Network Access Control via Application Detection Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network owners face challenges in managing prohibited software applications on devices connected to their networks, particularly in identifying and handling applications like BitTorrent and UltraSurf, which can generate unwanted traffic and security risks, especially in Bring Your Own Device (BYOD) environments where control over devices is limited.
Innovation Solution
Implementing a system that detects prohibited applications by monitoring network activities and associates devices running such applications with restricted network profiles, limiting or denying access to specific network resources rather than attempting to block all associated traffic, allowing continued access to public networks while restricting access to internal resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all traffic associated with prohibited applications is blocked, then network security is improved, but device functionality and user experience deteriorate
Solution Approach 1:
The patent segments network access into different profiles (unrestricted and restricted) based on application detection. Instead of blocking all traffic from devices running prohibited applications, the system applies restrictions only to specific network resources while allowing access to others, thereby maintaining security while preserving essential device functionality.
Solution Approach 2:
The patent implements local quality by applying different access restrictions to different network resources. The restricted network profile denies access to specific internal resources while allowing access to public networks and other resources, creating a localized restriction rather than a blanket block that would impair overall device functionality.
2Reliability
If traditional blocking methods are used for applications like UltraSurf, then security is improved, but the system requires constant reconfiguration as applications update, increasing operational complexity
Solution Approach 1:
The patent performs preliminary action by detecting the presence of prohibited applications and pre-applying restricted network profiles before security issues can arise. The system proactively identifies applications like UltraSurf and immediately restricts their network access, eliminating the need for constant reconfiguration when applications update.
Solution Approach 2:
The patent implements feedback mechanisms that continuously monitor network traffic patterns to detect prohibited applications. The system receives feedback from network activity analysis and automatically adjusts access profiles accordingly, reducing manual configuration complexity while maintaining security.
3Reliability
If restricted network profiles are applied upon first detection, then protection against unwanted activity is improved, but device connectivity is reduced
Solution Approach 1:
The patent applies local quality by implementing restricted access only to specific network resources rather than completely isolating the device. The restricted network profile allows continued connectivity to public networks and essential resources while blocking access only to internal resources that pose security risks, thereby maintaining productivity while providing protection.
Data Source
AI summary
This specification generally relates to controlling access of a device to a network based on detection of a network application running on the device. One example method includes maintaining one or more application profiles, each application profile associated with one or more network activities in a network; detecting one or more network activities associated with a device connected to the network; determining that the one or more detected network activities associated with the device substantially match network activities associated with a first application profile; and associating the device with a restricted network profile upon determining that the one or more detected network activities substantially match network activities associated with the first application profile, the restricted network profile configured to deny access by the device to one or more first resources on the network, and configured to allow access by the device to one or more second resources on the network.


