Network Access Control via Application Detection Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network owners face challenges in managing prohibited software applications on devices connected to their networks, particularly in identifying and handling applications like BitTorrent and UltraSurf, which can generate unwanted traffic and security risks, especially in Bring Your Own Device (BYOD) environments where control over devices is limited.

Innovation Solution

Implementing a system that detects prohibited applications by monitoring network activities and associates devices running such applications with restricted network profiles, limiting or denying access to specific network resources rather than attempting to block all associated traffic, allowing continued access to public networks while restricting access to internal resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all traffic associated with prohibited applications is blocked, then network security is improved, but device functionality and user experience deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments network access into different profiles (unrestricted and restricted) based on application detection. Instead of blocking all traffic from devices running prohibited applications, the system applies restrictions only to specific network resources while allowing access to others, thereby maintaining security while preserving essential device functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different access restrictions to different network resources. The restricted network profile denies access to specific internal resources while allowing access to public networks and other resources, creating a localized restriction rather than a blanket block that would impair overall device functionality.

Inventive Principle:
Principle #3Local quality

2Reliability

If traditional blocking methods are used for applications like UltraSurf, then security is improved, but the system requires constant reconfiguration as applications update, increasing operational complexity

Engineering Contradiction:
ImprovesecurityVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by detecting the presence of prohibited applications and pre-applying restricted network profiles before security issues can arise. The system proactively identifies applications like UltraSurf and immediately restricts their network access, eliminating the need for constant reconfiguration when applications update.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that continuously monitor network traffic patterns to detect prohibited applications. The system receives feedback from network activity analysis and automatically adjusts access profiles accordingly, reducing manual configuration complexity while maintaining security.

Inventive Principle:
Principle #23Feedback

3Reliability

If restricted network profiles are applied upon first detection, then protection against unwanted activity is improved, but device connectivity is reduced

Engineering Contradiction:
Improveprotection against unwanted activityVSAvoidnetwork connectivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing restricted access only to specific network resources rather than completely isolating the device. The restricted network profile allows continued connectivity to public networks and essential resources while blocking access only to internal resources that pose security risks, thereby maintaining productivity while providing protection.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8726390B1Controlling network access based on application detection
Publication Date: 2014.05.13 IBOSS INC
  • US8726390B1 patent drawing
  • US8726390B1 patent drawing
  • US8726390B1 patent drawing

AI summary

This specification generally relates to controlling access of a device to a network based on detection of a network application running on the device. One example method includes maintaining one or more application profiles, each application profile associated with one or more network activities in a network; detecting one or more network activities associated with a device connected to the network; determining that the one or more detected network activities associated with the device substantially match network activities associated with a first application profile; and associating the device with a restricted network profile upon determining that the one or more detected network activities substantially match network activities associated with the first application profile, the restricted network profile configured to deny access by the device to one or more first resources on the network, and configured to allow access by the device to one or more second resources on the network.