Network Access Control via Application Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network owners face challenges in identifying and managing prohibited software applications on devices connected to their networks, especially in Bring Your Own Device (BYOD) environments, where these applications can generate unwanted traffic and introduce security risks, as they often communicate using multiple protocols, making it difficult to block all associated traffic effectively.

Innovation Solution

Implementing a system that detects prohibited applications by monitoring network activities and restricting access to the network when such applications are detected, rather than attempting to block all associated traffic, allowing for flexible administration of network policies and improved security by denying access to internal resources while still allowing Internet access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all traffic associated with prohibited applications is blocked, then network security is improved, but device complexity and difficulty of detection increase due to multiple communication protocols

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and monitors only specific network activities and protocols associated with prohibited applications, rather than attempting to block all traffic. This selective approach simplifies the detection system while maintaining security effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the detection parameter from attempting to identify all application traffic to monitoring specific network activities and protocol patterns. This parameter change reduces detection complexity while maintaining security.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If reconfiguration is performed constantly to address new application versions, then detection accuracy is improved, but loss of time and productivity decrease

Engineering Contradiction:
Improvedetection accuracyVSAvoidreconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent establishes a monitoring system that proactively detects prohibited applications and their network activities in advance, allowing for automated responses without manual reconfiguration. This preliminary detection approach maintains accuracy while eliminating repeated setup time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous monitoring and feedback mechanisms that automatically adapt to new application versions by detecting their network activities, eliminating the need for manual reconfiguration while maintaining detection accuracy.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If prohibited applications are allowed to run, then ease of operation is improved, but object-generated harmful factors increase due to unwanted traffic and security risks

Engineering Contradiction:
Improvedevice usage flexibilityVSAvoidunwanted traffic and security risks
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a network monitoring system as an intermediary that allows prohibited applications to run on devices while intercepting and controlling their network activities. This mediator approach maintains device usability while preventing harmful network traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies different quality controls to different network activities, allowing legitimate traffic while blocking harmful patterns specific to prohibited applications. This localized control maintains ease of operation for authorized uses while preventing security risks.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4024756B1Controlling network access based on application detection
Publication Date: 2023.11.01 IBOSS INC
  • EP4024756B1 patent drawingFigure 1
  • EP4024756B1 patent drawingFigure 2
  • EP4024756B1 patent drawingFigure 3

AI summary

This specification generally relates to controlling access of a device to a network based on the detection of a network application running on the device. One example method includes maintaining one or more application profiles, each application profile associated with one or more network activities in a network; detecting one or more network activities in the network associated with a device, the one or more activities directed outside the network; determining that the one or more detected network activities associated with the device directed outside the network substantially match network activities associated with a predetermined application profile; and denying access by the device to one or more resources within the network based upon the determination.