Network Access Control via Application Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network owners face challenges in identifying and managing prohibited software applications on devices connected to their networks, especially in Bring Your Own Device (BYOD) environments, where devices may generate unwanted or malicious traffic, increasing bandwidth costs and security risks.

Innovation Solution

Implementing a system that monitors network activities to detect prohibited applications and restricts network access based on predefined application profiles, allowing or blocking access to specific resources, rather than attempting to block all associated traffic, thereby simplifying the management of communication techniques and reducing the need for frequent security solution reconfigurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all traffic associated with a prohibited application is blocked, then security protection is improved, but device complexity and management difficulty increase due to multiple communication techniques

Engineering Contradiction:
Improvesecurity protectionVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the core identifying characteristic of prohibited applications (specific network activities patterns) from their various communication manifestations. Instead of blocking all possible communication techniques, the system identifies and blocks only the distinctive network signatures that reliably indicate prohibited application usage, simplifying management while maintaining security effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the approach from blocking based on application identity to blocking based on observable network activity parameters. By monitoring and analyzing network traffic patterns, ports, protocols, and communication behaviors, the system identifies prohibited applications through their operational characteristics rather than requiring direct application-level blocking, reducing complexity.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If security solutions are reconfigured frequently to address new application versions, then detection accuracy is improved, but loss of time and productivity decrease

Engineering Contradiction:
Improvedetection accuracyVSAvoidreconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of network activities to establish baseline patterns of prohibited applications before new versions are deployed. By pre-configuring detection rules based on fundamental communication behaviors that remain consistent across versions, the system maintains detection accuracy without requiring frequent reconfiguration when applications are updated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous monitoring and feedback mechanisms that automatically adapt to new application versions by learning their network behavior patterns. When new prohibited applications or versions are detected, the system automatically updates its detection profiles based on observed network activities, eliminating manual reconfiguration time while maintaining high detection accuracy.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If network access is restricted upon detection of prohibited applications, then security risks are reduced, but ease of operation decreases for legitimate users

Engineering Contradiction:
Improvesecurity risksVSAvoiduser convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies different levels of network access restriction based on the specific prohibited application detected and the user's role. Rather than uniformly blocking all access, the system selectively restricts only the network resources and protocols associated with the prohibited application while maintaining access to essential business resources, balancing security with user convenience.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements dynamic access control that adjusts network permissions in real-time based on detected application behavior. Access restrictions are applied dynamically rather than statically, allowing legitimate users to resume full access once prohibited applications are terminated or removed, thereby maintaining ease of operation for genuine needs while enforcing security policies.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8819829B1Controlling network access based on application detection
Publication Date: 2014.08.26 IBOSS INC
  • US8819829B1 patent drawing
  • US8819829B1 patent drawing
  • US8819829B1 patent drawing

AI summary

This specification generally relates to controlling access of a device to a network based on the detection of a network application running on the device. One example method includes maintaining one or more application profiles, each application profile associated with one or more network activities in a network; detecting one or more network activities associated with a device connected to the network; determining that the one or more detected network activities associated with the device substantially match network activities associated with a predetermined application profile; and denying network access by the device to the network based upon the determination.