Network Access Control via Combined Client and Trusted Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures are inadequate in preventing malware infections and unauthorized access to malicious websites, as they can become outdated quickly and are often disabled by malware, allowing infections to occur before updates can be applied, and they lack effective control over client options.
Innovation Solution
A system and method for controlling network content access by combining client and trusted site profiles, using a network access server with a combining engine and filtering engine to ensure access rules are enforced, allowing only compliant requests to proceed, and enabling automatic updates to ensure the latest security measures are applied.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional antivirus and firewall applications are installed on client processors, then malware protection is provided, but the protection becomes outdated quickly and can be disabled by malware
Solution Approach 1:
A network access server acts as an intermediary between clients and the network, centralizing security control. The server hosts updated security profiles and filters network traffic, preventing malware from reaching clients before they can disable local protections. This mediator approach ensures clients receive current security measures without relying on timely local updates.
Solution Approach 2:
Security profiles and filtering rules are prepared and updated in advance on the network access server before malware can infect clients. The server pre-configures protection mechanisms that are applied to network traffic before it reaches client processors, preventing the time-lag problem where local antivirus software becomes outdated after infection occurs.
2Reliability
If client processors run local antivirus and security software, then protection is provided, but client options and control are excessive and difficult to manage
Solution Approach 1:
Security control functions are extracted from individual client processors and centralized on the network access server. The server handles profile management, update distribution, and filtering decisions, removing the complexity of managing multiple client-based security systems. Clients simply receive and apply centrally-managed security profiles.
Solution Approach 2:
The network access server provides universal security control for all clients through a single platform. It performs multiple functions including hosting security profiles, filtering network traffic, updating protections, and managing access rules, replacing the need for each client to independently manage its own security software.
3Reliability
If content assessment is performed to control network access, then access security is improved, but access speed is reduced
Solution Approach 1:
Security profiles and filtering rules are pre-configured and stored on the network access server before access requests occur. When clients request network access, the server applies pre-established rules rather than performing real-time content assessment, maintaining both security and speed by avoiding on-the-fly analysis of each access request.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A system comprises a client (10) that can place a network site (18) access request to a network access server (14). Sometime prior to placing the request, the client has already accessed the network access server (14) to set up a network access profile relating to personal choices and has accessed a trusted site (16) to select one or more options to provide a trusted site profile. When the client (10) places a request, client data is provided along with the request whereby the client is automatically recognized by the network access server (14). The network access server, upon recognition of the client, passes the client data to the trusted site (16), the trusted site (16) uses the client data to retrieve the client's (10) trusted site profile, and the trusted site (16) transfers the trusted site profile to the network access server (14). A combining engine in the network access server (14) then combines the trusted site profile with the network access profile and a filtering engine applies the combined profiles to permit or forbid the network site (18) request to be fulfilled.