Network Access Control Server for Dynamic Asset Quarantine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures are insufficient in controlling access and managing vulnerabilities, as they often focus on single discrete vulnerabilities, are costly, and may have known or unknown holes, leading to exposure to various threats from both authorized and unauthorized clients.
Innovation Solution
A system and method that dynamically obtain information about network assets, compare device identifiers to policy constraints, and quarantine devices from the network if they do not comply, using a combination of self-discovery methods, assets database, and policy database to enforce uniform security policies and segmentation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple discrete security solutions (firewalls, authentication servers, patch management) are implemented to control network access, then specific security vulnerabilities are addressed, but the overall system complexity increases and coverage gaps remain
Solution Approach 1:
The patent combines multiple discrete security functions (authentication, authorization, asset management, policy enforcement) into a single integrated NAC server that maintains databases of network assets and policies, and coordinates all access control decisions in one centralized location, thereby reducing system complexity while maintaining comprehensive security coverage
Solution Approach 2:
The NAC server performs multiple security functions simultaneously: it authenticates devices, authorizes access levels, monitors network assets, enforces policies, and dynamically quarantines threats. This multi-functional approach replaces the need for separate specialized security systems, reducing overall complexity while improving reliability
2Reliability
If continuous network auditing and monitoring are performed to identify security threats, then network vulnerability detection improves, but network performance and available bandwidth are degraded
Solution Approach 1:
The system performs partial monitoring by selectively auditing only authentication traffic and policy-relevant communications rather than all network traffic. The NAC server focuses monitoring efforts on critical security functions while allowing normal network traffic to flow uninterrupted, thus maintaining threat detection capability without significantly degrading network throughput
Solution Approach 2:
The NAC server acts as an intermediary that handles all authentication and authorization traffic, performing security checks at this intermediate layer. This allows the system to monitor and control security-critical communications without needing to inspect or process every data packet flowing through the network, preserving network performance while maintaining detection capability
3Reliability
If unauthorized devices are immediately denied network access, then network security is improved, but legitimate devices with temporary issues (unpatched software, missing certificates) are incorrectly blocked
Solution Approach 1:
The system performs preliminary authentication and policy verification before granting full network access. Devices undergo initial checks against the asset database and policy rules, and those that fail temporarily can be placed in a restricted quarantine VLAN where they can receive patches or certificates before being fully authorized, preventing incorrect blocking of legitimate devices
Solution Approach 2:
The network is segmented into different access levels using VLANs: fully authorized devices access the main network, while devices with temporary issues are segregated into quarantine zones with limited access. This segmentation allows the system to maintain strict security controls while providing appropriate access to legitimate devices based on their current compliance status
Data Source
AI summary
A system and method capable of obtaining information dynamically of assets residing on a network. The system and method further capable of comparing a device identifier to the dynamically obtained information of assets and policies at a time of a request to access the network and determining whether the device identifier matches at least one of the dynamically obtained information of assets and policies. The system and method further capable of quarantining the device from the network or a portion thereof based upon the determining.


