Network Access Controller for Automated Malware Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large corporate networks face challenges in managing access control and security due to the susceptibility to malware spread and the difficulty in tracking and managing numerous network users, leading to productivity losses and security breaches.

Innovation Solution

A system and method that employs a network access controller to intercept data transmissions, identify and enforce access policies, deploy administrative agents to collect configuration and topology information, and activate antivirus software to detect and mitigate malicious activities, thereby controlling data transmissions and preventing malware spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access control is performed for each network user, then access security is improved, but administration time and complexity increase significantly

Engineering Contradiction:
Improveaccess securityVSAvoidadministration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service access control where the network access controller automatically evaluates user credentials, authentication tokens, and authorization policies to grant or deny access without requiring manual intervention from network administrators for each user connection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameters of access control from manual, static decisions to automated, dynamic evaluations based on real-time authentication tokens, user profiles, and policy rules that can be changed without affecting active connections

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive security monitoring is implemented, then malware detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network access controller performs multiple security functions including authentication, authorization, access control, and malware monitoring through a single integrated system, eliminating the need for separate security devices and reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary layer of automated policy evaluation and decision-making between users and network resources, where the network access controller mediates all access requests through centralized authentication tokens and authorization policies

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2541835B1System and method for controlling access to network resources
Publication Date: 2015.01.07 AO KASPERSKY LAB
  • EP2541835B1 patent drawingFigure 1A
  • EP2541835B1 patent drawingFigure 1B
  • EP2541835B1 patent drawingFigure 1C

AI summary

Disclosed are systems and methods for controlling access to a computer network. An example network access controller is configured to intercept data transmission to or from a computer and identify a network access policy associated with said computer. If there is no network access policy associated with said computer, the controller deploys on said computer an administration agent configured to collect configuration information from said computer and information about topology of said network. The controller determines a network access policy for said computer based on the collected information. The controller also activates antivirus software on said computer, to detect any malicious activity on said computer. If malicious activity is detected, the controller limits data transmissions to or from said computer until the malicious activity is eliminated by the antivirus software to prevent spread of the malicious activity to other computers in the network.