Network Appliance Dynamic Blocking for Threat Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network appliances work independently and may block the same IP addresses, leading to incomplete threat fingerprinting and reduced effectiveness of Global Threat Intelligence systems, as they lack coordinated instructions for blocking IP addresses.

Innovation Solution

A centralized management system allows network appliances to temporarily alter their configuration to gather information from specific IP addresses, enabling coordinated blocking and enhanced threat analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network appliances completely block IP addresses when threats are detected, then security protection is improved, but threat intelligence data collection is worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoidthreat intelligence data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamic blocking where network appliances temporarily suspend blocking of specific IP addresses for predetermined periods to allow threat intelligence systems to collect data, then resume blocking. This dynamic adjustment resolves the contradiction by making the blocking state flexible rather than static, enabling both security protection and data collection at different times.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic blocking suspension where appliances automatically restore communication from previously blocked IP addresses at scheduled intervals to gather threat intelligence, then re-impose blocking. This periodic action ensures continuous security protection while systematically collecting necessary threat data without permanent loss of intelligence information.

Inventive Principle:
Principle #19Periodic action

2Speed

If all network appliances work independently and block IP addresses autonomously, then local security response is improved, but global threat intelligence effectiveness is worsened

Engineering Contradiction:
Improvelocal security responseVSAvoidglobal threat intelligence
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent establishes a feedback mechanism where network appliances report blocked IP address information to a central threat intelligence system, which then coordinates suspension of blocking across multiple appliances. This feedback loop enables local appliances to maintain autonomous response speed while the central system aggregates information to improve global threat intelligence effectiveness.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system merges independent local blocking decisions with centralized threat intelligence coordination. Multiple appliances combine their blocking actions and share intelligence through the central system, achieving both fast local response and enhanced global threat detection by pooling information from distributed sources.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If network appliances maintain strict blocking configuration, then security enforcement is improved, but threat analysis capability is worsened

Engineering Contradiction:
Improvesecurity enforcementVSAvoidthreat analysis capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by automatically suspending blocking configurations before threat analysis is complete. The system proactively temporarily restores communication from blocked IP addresses to enable threat intelligence systems to collect and analyze data, then resumes blocking after analysis. This preliminary suspension ensures threat analysis capability is maintained without compromising long-term security enforcement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2764660B1Distributed system and method for tracking and blocking malicious internet hosts
Publication Date: 2018.12.05 MCAFEE LLC
  • EP2764660B1 patent drawingFigure 1
  • EP2764660B1 patent drawingFigure 2
  • EP2764660B1 patent drawingFigure 3

AI summary

Disclosed are systems and methods to perform coordinated blocking of source addresses, such as an Internet Protocol (IP) addresses, across a plurality of network appliances {e.g., gateways). In one disclosed embodiment the method and system temporarily alter a configuration of one or more network appliances (based on user defined configuration parameters) to allow communication from a "blocked" IP address for a period of time. A network appliance can then "receive" an email and perform analysis and provide results of the analysis to a reputation service. Thereby, the temporarily allowed communication can be used to learn information about a threat which would not have been available if all communication from that IP address had actually been blocked at the network appliance.