Network Appliance Dynamic Blocking for Threat Intelligence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network appliances work independently and may block the same IP addresses, leading to incomplete threat fingerprinting and reduced effectiveness of Global Threat Intelligence systems, as they lack coordinated instructions for blocking IP addresses.
Innovation Solution
A centralized management system allows network appliances to temporarily alter their configuration to gather information from specific IP addresses, enabling coordinated blocking and enhanced threat analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network appliances completely block IP addresses when threats are detected, then security protection is improved, but threat intelligence data collection is worsened
Solution Approach 1:
The patent implements dynamic blocking where network appliances temporarily suspend blocking of specific IP addresses for predetermined periods to allow threat intelligence systems to collect data, then resume blocking. This dynamic adjustment resolves the contradiction by making the blocking state flexible rather than static, enabling both security protection and data collection at different times.
Solution Approach 2:
The system employs periodic blocking suspension where appliances automatically restore communication from previously blocked IP addresses at scheduled intervals to gather threat intelligence, then re-impose blocking. This periodic action ensures continuous security protection while systematically collecting necessary threat data without permanent loss of intelligence information.
2Speed
If all network appliances work independently and block IP addresses autonomously, then local security response is improved, but global threat intelligence effectiveness is worsened
Solution Approach 1:
The patent establishes a feedback mechanism where network appliances report blocked IP address information to a central threat intelligence system, which then coordinates suspension of blocking across multiple appliances. This feedback loop enables local appliances to maintain autonomous response speed while the central system aggregates information to improve global threat intelligence effectiveness.
Solution Approach 2:
The system merges independent local blocking decisions with centralized threat intelligence coordination. Multiple appliances combine their blocking actions and share intelligence through the central system, achieving both fast local response and enhanced global threat detection by pooling information from distributed sources.
3Reliability
If network appliances maintain strict blocking configuration, then security enforcement is improved, but threat analysis capability is worsened
Solution Approach 1:
The patent implements preliminary action by automatically suspending blocking configurations before threat analysis is complete. The system proactively temporarily restores communication from blocked IP addresses to enable threat intelligence systems to collect and analyze data, then resumes blocking after analysis. This preliminary suspension ensures threat analysis capability is maintained without compromising long-term security enforcement.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed are systems and methods to perform coordinated blocking of source addresses, such as an Internet Protocol (IP) addresses, across a plurality of network appliances {e.g., gateways). In one disclosed embodiment the method and system temporarily alter a configuration of one or more network appliances (based on user defined configuration parameters) to allow communication from a "blocked" IP address for a period of time. A network appliance can then "receive" an email and perform analysis and provide results of the analysis to a reputation service. Thereby, the temporarily allowed communication can be used to learn information about a threat which would not have been available if all communication from that IP address had actually been blocked at the network appliance.