Automatic Network Bad Actor Blocking via Centralized Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large retailers face challenges in efficiently blocking identified bad actors from accessing their networks, as manual blocking across multiple access points is time-consuming and prone to circumvention, and can result in accidental targeting of internal assets or failure to block intended external threats.
Innovation Solution
A system and method for automatically blocking identified bad actors across all access points of a network, utilizing a monitoring module to identify potential threats and a blocking module to configure network security appliances, such as firewalls and Intrusion Prevention Systems, to prevent access, while ensuring user authorization and avoiding self-blocking or approved vendor blocking through IP address verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual blocking procedures are used at each network security appliance, then authorization control and verification can be implemented, but the time required to block bad actors increases and productivity decreases
Solution Approach 1:
The system divides the blocking task into two segments: a monitoring module that identifies potential bad actors and collects authorization information, and a blocking module that executes the blocking action across all security appliances. This segmentation allows authorization verification to occur once during monitoring rather than repeatedly at each appliance, improving both reliability and productivity.
Solution Approach 2:
The monitoring module acts as an intermediary between the blocking request and the multiple network security appliances. It consolidates authorization verification and bad actor identification in one location, then communicates with all appliances centrally. This eliminates the need for manual intervention at each appliance while maintaining authorization control, resolving the contradiction between reliability and productivity.
2Reliability
If manual blocking is performed at each access point, then specific control over blocking actions is maintained, but the complexity of the blocking process increases and time consumption rises
Solution Approach 1:
The system merges the identification, authorization verification, and blocking execution functions into a unified automated process. The monitoring module consolidates bad actor identification and authorization checks, while the blocking module handles communication with all security appliances. This merging reduces process complexity by eliminating manual coordination between multiple access points while maintaining reliable control through centralized management.
3Productivity
If automated blocking is implemented across all network security appliances, then blocking speed and productivity improve, but the risk of accidental blocking of internal assets increases
Solution Approach 1:
The monitoring module performs preliminary actions before blocking is executed: it identifies potential bad actors, verifies authorization requirements, and checks whether the target is an internal asset or external threat. This preliminary verification process occurs automatically but includes safeguards to prevent accidental blocking of legitimate internal resources, allowing fast automated blocking while reducing harmful errors.
Solution Approach 2:
The system implements feedback mechanisms where the monitoring module continuously monitors network traffic and verifies blocking accuracy. When a blocking action is initiated, the system provides feedback to confirm the target is indeed a bad actor and not an internal asset. This feedback loop enables automated high-speed blocking while maintaining safety by detecting and preventing accidental blocking of legitimate resources.
Data Source
AI summary
According to one aspect, embodiments of the invention provide a system for restricting access to a network, the system comprising a monitoring module configured to be coupled to a plurality of network access points and to monitor transmissions to the network via a plurality of network security appliances, and a blocking module, wherein the monitoring module is further configured to identify a potential bad actor based on a transmission from the potential bad actor to the network via a first one of the plurality of network access points and a first one of the plurality of network security appliances and provide information related to the potential bad actor to the blocking module, and wherein the blocking module is configured to confirm that the potential bad actor should be blocked and in response, to automatically configure each network security appliance to block the potential bad actor from accessing the network.


