Automatic Network Bad Actor Blocking via Centralized Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large retailers face challenges in efficiently blocking identified bad actors from accessing their networks, as manual blocking across multiple access points is time-consuming and prone to circumvention, and can result in accidental targeting of internal assets or failure to block intended external threats.

Innovation Solution

A system and method for automatically blocking identified bad actors across all access points of a network, utilizing a monitoring module to identify potential threats and a blocking module to configure network security appliances, such as firewalls and Intrusion Prevention Systems, to prevent access, while ensuring user authorization and avoiding self-blocking or approved vendor blocking through IP address verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual blocking procedures are used at each network security appliance, then authorization control and verification can be implemented, but the time required to block bad actors increases and productivity decreases

Engineering Contradiction:
Improveauthorization controlVSAvoidblocking speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides the blocking task into two segments: a monitoring module that identifies potential bad actors and collects authorization information, and a blocking module that executes the blocking action across all security appliances. This segmentation allows authorization verification to occur once during monitoring rather than repeatedly at each appliance, improving both reliability and productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The monitoring module acts as an intermediary between the blocking request and the multiple network security appliances. It consolidates authorization verification and bad actor identification in one location, then communicates with all appliances centrally. This eliminates the need for manual intervention at each appliance while maintaining authorization control, resolving the contradiction between reliability and productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual blocking is performed at each access point, then specific control over blocking actions is maintained, but the complexity of the blocking process increases and time consumption rises

Engineering Contradiction:
Improveblocking controlVSAvoidblocking process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the identification, authorization verification, and blocking execution functions into a unified automated process. The monitoring module consolidates bad actor identification and authorization checks, while the blocking module handles communication with all security appliances. This merging reduces process complexity by eliminating manual coordination between multiple access points while maintaining reliable control through centralized management.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If automated blocking is implemented across all network security appliances, then blocking speed and productivity improve, but the risk of accidental blocking of internal assets increases

Engineering Contradiction:
Improveblocking speedVSAvoidaccidental blocking risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The monitoring module performs preliminary actions before blocking is executed: it identifies potential bad actors, verifies authorization requirements, and checks whether the target is an internal asset or external threat. This preliminary verification process occurs automatically but includes safeguards to prevent accidental blocking of legitimate internal resources, allowing fast automated blocking while reducing harmful errors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the monitoring module continuously monitors network traffic and verifies blocking accuracy. When a blocking action is initiated, the system provides feedback to confirm the target is indeed a bad actor and not an internal asset. This feedback loop enables automated high-speed blocking while maintaining safety by detecting and preventing accidental blocking of legitimate resources.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10084749B2Automatic blocking of bad actors across a network
Publication Date: 2018.09.25 WALMART APOLLO LLC
  • US10084749B2 patent drawing
  • US10084749B2 patent drawing
  • US10084749B2 patent drawing

AI summary

According to one aspect, embodiments of the invention provide a system for restricting access to a network, the system comprising a monitoring module configured to be coupled to a plurality of network access points and to monitor transmissions to the network via a plurality of network security appliances, and a blocking module, wherein the monitoring module is further configured to identify a potential bad actor based on a transmission from the potential bad actor to the network via a first one of the plurality of network access points and a first one of the plurality of network security appliances and provide information related to the potential bad actor to the blocking module, and wherein the blocking module is configured to confirm that the potential bad actor should be blocked and in response, to automatically configure each network security appliance to block the potential bad actor from accessing the network.