Network Control Device Zone Segmentation for Incident Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network control methods struggle to efficiently respond to targeted attacks in large-scale networks, often missing suspicious communication activities due to overwhelming logs and alerts, and fail to fully capture internal reconnaissance activities, leading to inefficiencies in incident analysis and potential adverse effects on business operations.

Innovation Solution

A network control device and method that divide terminals and related groups into zones based on terminal information and communication history, allowing for targeted communication control and countermeasure device settings within each zone to enhance incident response efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network control is performed for all terminals in a network segment, then incident response coverage is improved, but the number of logs and alerts increases excessively, making it difficult to detect suspicious activities

Engineering Contradiction:
Improveincident response coverageVSAvoidnumber of logs and alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the network segment into multiple sub-segments based on terminal relationships and communication patterns. By dividing the large network segment into smaller, more manageable sub-segments, the system can apply targeted monitoring and control measures that reduce the overall volume of logs and alerts while maintaining effective incident response coverage for suspicious activities.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control is performed for all terminals in a network segment, then security against targeted attacks is improved, but business operations are adversely affected due to excessive disruption

Engineering Contradiction:
Improvesecurity against targeted attacksVSAvoidbusiness operations
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating control measures based on terminal characteristics and relationships. Instead of applying uniform access control to all terminals in a network segment, the system identifies and applies enhanced security measures only to terminals that exhibit suspicious behavior or have established malicious relationships, thereby maintaining security effectiveness while minimizing disruption to legitimate business operations.

Inventive Principle:
Principle #3Local quality

3Reliability

If conventional boundary defense type information security products are used, then basic security protection is provided, but targeted attacks cannot be completely prevented due to inability to detect internal reconnaissance activities

Engineering Contradiction:
Improvebasic security protectionVSAvoidinternal reconnaissance activities
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms that continuously monitor terminal behavior, communication patterns, and relationships within the network. By analyzing this feedback data in real-time, the system can detect internal reconnaissance activities and adjust security controls dynamically, overcoming the limitations of static boundary defense products and enabling detection of sophisticated targeted attacks.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11588846B2Network control device and network control method
Publication Date: 2023.02.21 NEC CORP
  • US11588846B2 patent drawing
  • US11588846B2 patent drawing
  • US11588846B2 patent drawing

AI summary

Provided is a network control device 2000 for controlling a network where a plurality of terminals and countermeasure devices are connected, the network control device 2000 including: a clustering unit 2001 that divides terminals including an incident-detected terminal and the related terminal group into a plurality of zones, on the basis of terminal information including information with which an incident-detected terminal is able to be identified, information with which a related terminal group suspected of being related to an incident is able to be identified among the plurality of terminals, and an inter-terminal communication history; and a communication control setting unit 2002 that sets communication control relating to the terminals and the countermeasure devices for each of the plurality of zones.