Network Control Device Zone Segmentation for Incident Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network control methods struggle to efficiently respond to targeted attacks in large-scale networks, often missing suspicious communication activities due to overwhelming logs and alerts, and fail to fully capture internal reconnaissance activities, leading to inefficiencies in incident analysis and potential adverse effects on business operations.
Innovation Solution
A network control device and method that divide terminals and related groups into zones based on terminal information and communication history, allowing for targeted communication control and countermeasure device settings within each zone to enhance incident response efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network control is performed for all terminals in a network segment, then incident response coverage is improved, but the number of logs and alerts increases excessively, making it difficult to detect suspicious activities
Solution Approach 1:
The patent segments the network segment into multiple sub-segments based on terminal relationships and communication patterns. By dividing the large network segment into smaller, more manageable sub-segments, the system can apply targeted monitoring and control measures that reduce the overall volume of logs and alerts while maintaining effective incident response coverage for suspicious activities.
2Reliability
If access control is performed for all terminals in a network segment, then security against targeted attacks is improved, but business operations are adversely affected due to excessive disruption
Solution Approach 1:
The patent applies local quality by differentiating control measures based on terminal characteristics and relationships. Instead of applying uniform access control to all terminals in a network segment, the system identifies and applies enhanced security measures only to terminals that exhibit suspicious behavior or have established malicious relationships, thereby maintaining security effectiveness while minimizing disruption to legitimate business operations.
3Reliability
If conventional boundary defense type information security products are used, then basic security protection is provided, but targeted attacks cannot be completely prevented due to inability to detect internal reconnaissance activities
Solution Approach 1:
The patent implements feedback mechanisms that continuously monitor terminal behavior, communication patterns, and relationships within the network. By analyzing this feedback data in real-time, the system can detect internal reconnaissance activities and adjust security controls dynamically, overcoming the limitations of static boundary defense products and enabling detection of sophisticated targeted attacks.
Data Source
AI summary
Provided is a network control device 2000 for controlling a network where a plurality of terminals and countermeasure devices are connected, the network control device 2000 including: a clustering unit 2001 that divides terminals including an incident-detected terminal and the related terminal group into a plurality of zones, on the basis of terminal information including information with which an incident-detected terminal is able to be identified, information with which a related terminal group suspected of being related to an incident is able to be identified among the plurality of terminals, and an inter-terminal communication history; and a communication control setting unit 2002 that sets communication control relating to the terminals and the countermeasure devices for each of the plurality of zones.


