Network Gatekeeper Risk Assessment for Data Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data network security methods are inadequate in effectively managing risks associated with data distribution across networks, as they fail to consider the sensitivity of data and the degree of network intrusion at receiving devices, leading to potential unauthorized access and diffusion of threats like viruses and worms.

Innovation Solution

Implementing a network gatekeeper system that assesses the risk of data distribution by combining sensitivity factors of the data with intrusion monitoring data from receiving network devices, blocking distribution if the risk exceeds a threshold, and allowing it if within acceptable limits, while also considering additional risk factors and zone-based security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall and intrusion detection systems are used, then basic network security is provided, but they fail to effectively manage risks associated with data distribution sensitivity and receiving device intrusion status

Engineering Contradiction:
Improvedata distribution securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary risk assessment by evaluating data sensitivity factors and receiving device intrusion status before data distribution occurs. The gatekeeper calculates a risk score in advance and makes blocking decisions proactively, preventing unauthorized data flow before it can compromise the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A network gatekeeper is introduced as an intermediary component between data sources and receiving devices. This gatekeeper acts as a mediator that dynamically assesses risk factors and controls data distribution flow, adding a layer of intelligence between traditional firewall and intrusion detection systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data distribution is blocked to prevent unauthorized access, then security is improved, but legitimate data exchange may be hindered

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiddata exchange efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security system dynamically adjusts its blocking behavior based on real-time risk assessment. The gatekeeper continuously evaluates data sensitivity and receiving device status, making adaptive decisions about whether to allow or block data distribution. This dynamic approach prevents both unauthorized access and false blocking of legitimate exchanges.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of data distribution permission based on calculated risk scores. When the risk score exceeds a threshold, the gatekeeper blocks distribution; when it remains below the threshold, distribution is permitted. This parameter-based control mechanism balances security and productivity automatically.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7549162B2Methods of providing security for data distributions in a data network and related devices, networks, and computer program products
Publication Date: 2009.06.16 AT&T INTELLECTUAL PROPERTY I L P
  • US7549162B2 patent drawing
  • US7549162B2 patent drawing
  • US7549162B2 patent drawing

AI summary

Methods of operating a data network including a first network device and a second network device may be provided. In particular, data for distribution from the first network device to the second network device, a first risk factor associated with the data, and a second risk factor associated with the second network device may be provided. A risk of distribution may be assessed based on consideration of the first and second risk factors, and the distribution of data to the second network device may be blocked if the risk of distribution exceeds a threshold. Related systems, devices, and computer program products are also discussed.