Network Traffic Hub Intercepts Port Forwarding Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart appliances are vulnerable to security breaches due to vulnerabilities at the operating system and network layers, and existing anti-virus software is ill-suited for these devices, which lack the computing resources to support it, making it difficult for users to detect malicious behavior.

Innovation Solution

A network traffic hub intercepts requests for port services from smart appliances, sending an authorization request to the user before allowing port forwarding or port triggering, and includes a behavior analysis engine to assess the appliance's vulnerability before approving the request, thereby preventing automatic establishment of port services until user approval is received.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If port forwarding or port triggering is automatically established for smart appliances, then network connectivity and functionality are improved, but security vulnerability increases due to unauthorized access risks

Engineering Contradiction:
Improveautomatic port service establishmentVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authorization mechanism between the smart appliance and the network router. When a smart appliance requests port forwarding or port triggering, the system intercepts the request and requires user authorization before establishing the port service. This intermediary step prevents automatic establishment of potentially malicious port services while allowing legitimate ones, thus resolving the contradiction between ease of operation and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If anti-virus software is installed on smart appliances, then malicious code detection capability is improved, but device complexity and resource requirements increase beyond what smart appliances can support

Engineering Contradiction:
Improvemalicious code detectionVSAvoidsoftware resource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security analysis function from the smart appliance itself and places it on an external server or cloud-based system. The smart appliance only needs to transmit its behavior data and receive authorization decisions, while the complex malicious code detection and behavior analysis are performed externally. This extraction allows reliable security detection without increasing the complexity or resource requirements of the smart appliance.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If users have limited access to smart appliance functionality, then device simplicity is maintained, but ability to detect malicious behavior is reduced

Engineering Contradiction:
Improveuser access simplicityVSAvoidmalicious behavior detection
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the system monitors smart appliance behavior, analyzes it for malicious patterns, and provides authorization decisions back to the user through a simplified interface. Users receive notifications about port service requests with clear approve/deny options, without needing to understand the complex underlying security analysis. This feedback loop maintains device simplicity while enabling effective malicious behavior detection through external analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3602315B1Securing port forwarding through a network traffic hub
Publication Date: 2022.06.22 CUJO LLC
  • EP3602315B1 patent drawingFigure 1
  • EP3602315B1 patent drawingFigure 2
  • EP3602315B1 patent drawingFigure 3

AI summary

A network traffic hub is configured to receive a request for a port service (i.e., port forwarding or port triggering) from a smart appliance in a local network. The request may be a part of the UPnP protocol, which includes SSDP and IGDP. The request may be transmitted to the network traffic hub directly or the network traffic hub may intercept the request transmitted to a router of the local network. By receiving the request, the network traffic hub prevents automatic establishment of the port service between the smart appliance and the router until an approval or denial of the port sendee is received from, a user. As such, the user is informed of the request and has the ability to approve or deny the port service. Furthermore, the network traffic hub can configure a network to perform a port sendee if the network does not allow for it natively.