Network Isolation via Segmented Sandboxes and Proxy Firewalls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Host computer systems are vulnerable to malware infections, which can lead to security losses, efficiency reductions, and loss of command and control, allowing malicious software to compromise user privacy and data, as well as use the infected system to attack other network resources.

Innovation Solution

Implementing an internet isolation system that includes a network, host computer systems, border firewalls, authorization devices, and proxy devices to segregate communications into trusted and untrusted memory spaces, using sandboxed computing environments and internal isolation firewalls to prevent malware from moving between devices and accessing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a host computer system connects to untrusted networks to access beneficial data, then information accessibility is improved, but vulnerability to malware infection increases

Engineering Contradiction:
Improveinformation accessibilityVSAvoidmalware infection vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the host computer system into isolated computing environments (sandboxes) that are separated from the main trusted network. Each sandboxed environment can access untrusted networks independently, containing any potential malware infection within that specific environment and preventing it from spreading to other devices or compromising sensitive data on the main system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces proxy devices and border firewalls as intermediary components between the host computer system and untrusted networks. These intermediaries act as controlled access points that filter and monitor network traffic, allowing beneficial data access while blocking malicious content and preventing direct connections that could lead to malware infections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-generated harmful factors

If malware is downloaded to a host computer system, then access to harmful data is achieved, but system security and efficiency are compromised

Engineering Contradiction:
Improvemalware execution capabilityVSAvoidsystem security
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The system extracts potentially harmful malware executions from the main trusted environment and relocates them to isolated sandboxed computing environments. This extraction ensures that even if malware is downloaded and executed, it operates in a contained space where it cannot access or compromise the main system's security, files, or network resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary protective measures by configuring host-based firewalls, border firewalls, and authorization devices before malware can cause harm. These pre-established security controls actively prevent malware from establishing command and control connections, blocking its ability to spread or compromise the system even before an infection is detected.

Inventive Principle:
Principle #9Preliminary anti-action

3Adaptability or versatility

If an infected host computer system is used to attack other network resources, then network penetration capability is improved, but network security is worsened

Engineering Contradiction:
Improvenetwork penetration capabilityVSAvoidnetwork attack capability
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system divides network communication into separate isolated channels: one channel allows sandboxed environments to access untrusted networks for legitimate purposes, while another channel maintains strict isolation from the trusted network. This segmentation prevents an infected sandboxed environment from penetrating into the trusted network or attacking other devices, as the network architecture itself blocks such lateral movement.

Inventive Principle:
Principle #1Segmentation

4Reliability

If network isolation is implemented using sandboxed computing environments and firewalls, then malware containment is improved, but device complexity increases

Engineering Contradiction:
Improvemalware containmentVSAvoidisolation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functional security components that perform multiple roles simultaneously. For example, border firewalls serve both as network traffic filters and as authorization devices that manage access control. Proxy devices function both as intermediaries for safe network access and as additional isolation layers. This multi-functionality reduces the overall number of separate components needed, thereby managing system complexity while maintaining strong malware containment capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11240207B2Network isolation
Publication Date: 2022.02.01 CROGA INNOVATIONS LTD
  • US11240207B2 patent drawing
  • US11240207B2 patent drawing
  • US11240207B2 patent drawing

AI summary

Methods and systems are disclosed for isolation of communications between a host computer system and one or more untrusted network destinations. An Internet isolation system may include a network, one or more host computer systems, a border firewall, an authorization device, and/or a proxy device. The Internet isolation system may be configured to implement network isolation between one or more untrusted network destinations, the one or more host computer systems, and/or the network. The network isolation may be implemented via one or more of a host-based firewall on each of the one or more host computer systems, the border firewall, the authorization device, the proxy device, an internal isolation firewall on each of the one or more host computer systems, and/or a segregation of a trusted memory space and an untrusted memory space on each of the one or more host computer systems.