Network Security Appliance for Dynamic Firewall Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewalls in home and small business networks are inadequate due to static configurations, poor user interfaces, and lack of robust protection, making them vulnerable to data loss and cyber attacks, as they are difficult for non-technical users to manage and maintain, and often leave security gaps due to loose settings and limited visibility into network traffic.

Innovation Solution

A computer security device that intercepts all traffic between a LAN and WAN, using a hardware element to monitor and analyze data, block or modify suspicious communications, and provide remote access for updating threat definitions, while remaining undetectable from the outside world, with a single appliance positioned between the firewall and WAN, featuring a data transport module, data storage module, and management information module to manage and visualize network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If static firewall settings are used, then device complexity is reduced, but security protection deteriorates

Engineering Contradiction:
Improvefirewall configuration complexityVSAvoidsecurity protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic firewall settings that automatically adjust based on monitored network traffic patterns. The system learns normal traffic behavior and dynamically modifies firewall rules to allow or block traffic accordingly, eliminating the need for manual static configuration while maintaining strong security protection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The firewall system performs self-configuration by automatically monitoring network traffic, learning patterns, and adjusting its own rules without user intervention. This self-service capability resolves the contradiction by providing both simplicity (no manual configuration needed) and reliability (adaptive security).

Inventive Principle:
Principle #25Self-service

2Ease of operation

If firewall settings are made loose to allow multiple activities, then ease of operation is improved, but security protection deteriorates

Engineering Contradiction:
Improveuser interface simplicityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system automatically monitors and learns traffic patterns, then self-adjusts firewall rules without requiring user configuration. This provides ease of operation (simple interface) while maintaining security protection through automated adaptive rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic and uses this feedback to dynamically adjust firewall settings. This closed-loop approach ensures security protection is maintained while keeping the user interface simple, as the system automatically responds to changing conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11201883B2System, method, and apparatus for data loss prevention
Publication Date: 2021.12.14 SECULORE ACQUISITION LLC
  • US11201883B2 patent drawing
  • US11201883B2 patent drawing
  • US11201883B2 patent drawing

AI summary

Disclosed is a computer security device configured to monitor data traffic between computing devices on a local area network and an external network in order to protect the local area network against unauthorized access and data exfiltration. Such computer security device includes each of a data transport module, a management information module, and a data storage module, each of which are operable independently of the other modules, but which modules together form the single computer security device. The computer security device is configured for connection between a router on a local network that is to be protected and a wide area network, such as the Internet, which such local network communicates with. The computer security device monitors data traffic, collecting it for analysis and data visualization, creating alerts upon detection of potentially dangerous communications, and blocking, redirecting, or replacing such data with corrupted data or predetermined innocuous information in a similar format to the original data. Methods of using such a computer security device are also disclosed.