Network Security via Device Identifier Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems fail to effectively identify and prevent malicious network communications, as hackers and unauthorized users exploit vulnerabilities in network addresses and device identifiers to infiltrate corporate and government networks, leading to data breaches and undesirable actions.
Innovation Solution
The implementation of a system that evaluates network addresses and device identifiers against a list of trusted entities, using a white list to validate communications and apply varying levels of access based on trust levels, including the use of non-modifiable device identifiers and geographic location verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security systems are used to monitor and detect malicious communications, then network traffic can be analyzed, but unauthorized access and data breaches cannot be effectively prevented because hackers exploit vulnerabilities in network addresses and device identifiers
Solution Approach 1:
The system performs preliminary validation by maintaining a white list of trusted network addresses and device identifiers before allowing communications. By pre-establishing trusted entity records and checking incoming communications against this white list, the system prevents malicious communications from establishing connections, rather than merely detecting them after infiltration attempts occur.
Solution Approach 2:
The patent introduces an intermediary validation mechanism that sits between network communications and the target system. This intermediary layer evaluates incoming communications by comparing network addresses and device identifiers against the white list of trusted entities, acting as a mediator that allows legitimate communications while blocking unauthorized access attempts.
2Measurement precision
If network addresses and device identifiers are used to identify communications, then communication tracking is enabled, but hackers can exploit vulnerabilities in these identifiers to infiltrate networks
Solution Approach 1:
The system pre-establishes a white list containing validated network addresses and device identifiers of trusted entities before communications occur. By performing this validation preparation in advance, the system creates a reference framework that enables accurate identification of legitimate communications while making it difficult for hackers to exploit identifier vulnerabilities, as any deviation from the pre-validated list is automatically detected.
3Reliability
If a white list of trusted entities is implemented to validate communications, then unauthorized access is prevented, but system complexity increases due to multiple validation layers
Solution Approach 1:
The validation system is segmented into distinct functional components: a white list storage module that maintains trusted entity records, an evaluation module that performs the actual validation, and a communication control module that enforces access decisions. This segmentation allows each component to perform its specific function efficiently, reducing overall system complexity while maintaining high security standards.
Solution Approach 2:
The evaluation module serves multiple functions: it validates network addresses, verifies device identifiers, checks communication patterns, and makes access control decisions. By consolidating these multiple validation functions into a single universal module, the system reduces complexity compared to having separate dedicated systems for each validation task.
Data Source
AI summary
Techniques for network security are disclosed. In some implementations, an evaluation module determines whether a network communication from a computing device is allowable. The allowability of the communication is determined based on (1) whether the computing device is using an authorized source network address, and (2) whether a non-modifiable identifier of the computing device is authorized. The non-modifiable identifier is a fixed hardware identifier of the computing device, such as an identifier of a CPU, network interface card, storage device, or the like.


