Network Security Device Profile-Based Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet-connected devices often have unrestricted access to networks, leading to security vulnerabilities that can be exploited by malicious actors, as existing security devices treat all devices within a network segment uniformly without distinguishing between different types of devices, resulting in unnecessary exposure to risks such as firmware updates and peer-to-peer communications.

Innovation Solution

A security device that receives and analyzes data packets based on device profiles, determining whether forwarding is authorized by checking parameters such as ports, access permissions, and protocols, and blocking unauthorized packets to prevent malicious activities, while allowing authorized communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a security device treats all devices within a network segment uniformly without distinguishing between different types of devices, then device compatibility and ease of operation are improved, but network security and vulnerability protection deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network segment into multiple virtual network segments or zones based on device types, functions, or security requirements. Each segment has its own security policies and access rules, allowing the security device to treat different device groups differently while maintaining uniform treatment within each group. This resolves the contradiction by enabling differentiated security enforcement without complicating overall system operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning specific security attributes and policies to different device types, network zones, or packet characteristics. Instead of uniform security treatment, each local segment or device category receives customized security enforcement appropriate to its specific needs, thereby improving security without sacrificing ease of operation through automated profile-based management.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If a security device implements profile-based access control with multiple parameters, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal profile-based security framework that handles multiple security parameters, device types, and network zones through a single integrated system. The security device uses standardized profiles that can be applied across different contexts, reducing complexity by providing a unified approach rather than separate mechanisms for each security concern.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent manages complexity through parameter changes by dynamically adjusting security parameters based on device profiles, packet characteristics, and network conditions. The system automatically modifies security enforcement parameters without requiring manual configuration of each individual rule, thereby maintaining high security with reduced operational complexity.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If a security device blocks unauthorized data packets based on profile analysis, then network security is improved, but loss of information increases due to potential blocking of legitimate traffic

Engineering Contradiction:
Improvenetwork securityVSAvoidloss of information
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where the security device continuously monitors blocked and permitted traffic, analyzes patterns, and adjusts profile rules accordingly. This feedback loop enables the system to learn from actual network behavior, reducing false positives that block legitimate traffic while maintaining security against actual threats, thereby minimizing information loss.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary action by pre-configuring comprehensive device profiles that anticipate legitimate traffic patterns before they occur. By establishing allowed communication paths, ports, and protocols in advance based on device functionality and network policies, the system permits legitimate traffic to flow freely while only blocking truly unauthorized packets, thus reducing information loss.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230300111A1System and method for network-connected device security
Publication Date: 2023.09.21 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US20230300111A1 patent drawing
  • US20230300111A1 patent drawing
  • US20230300111A1 patent drawing

AI summary

Internet-connected devices are commonly used in various applications including home automation and industrial telemetry and control. Such devices may have relatively constrained needs for the various types of communications that are possible within the local network and with other devices on the internet, but the networks to which they are connected may nonetheless grant such devices unrestricted access. This may result in vulnerabilities that may be exploited by a malicious actor. As such, a system and method for providing security to internet-connected devices are provided.