Network Security via Redirection to Mock Computing System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are inadequate in detecting and preventing malicious network communications, as hackers and unauthorized users can penetrate corporate and government networks, stealing information and installing malicious software, often exploiting security holes in publicly accessible computers.

Innovation Solution

The system evaluates network communications by comparing them to allowable properties represented in a white list, redirecting questionable communications to a mock computing system that simulates the destination, using device identifiers and network addresses to authenticate and authorize communications, and employing a combination of hardware and software components to enforce security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security systems are used to monitor and block malicious communications, then network security is maintained, but hackers can still penetrate networks through security holes in publicly accessible computers

Engineering Contradiction:
Improvenetwork securityVSAvoidmalicious communications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a mock computing system as an intermediary between the questionable computing device and the destination computing system. This intermediary receives redirected communications, simulates the destination system's behavior, and allows security evaluation without exposing the real destination system to potential attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary evaluation of network communications by redirecting them to a mock computing system before allowing access to the actual destination. This preliminary action enables security assessment of device identifiers and communication patterns without risking the real system

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network communications are redirected to a mock computing system for evaluation, then malicious communications are detected and prevented, but network traffic is diverted from its intended destination

Engineering Contradiction:
Improvedetection of malicious communicationsVSAvoidnetwork traffic flow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mock computing system serves as a mediator that receives redirected traffic, evaluates it, and can forward legitimate communications to the actual destination while blocking malicious ones. This maintains proper traffic flow for legitimate users while enabling security evaluation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy or simulation of the destination computing system (the mock computing system) that replicates the destination's behavior and interface. This copy allows traffic to be redirected for evaluation while the real destination remains protected and accessible through the mock system

Inventive Principle:
Principle #26Copying

3Reliability

If device identifiers and network addresses are used to authenticate communications, then unauthorized access is prevented, but the complexity of authentication mechanisms increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses universal identifiers (device identifiers and network addresses) that are already present in standard network communications. These existing identifiers serve multiple functions: device identification, location tracking, and authentication, without requiring additional complex authentication mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10542006B2Network security based on redirection of questionable network access
Publication Date: 2020.01.21 CHIEN DANIEL
  • US10542006B2 patent drawing
  • US10542006B2 patent drawing
  • US10542006B2 patent drawing

AI summary

Techniques for network security are disclosed. In some implementations, an evaluation module determines whether a network communication from a source computing system to a destination computing system is allowable. The allowability of the communication is determined based properties of the network communication, such as a source or destination address, a port number, a time of day, a geographic location, and the like. If the communication is disallowed, the evaluation module or a related component redirects the communication to an alternative computing system that masquerades as the destination communication system.