Network Security Module for Exploit Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security measures, such as anti-virus software and firewalls, are inadequate in protecting against unknown computer exploits and do not adapt to individual computing devices' needs, leading to a vulnerability window where systems are exposed to attacks until updates are installed, and they can disrupt system operations.

Innovation Solution

A network security module is interposed between computing devices and networks to dynamically control network access based on specific security information, implementing protective measures such as blocking unauthorized communications and adapting to the device's configuration, even before updates are installed, using a security service to obtain and enforce security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus software and firewalls are used to protect computing devices, then known computer exploits can be detected and blocked, but unknown exploits propagate unchecked until updates are installed

Engineering Contradiction:
Improveprotection against known exploitsVSAvoidability to protect against unknown exploits
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network security module performs preliminary analysis of incoming network communications before they reach the computing device. By examining communication patterns, protocols, and behaviors in advance, the system can identify and block potential exploits including unknown ones, rather than relying solely on signature-based detection that only works for known threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network security module acts as an intermediary component positioned between the computing device and the network. This intermediate position allows it to inspect, analyze, and control all network communications passing through it, enabling the system to detect and block exploits at the network level before they can infect the computing device, regardless of whether the exploits are known or unknown.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security updates are installed to protect against new exploits, then protection is improved, but system operations may be disrupted during the update process

Engineering Contradiction:
Improveprotection level against new exploitsVSAvoidsystem operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The network security module implements security measures in advance by continuously monitoring and controlling network communications. This ongoing preliminary protection eliminates the need for periodic system updates that would disrupt operations, as the security module maintains continuous protection without requiring the computing device to be taken offline.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network security module operates autonomously to provide continuous security protection. It independently analyzes network communications, makes security decisions, and blocks threats without requiring manual intervention or system updates, thereby maintaining both high protection levels and continuous system operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If firewalls are configured to block unauthorized access, then security is improved, but configuration complexity increases and requires sophisticated setup

Engineering Contradiction:
Improveunauthorized access blockingVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network security module automatically performs security analysis and decision-making functions. It independently examines incoming network communications, identifies potential threats based on behavior and patterns, and takes appropriate blocking actions without requiring complex manual configuration, thereby simplifying the system while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network security module dynamically adjusts security parameters and control strategies based on real-time analysis of network communications. Rather than relying on static, pre-configured firewall rules that require sophisticated setup, the system adapts its security measures to the specific characteristics of each communication, automatically optimizing protection without complex configuration.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If network security monitoring is implemented to detect exploits, then detection capability is improved, but processing time and system resources increase

Engineering Contradiction:
Improveexploit detection accuracyVSAvoidcommunication processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The network security module extracts and analyzes only the critical security-relevant features of incoming network communications, such as protocol patterns, data flow characteristics, and behavioral indicators. By focusing on these key parameters rather than examining every byte of data in detail, the system achieves high detection accuracy while minimizing processing time and resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7716726B2System and method for protecting a computing device from computer exploits delivered over a networked environment in a secured communication
Publication Date: 2010.05.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7716726B2 patent drawing
  • US7716726B2 patent drawing
  • US7716726B2 patent drawing

AI summary

A network security module for protecting computing devices connected to a communication network from identified security threats communicated in a secured communication is presented. The network security module is interposed, either logically or physically, between the protected computer and the communication network. Upon detecting a secured communication, the network security module obtains a decryption key from the computing device to decrypt the secured communication. The network security module then processes the decrypted communication according to whether the decrypted communication violates protective security measures implemented by the network security module.