Network Security Module Dynamic Port Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems, including anti-virus software and firewalls, are inadequate in protecting computing devices from sophisticated network attacks, particularly polymorphic exploits and vulnerabilities, as they require updates that can disrupt system operations and create new vulnerabilities, leading to a vulnerability window where systems are exposed to threats before patches are installed.

Innovation Solution

A network security system with a module that interposes between computing devices and the network, obtaining and implementing security information to dynamically control network activities based on the device's specific configuration, providing protective measures such as blocking unauthorized access and adapting security levels to mitigate threats before updates are available.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus software and firewalls are used to protect computing devices, then known exploits can be detected and blocked, but polymorphic and unknown exploits can propagate unchecked until software updates are installed

Engineering Contradiction:
Improvesecurity protectionVSAvoidability to detect unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by proactively closing network ports and blocking network activities before exploits can take advantage of vulnerabilities. Security measures are implemented in advance based on vulnerability databases, so when unknown or polymorphic exploits attempt to propagate, the network pathways are already closed, preventing infection before it occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts security measures by continuously monitoring vulnerability databases and automatically updating network security configurations. Rather than static firewall rules, the system adapts its port blocking and network activity restrictions in real-time based on current vulnerability information, making it effective against both known and emerging threats.

Inventive Principle:
Principle #15Dynamics

2Reliability

If security updates and patches are installed to protect against vulnerabilities, then systems become more secure against known exploits, but system operations may be disrupted and new vulnerabilities may be introduced

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts and implements only the essential security protective measures (port closing, network activity blocking) without requiring full security updates or patches. By separating the protective function from the update installation process, the system achieves security enhancement without the operational disruptions, compatibility issues, or potential new vulnerabilities that accompany comprehensive software updates.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies preliminary anti-action by blocking network pathways before exploits can exploit vulnerabilities. Rather than waiting for patches to fix vulnerabilities, the system proactively prevents exploit execution by closing ports and restricting network activities, thereby achieving security protection without requiring system updates that could disrupt operations.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If network security measures are implemented to block all network activities, then protection against exploits is enhanced, but legitimate network operations are also blocked

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies local quality by implementing security measures selectively at specific network ports and protocols that are vulnerable to exploits, rather than blocking all network activities uniformly. Trusted applications and processes are allowed to communicate through otherwise blocked ports, maintaining network accessibility for legitimate operations while preventing exploit propagation through vulnerable pathways.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses feedback mechanisms to monitor network traffic and distinguish between legitimate and malicious activities. By continuously analyzing network patterns and comparing them against vulnerability information, the system dynamically adjusts its blocking rules to maintain security while allowing legitimate network operations to proceed uninterrupted.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7814543B2System and method for securing a computer system connected to a network from attacks
Publication Date: 2010.10.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7814543B2 patent drawing
  • US7814543B2 patent drawing
  • US7814543B2 patent drawing

AI summary

A network security system for protecting computing devices connected to a communication network from identified security threats is presented. A security service published security information intended for network security modules in the communication network. A network security module is interposed, either logically or physically, between a computer and the communication network. The security information comprises security measures which, when implemented by a network security module, protect the corresponding computer from an identified security threat to the computer.