Network Security Module Dynamic Port Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security systems, including anti-virus software and firewalls, are inadequate in protecting computing devices from sophisticated network attacks, particularly polymorphic exploits and vulnerabilities, as they require updates that can disrupt system operations and create new vulnerabilities, leading to a vulnerability window where systems are exposed to threats before patches are installed.
Innovation Solution
A network security system with a module that interposes between computing devices and the network, obtaining and implementing security information to dynamically control network activities based on the device's specific configuration, providing protective measures such as blocking unauthorized access and adapting security levels to mitigate threats before updates are available.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anti-virus software and firewalls are used to protect computing devices, then known exploits can be detected and blocked, but polymorphic and unknown exploits can propagate unchecked until software updates are installed
Solution Approach 1:
The system performs preliminary actions by proactively closing network ports and blocking network activities before exploits can take advantage of vulnerabilities. Security measures are implemented in advance based on vulnerability databases, so when unknown or polymorphic exploits attempt to propagate, the network pathways are already closed, preventing infection before it occurs.
Solution Approach 2:
The system dynamically adjusts security measures by continuously monitoring vulnerability databases and automatically updating network security configurations. Rather than static firewall rules, the system adapts its port blocking and network activity restrictions in real-time based on current vulnerability information, making it effective against both known and emerging threats.
2Reliability
If security updates and patches are installed to protect against vulnerabilities, then systems become more secure against known exploits, but system operations may be disrupted and new vulnerabilities may be introduced
Solution Approach 1:
The system extracts and implements only the essential security protective measures (port closing, network activity blocking) without requiring full security updates or patches. By separating the protective function from the update installation process, the system achieves security enhancement without the operational disruptions, compatibility issues, or potential new vulnerabilities that accompany comprehensive software updates.
Solution Approach 2:
The system applies preliminary anti-action by blocking network pathways before exploits can exploit vulnerabilities. Rather than waiting for patches to fix vulnerabilities, the system proactively prevents exploit execution by closing ports and restricting network activities, thereby achieving security protection without requiring system updates that could disrupt operations.
3Reliability
If network security measures are implemented to block all network activities, then protection against exploits is enhanced, but legitimate network operations are also blocked
Solution Approach 1:
The system applies local quality by implementing security measures selectively at specific network ports and protocols that are vulnerable to exploits, rather than blocking all network activities uniformly. Trusted applications and processes are allowed to communicate through otherwise blocked ports, maintaining network accessibility for legitimate operations while preventing exploit propagation through vulnerable pathways.
Solution Approach 2:
The system uses feedback mechanisms to monitor network traffic and distinguish between legitimate and malicious activities. By continuously analyzing network patterns and comparing them against vulnerability information, the system dynamically adjusts its blocking rules to maintain security while allowing legitimate network operations to proceed uninterrupted.
Data Source
AI summary
A network security system for protecting computing devices connected to a communication network from identified security threats is presented. A security service published security information intended for network security modules in the communication network. A network security module is interposed, either logically or physically, between a computer and the communication network. The security information comprises security measures which, when implemented by a network security module, protect the corresponding computer from an identified security threat to the computer.


