Network Security Protection Proactive Threat Elimination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security protection solutions can only detect and block threats after they have occurred, failing to identify potential threats and actively mitigate them, thus lacking proactive security measures.
Innovation Solution
A network security protection method and apparatus that obtain network environment and threat detection data to search for and provide information, such as cleanup programs or file operation instructions, to eliminate security threats in hosts within a protected network, enabling proactive threat mitigation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security gateway with DPI processing is used, then known malicious programs can be blocked, but potential threats cannot be detected or eliminated proactively
Solution Approach 1:
The patent applies preliminary action by collecting host information (software versions, configurations, vulnerabilities) before threats occur, and proactively pushing cleanup programs to eliminate potential threats before they can be exploited. This shifts security from reactive blocking to proactive prevention by preparing and deploying countermeasures in advance.
Solution Approach 2:
The patent implements feedback by establishing a closed-loop system where the security server continuously collects host information, analyzes vulnerabilities, pushes appropriate cleanup programs, and monitors execution results. This feedback mechanism enables the system to adaptively improve threat detection and elimination based on actual network conditions and emerging threats.
2Reliability
If security gateway performs DPI processing on all traffic, then malicious programs can be identified, but response time is delayed until threats occur
Solution Approach 1:
The patent applies preliminary action by proactively pushing cleanup programs to hosts before threats materialize into actual attacks. By preparing remediation measures in advance and delivering them to endpoints, the system eliminates threats at their source before they can cause harm, rather than waiting to detect and block them after they occur.
Solution Approach 2:
The patent implements self-service by enabling hosts to automatically execute cleanup programs locally without requiring manual intervention or real-time gateway processing. The cleanup programs run autonomously on endpoint devices, allowing hosts to self-heal by removing vulnerabilities and malicious elements, thereby reducing response time and gateway processing burden.
3Reliability
If comprehensive threat detection is implemented, then security coverage is improved, but system complexity increases
Solution Approach 1:
The patent applies the extraction principle by separating complex threat analysis and cleanup program management functions from individual hosts and concentrating them in a centralized security server. The server collects host information, analyzes vulnerabilities, selects appropriate cleanup programs, and pushes them to endpoints. This centralization reduces complexity at distributed devices while maintaining comprehensive security coverage through coordinated centralized control.
Data Source
AI summary
A network security protection method is executed by a network security protection device and includes obtaining at least one of network environment data or threat detection data of a host that is in a protected network and that is connected to the network security protection device, where the network environment data includes an identifier of an operating system, a parameter of the operating system, an identifier of software with a network port access function, or a parameter of the software; and the threat detection data includes a threat type or a threat identifier, where the threat type includes a vulnerability or a malicious program; searching, according to the obtained at least one of network environment data or threat detection data, for corresponding information used to eliminate a security threat in the host; and sending the found information to the host.


