Network Security Device Selective Protection Strategy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems are computationally expensive and incur significant bandwidth overhead, especially when handling large volumes of data, and often route unnecessary traffic through security devices, which can be inefficient.

Innovation Solution

A network security device selectively protects private network devices by categorizing them based on their computational capabilities and network traffic volumes, using techniques like ARP spoofing to intercept and filter data only for devices that need it, thereby reducing computational and bandwidth burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all private network devices are protected by the network security device, then security coverage is improved, but computational overhead and bandwidth consumption increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments private network devices into three categories (first, second, and third groups) based on their security requirements and characteristics. The network security device applies different protection strategies to each group, with the first group receiving full protection while the third group receives minimal or no protection, thereby reducing overall computational overhead while maintaining adequate security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying differentiated security protection levels to different devices based on their specific characteristics and risk profiles. Instead of uniform protection, each device group receives tailored security measures appropriate to its needs, optimizing the balance between security effectiveness and resource consumption.

Inventive Principle:
Principle #3Local quality

2Reliability

If all private network devices are protected by the network security device, then security coverage is improved, but bandwidth consumption increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments private network devices into three categories (first, second, and third groups) based on their security requirements and characteristics. The network security device applies different protection strategies to each group, with the first group receiving full protection while the third group receives minimal or no protection, thereby reducing overall bandwidth consumption while maintaining adequate security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by providing full security protection only to the first group of devices that require it most, while applying reduced or no protection to the second and third groups. This partial protection approach avoids the excessive bandwidth consumption that would result from protecting all devices uniformly, while still maintaining adequate security for the most vulnerable devices.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If network traffic is routed through the security device for inspection, then threat detection capability is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments network traffic into different categories corresponding to the three device groups. Traffic destined for first group devices is routed through the network security device for thorough inspection, while traffic for second and third group devices is handled more efficiently with reduced inspection, thereby reducing overall processing time while maintaining high threat detection capability for critical devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing comprehensive threat detection only on traffic destined for the first group of devices, while applying reduced or no detection to traffic for other groups. This selective approach reduces processing time and computational resource consumption while maintaining adequate threat detection capability where it is most needed.

Inventive Principle:
Principle #16Partial or excessive action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach reduces the computational and bandwidth overhead by only protecting devices that require it, enhancing efficiency in detecting and mitigating threats while minimizing unnecessary traffic routing.

Implementation Method 1

This is achieved in one example by using Address Resolution Protocol (ARP) spoofing, by which the security device associates its own MAC address with the IP address of a different device that is a target of communication.

Methodology Applied
Scientific EffectARP spoofing:

Data Source

PatentUS11316861B2Automatic device selection for private network security
Publication Date: 2022.04.26 GEN DIGITAL INC
  • US11316861B2 patent drawing
  • US11316861B2 patent drawing
  • US11316861B2 patent drawing

AI summary

A method of selecting devices on a private network for security protection via a network security device comprises classifying devices on the private network into devices that are sometimes protected and devices that are always either protected or not protected. Threats are monitored, the threats comprising at least one of a macro security event and a local security event, the macro security event detected by one or more external systems and the local security event detected by one or more devices local to the private network. When a threat is detected, it is determined whether the detected threat is a threat to one or more devices on the private network classified as devices that are sometimes protected, and if the detected threat is determined to be a threat to the one or more devices that are sometimes protected the one or more devices are protected.