Network Security System Identifying Subversion Attempts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems struggle to effectively identify and respond to attempts by users to subvert security walls within an enterprise environment, particularly in cases where users attempt to bypass blocks by using alternative methods over time.
Innovation Solution
A network security system that monitors and assesses network activity to identify indicators of suspicious behavior, such as changes in user behavior over time, and triggers security rules to block and alert on potential security threats. The system differentiates between nefarious attempts and benign actions by considering sensitivity levels and timing of network activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the network security system implements strict security rules to block malicious activity, then network security is improved, but false positives blocking benign user actions increase
Solution Approach 1:
The system performs preliminary actions by blocking suspicious network activity and then proactively monitors for alternative subversion attempts within a defined time window. This preliminary blocking followed by targeted monitoring allows the system to catch repeat offenders while minimizing false positives on legitimate users who simply need assistance with their blocked actions.
Solution Approach 2:
The system implements feedback by continuously monitoring network activity following an initial block to detect patterns of repeated subversion attempts. This feedback loop allows the system to differentiate between malicious users who persistently attempt to bypass security walls and benign users who may have legitimate needs but were blocked due to security policies.
2Difficulty of detecting and measuring
If the network security system monitors all network activity to identify subversion attempts, then detection capability is improved, but system complexity increases
Solution Approach 1:
The system applies local quality by implementing targeted monitoring only for specific user activities that occur within a defined time window after a security wall is triggered. Instead of uniformly monitoring all network activity, the system focuses computational resources on detecting repeated subversion attempts by the same user, thereby reducing overall system complexity while maintaining high detection capability for malicious behavior.
3Speed
If the network security system responds immediately to blocked activity by blocking the user account, then security response speed is improved, but loss of legitimate user productivity increases
Solution Approach 1:
The system implements dynamic response by adjusting the severity of security measures based on the user's behavior pattern. Instead of immediately blocking legitimate user accounts, the system dynamically monitors for repeated subversion attempts and only escalates to account blocking when a pattern of malicious behavior is confirmed within the monitoring window. This dynamic approach maintains fast security response while preserving user productivity for legitimate activities.
Data Source
AI summary
Disclosed are techniques for monitoring and identifying attempts to subvert a security wall within a network infrastructure. A method can include receiving, by a network security system monitoring and protecting the network infrastructure, network activity for the network infrastructure, determining whether the network activity triggers at least one security event rule, blocking the network activity when the network activity triggers the rule, determining a sensitivity level associated with the network activity, starting a timer based on the sensitivity level satisfying a threshold level of sensitivity, continuously monitoring subsequent network activity until the timer expires, determining whether the subsequent network activity triggers one or more security event rules before the timer expires, associating the blocked network activity with the subsequent network activity if the subsequent network activity triggers the rules, and generating an alert indicating the associated network activity as an attempt to subvert a security wall within the network infrastructure.


