Network Traffic Controller for Closed OS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Closed operating systems, such as those used in mobile devices, restrict applications from controlling machine-level network traffic, making it difficult to tune or secure network behavior, which can lead to unauthorized data leaks due to compromised applications.

Innovation Solution

A system and method that identifies applications on closed operating systems, determines their expected network behavior, intercepts and analyzes network traffic, and modifies it to conform to that behavior by blocking or redirecting traffic that does not match the expected patterns, thereby enhancing security and control over application network interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If closed operating systems are used to ensure system stability and security, then system reliability is improved, but application-level network traffic control capability deteriorates

Engineering Contradiction:
Improvesystem stabilityVSAvoidapplication network traffic control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a network traffic controller as an intermediary component that operates within the closed operating system to enable application-level network traffic control. This controller intercepts network packets at the socket level and applies security policies without requiring changes to the underlying closed operating system architecture, thus maintaining system stability while adding traffic control capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network traffic control functionality into separate, manageable components including packet interceptors, policy evaluators, and traffic modifiers. This segmentation allows the system to maintain the integrity of the closed operating system while adding modular network control capabilities that can be independently managed and updated.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traffic control software is deployed to control network traffic, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network traffic controller is designed as a universal component that handles multiple security functions including packet inspection, policy enforcement, and traffic modification through a single integrated system. This multi-functionality reduces overall system complexity compared to deploying separate specialized security tools for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs automated policy evaluation and enforcement mechanisms that operate without requiring manual intervention for each network transaction. The traffic controller automatically evaluates packets against security policies and applies appropriate actions, reducing the operational complexity of managing network security.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If applications are allowed to control machine-level network traffic to enhance security tuning, then network behavior control is improved, but system reliability deteriorates due to potential security vulnerabilities

Engineering Contradiction:
Improvenetwork behavior controlVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network traffic controller serves as a trusted intermediary between applications and the network stack, mediating all network traffic. This approach allows applications to benefit from fine-grained traffic control while the intermediary enforces security policies, preventing compromised applications from directly accessing and potentially compromising the network stack.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements preliminary security checks and policy evaluations on network packets before they are processed by applications or sent to the network. This preliminary anti-action prevents potentially malicious traffic from reaching applications, thereby maintaining system security while still allowing legitimate traffic control operations.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11005867B1Systems and methods for tuning application network behavior
Publication Date: 2021.05.11 CA TECH INC
  • US11005867B1 patent drawing
  • US11005867B1 patent drawing
  • US11005867B1 patent drawing

AI summary

The disclosed computer-implemented method for tuning application network behavior may include identifying an application for a closed operating system. The closed operating system may prevent applications from implementing machine-level traffic control for network traffic. The method may include determining an expected network behavior of the application, intercepting network traffic of the application on the closed operating system, determining whether the intercepted network traffic conforms to the expected network behavior, and modifying, based on the determining whether the intercepted network traffic conforms to the expected network behavior, the network traffic. Various other methods, systems, and computer-readable media are also disclosed.