Network Virus Control via Quarantine Sub-Network Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network virus control methods, such as quarantining devices in a remediation VLAN, are inefficient as they allow virus spread and reduce user productivity, as devices cannot access the rest of the network during quarantine.

Innovation Solution

A virus control server that assigns devices to a unique quarantine sub-network upon specific events, such as connection or reconnection to the network, ensuring all traffic passes through it, and releases devices when verified virus-free, allowing partial network access and reassigning IP addresses and sub-networks for quarantine status changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are quarantined in a remediation VLAN, then virus spread is prevented, but user productivity is dramatically reduced due to inability to access the network

Engineering Contradiction:
Improvevirus preventionVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The network is segmented into multiple VLANs including a remediation VLAN and a productivity VLAN. Devices undergoing remediation are assigned to the remediation VLAN where virus scanning occurs, while simultaneously maintaining connectivity to the productivity VLAN for continued work. This segmentation allows isolation of infected devices from the main network while preserving user access to necessary network resources.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If all network traffic passes through the virus control server during quarantine, then virus detection capability is improved, but network performance is reduced

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The virus control server acts as an intermediary for traffic between the remediation VLAN and other network segments. It performs deep packet inspection and virus scanning on traffic passing through it, while allowing optimized routing for traffic that does not require scanning. The server mediates between security requirements and performance needs by selectively applying inspection only where necessary.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If devices are immediately connected to the network upon joining, then user productivity is maintained, but vulnerability to virus introduction increases

Engineering Contradiction:
Improveuser productivityVSAvoidvirus vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Devices are automatically assigned to the remediation VLAN upon joining the network, before any full network access is granted. This preliminary action ensures that devices undergo virus scanning and remediation in an isolated environment before being moved to the main network. The system performs preliminary security checks proactively, preventing potential virus introduction while maintaining seamless user experience.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8245294B1Network based virus control
Publication Date: 2012.08.14 AVAYA INC
  • US8245294B1 patent drawing
  • US8245294B1 patent drawing
  • US8245294B1 patent drawing

AI summary

The present application relates to virus control in a network. An illustrative embodiment provides a network including a plurality of processing devices and at least one virus control server configured to quarantine a selected processing device from the network by assigning the selected processing device to a unique quarantine sub-network upon the occurrence of a first quarantine event such that all network traffic to and from the selected device must pass through the virus control server.