Outbound Network Traffic Filtering by User Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures fail to effectively restrict external access from pivoting to other internal network components, as they lack the ability to filter outbound network traffic based on user identity, leading to potential unauthorized access.
Innovation Solution
A containment system that filters outbound network traffic based on user account information, using rules to determine whether to block or allow traffic, thereby confining users to a single server and preventing access to other network components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall capabilities are used to restrict network access, then basic network security is maintained, but the ability to prevent pivot attacks and isolate users to single servers is insufficient
Solution Approach 1:
The patent segments network traffic filtering by user account, creating distinct filtering contexts for different users. The system divides outbound traffic into separate streams based on user identity, applying specific rules to each user's traffic independently. This segmentation enables the containment of users to specific network scopes and prevents lateral movement between servers.
Solution Approach 2:
Instead of filtering inbound traffic as traditional firewalls do, the patent inverts the approach by filtering outbound traffic generated by authenticated users. This inversion allows the system to control what authenticated users can access after they have been granted initial access, effectively preventing pivot attacks by blocking outbound connections to unauthorized targets.
2Ease of operation
If external vendors are granted access to internal network components for software updates, then software maintenance is enabled, but the risk of unauthorized access to other internal components increases
Solution Approach 1:
The patent applies preliminary filtering rules to outbound traffic before it leaves the authenticated user's system. By pre-configuring containment rules that limit outbound traffic destinations based on user identity, the system proactively prevents access to unauthorized internal components before the vendor can attempt to pivot to other servers.
Solution Approach 2:
The patent introduces an intermediary filtering mechanism that sits between the authenticated user and the internal network components. This intermediary evaluates outbound traffic against user-specific rules and blocks connections to unauthorized targets, acting as a mediator that allows necessary software updates while preventing unauthorized access attempts.
3Reliability
If user-based outbound traffic filtering is implemented to prevent pivot attacks, then network security is enhanced, but system complexity increases
Solution Approach 1:
The patent implements a universal filtering mechanism that handles multiple security functions through a single system. The same user-based filtering infrastructure that contains outbound traffic also provides authentication integration, rule management, and pivot attack prevention, eliminating the need for separate complex systems for each function.
Solution Approach 2:
The system automatically obtains user account information from authentication mechanisms and applies appropriate filtering rules without requiring manual configuration for each user. The filtering system self-configures based on user identity, reducing administrative overhead and system complexity while maintaining security.
Data Source
AI summary
Obtaining, in association with origination of outbound network traffic to be sent by a system, user account information of a user account on behalf of which the outbound network traffic is generated, and performing filtering of the outbound network traffic based on the obtained user account information of the user account on behalf of which the outbound network traffic is generated, where the filtering is further based on one or more rules, and the filtering includes determining whether to block or allow sending of the outbound network traffic from the system.


