Outbound Network Traffic Filtering by User Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures fail to effectively restrict external access from pivoting to other internal network components, as they lack the ability to filter outbound network traffic based on user identity, leading to potential unauthorized access.

Innovation Solution

A containment system that filters outbound network traffic based on user account information, using rules to determine whether to block or allow traffic, thereby confining users to a single server and preventing access to other network components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall capabilities are used to restrict network access, then basic network security is maintained, but the ability to prevent pivot attacks and isolate users to single servers is insufficient

Engineering Contradiction:
Improvenetwork securityVSAvoiduser-based traffic filtering capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments network traffic filtering by user account, creating distinct filtering contexts for different users. The system divides outbound traffic into separate streams based on user identity, applying specific rules to each user's traffic independently. This segmentation enables the containment of users to specific network scopes and prevents lateral movement between servers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of filtering inbound traffic as traditional firewalls do, the patent inverts the approach by filtering outbound traffic generated by authenticated users. This inversion allows the system to control what authenticated users can access after they have been granted initial access, effectively preventing pivot attacks by blocking outbound connections to unauthorized targets.

Inventive Principle:
Principle #13The other way round (Inversion)

2Ease of operation

If external vendors are granted access to internal network components for software updates, then software maintenance is enabled, but the risk of unauthorized access to other internal components increases

Engineering Contradiction:
Improvesoftware update capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary filtering rules to outbound traffic before it leaves the authenticated user's system. By pre-configuring containment rules that limit outbound traffic destinations based on user identity, the system proactively prevents access to unauthorized internal components before the vendor can attempt to pivot to other servers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary filtering mechanism that sits between the authenticated user and the internal network components. This intermediary evaluates outbound traffic against user-specific rules and blocks connections to unauthorized targets, acting as a mediator that allows necessary software updates while preventing unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If user-based outbound traffic filtering is implemented to prevent pivot attacks, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidfiltering system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal filtering mechanism that handles multiple security functions through a single system. The same user-based filtering infrastructure that contains outbound traffic also provides authentication integration, rule management, and pivot attack prevention, eliminating the need for separate complex systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically obtains user account information from authentication mechanisms and applies appropriate filtering rules without requiring manual configuration for each user. The filtering system self-configures based on user identity, reducing administrative overhead and system complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10523635B2Filtering outbound network traffic
Publication Date: 2019.12.31 ASSURED INFORMATION SECURITY
  • US10523635B2 patent drawing
  • US10523635B2 patent drawing
  • US10523635B2 patent drawing

AI summary

Obtaining, in association with origination of outbound network traffic to be sent by a system, user account information of a user account on behalf of which the outbound network traffic is generated, and performing filtering of the outbound network traffic based on the obtained user account information of the user account on behalf of which the outbound network traffic is generated, where the filtering is further based on one or more rules, and the filtering includes determining whether to block or allow sending of the outbound network traffic from the system.