Proactive Intrusion Protection System for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion protection systems are ineffective in proactively preventing communications with compromising entities, leading to vulnerabilities in digital telecommunication networks and remote devices, which can result in account intrusions, identity theft, and other malicious activities.

Innovation Solution

A proactive network intrusion protection system that identifies incoming and outgoing communications initiated by remote devices, determines if they are from compromising entities, and sends alerts or blocks communications in real-time to prevent potential threats, using secure communication protocols and data transformation to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time communication monitoring and blocking is implemented, then intrusion prevention capability is improved, but network traffic and processing demands increase

Engineering Contradiction:
Improveintrusion prevention capabilityVSAvoidnetwork traffic and processing demands
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by maintaining a pre-populated database of compromising entities and their identifiers. Before monitoring incoming communications, the system has already prepared the threat intelligence data, enabling rapid comparison and blocking decisions without requiring extensive real-time processing of threat databases.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts only the essential identifying information from communications (such as phone numbers, email addresses, or device identifiers) and compares these extracted elements against the compromising entities database. This selective extraction approach avoids processing entire communication contents, thereby reducing network traffic and processing demands while maintaining effective intrusion detection.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If comprehensive communication analysis is performed to identify compromising entities, then detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces complex mechanical analysis of communication contents with a streamlined information-based approach. Instead of analyzing the substance of communications, the system substitutes this with comparison of identifying elements (metadata, headers, contact information) against the compromising entities database. This substitution maintains high detection accuracy while dramatically reducing processing time and computational resource requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If proactive blocking signals are sent to remote devices, then security protection is improved, but network communication overhead increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork communication overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system extracts and transmits only the essential blocking signal information to remote devices - specifically the identifiers of compromising entities to be blocked. This minimal information extraction approach provides comprehensive security protection while minimizing network communication overhead, as only critical blocking data is transmitted rather than extensive security policies or full threat intelligence datasets.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10447722B2Proactive intrusion protection system
Publication Date: 2019.10.15 BANK OF AMERICA CORP
  • US10447722B2 patent drawing
  • US10447722B2 patent drawing
  • US10447722B2 patent drawing

AI summary

An application associated with a remote device executes logic to receive, from a remote system, data identifying a plurality of compromising entities, identify an incoming communication initiated by the remote device, and identify information regarding a source of the incoming communication. Additionally, the logic determines an entity associated with the source of the incoming communication and determines that the entity associated with the source matches at least one of the plurality of compromising entities based on comparing the data identifying the plurality of compromising entities and the entity associated with the source of the incoming communication. In addition, the logic generates a signal configured to block the incoming communication.