Remote Access Service Inspector Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional corporate firewall technologies are inadequate in protecting networks from remote attacks and virus infections, especially when devices connected through VPNs, as they do not provide protection against intrusions from remote devices and can spread viruses to other machines on the network.
Innovation Solution
The RAS Inspector system performs a series of inspections on remote access clients, including digital hash comparisons, live updates of virus definitions, validation of anti-virus software, and checks for operating system patches, before allowing access to a VPN, ensuring that only compliant devices connect to the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall products are used to regulate traffic between physical networks, then access control based on rules is improved, but protection against remote device intrusions and virus spread is insufficient
Solution Approach 1:
The patent segments the network access control into multiple layers: traditional firewall rules for basic traffic control, and a new inspection mechanism that segments devices into quarantined and non-quarantined states based on security compliance. This allows the system to maintain basic firewall functionality while adding specialized protection for remote devices.
Solution Approach 2:
The patent introduces an intermediary inspection mechanism between the traditional firewall and network access. This intermediary layer performs security checks, virus scanning, and compliance verification on remote devices before allowing full network access, thereby extending protection coverage without replacing existing firewall functionality.
2Adaptability or versatility
If remote devices are allowed to connect to the corporate network through VPN, then remote access capability is improved, but the risk of virus infection and unauthorized access increases
Solution Approach 1:
The patent implements preliminary security actions before granting full network access. Remote devices must undergo inspection, virus scanning, and compliance verification while in a quarantined state. Only after passing these preliminary security checks are devices allowed to access the full corporate network, thereby enabling remote access while mitigating virus risks.
Solution Approach 2:
The patent applies preliminary anti-action by implementing a quarantine mechanism that prevents potentially harmful remote devices from accessing the network until they prove secure. The system proactively blocks access for uninspected devices and only removes restrictions after verifying security compliance, countering potential threats before they can affect the network.
3Reliability
If anti-virus applications are installed on all machines, then protection against virus infiltration is improved, but the complexity of ensuring current virus definitions across all devices increases
Solution Approach 1:
The patent implements a feedback mechanism where the inspection system continuously monitors remote devices for security compliance, including virus definition currency. The system provides feedback to devices about their compliance status and can enforce remediation actions. This centralized feedback approach simplifies the management complexity by providing automated monitoring and reporting rather than requiring manual tracking of each device.
Solution Approach 2:
The patent enables self-service by requiring remote devices to automatically perform security self-assessments, virus scans, and compliance verifications as part of the quarantine inspection process. Devices must demonstrate their own security posture without requiring manual intervention from administrators, thereby reducing management complexity while maintaining high virus protection standards.
4Reliability
If inspection mechanisms are implemented to ensure device security before network access, then network security is improved, but the time required for remote access establishment increases
Solution Approach 1:
The patent implements periodic action by conducting security inspections in structured phases during the quarantine period. Rather than requiring a single lengthy inspection before access, the system performs security checks at periodic intervals throughout the quarantine state, allowing devices to progressively demonstrate compliance. This phased approach balances security verification with reasonable access establishment time.
Data Source
AI summary
A method, system, and computer program product for providing protected remote access from a remote access client to a remote access server over a computer network through a plurality of inspections. A remote access configuration file is created for the remote access client. A digital hash of the configuration file is then generated. The digital hash is compared with a configuration file stored at a predefined web location. If the comparison results in a match between the digital hash and the stored configuration file, a digital hash comparison is performed between an encrypted remote access configuration file and an encrypted configuration file stored at the predefined web location. If the plurality of inspections are passed, the remote access client is released from a quarantine state and a virtual private network (VPN) connection to the remote access server is established.


