Sandbox-Based Internet Isolation for Untrusted Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to effectively isolate and secure host computer systems from malware threats when connected to untrusted networks, leading to potential security losses, efficiency reductions, and compromised user privacy, as malware can spread and use infected systems to attack other network resources undetected.
Innovation Solution
A sandbox-based internet isolation system is implemented, using a host computer system with a processor and memory configured to operate a first firewall and two memory spaces: a workspace for trusted applications and a sandboxed computing environment for untrusted Internet access, where the sandbox container process segregates and restricts data communication between the two spaces without explicit user input, and a VPN client for secure communication with trusted networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the host computer system connects to an untrusted LAN to access Internet resources, then network connectivity and resource access are improved, but security risks and malware exposure increase
Solution Approach 1:
The system segments the host computer system into a trusted workspace and an untrusted sandboxed computing environment. The sandbox container process creates separate memory spaces that isolate untrusted Internet browsing activities from the trusted workspace, allowing network connectivity while preventing malware from spreading to the workspace.
Solution Approach 2:
The sandbox container process acts as an intermediary between the untrusted Internet resources and the trusted workspace. It mediates all communications by routing untrusted traffic through the sandboxed browser process while blocking direct access to the workspace, thus enabling network access while filtering out malware threats.
2Adaptability or versatility
If malware is downloaded and executed on the host computer system, then access to Internet resources is improved, but system integrity and security are compromised
Solution Approach 1:
The system divides the computer system into separate memory spaces: a first memory space for the trusted workspace and a second memory space for the sandboxed computing environment. This segmentation ensures that malware executed in the sandboxed environment cannot infect the workspace, maintaining system integrity while allowing resource access.
Solution Approach 2:
The system preemptively isolates the browser process in a sandboxed computing environment before any malware can execute. The sandbox container process establishes memory barriers and access controls in advance, preventing malware from spreading to the workspace even if downloaded and executed.
3Reliability
If the workspace is isolated from untrusted networks to prevent malware infection, then security is improved, but network accessibility and functionality are reduced
Solution Approach 1:
The system creates a segmented architecture where the workspace remains isolated from untrusted networks while the sandboxed computing environment maintains network connectivity. This allows the workspace to retain full network accessibility to trusted resources while the sandbox handles untrusted Internet access.
Solution Approach 2:
The sandbox container process serves as an intermediary that enables network accessibility for untrusted resources without compromising the workspace's security isolation. It allows the workspace to access trusted networks directly while routing untrusted Internet traffic through the sandboxed environment.
4Reliability
If a sandboxed computing environment is implemented to isolate untrusted activities, then security against malware is improved, but device complexity increases
Solution Approach 1:
The system implements segmentation through separate memory spaces managed by the sandbox container process, providing security isolation without requiring complex hardware modifications. This software-based segmentation achieves security protection while maintaining relative system simplicity.
Data Source
AI summary
Methods and systems are disclosed for a sandbox based internet isolation in an untrusted network. A host computer system may include a host-based firewall, an operating system, a first memory space, and a second memory space. The host-based firewall may be configured to prevent unauthorized communication between the trusted host computer system and one or more other devices on an untrusted LAN and/or the Internet. The second memory space may be configured to enable storage and/or operation of one or more applications and/or processes associated with a sandboxed computing environment. The host computer system may include a sandbox firewall that enforces separation of the first and second memory spaces.


