Sandbox Network Isolation Firewall for Cloud Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively isolate and protect cloud-based assets from malware, which can lead to security losses, efficiency reductions, and loss of command and control, as malicious software can infect host computer systems and compromise user privacy by communicating with untrusted network destinations.

Innovation Solution

A sandbox-based network isolation system is implemented, which segregates trusted and untrusted memory spaces using an internal isolation firewall, preventing unauthorized communication and allowing user-controlled access, and employs proxy servers to authenticate and route internet traffic through secure channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications are allowed to communicate freely with Internet destinations, then network functionality and accessibility are improved, but security risks increase as malware can infect host systems and compromise data

Engineering Contradiction:
Improvenetwork functionalityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the network communication environment by creating a sandboxed computing environment that isolates applications from direct access to host system resources. The internal isolation firewall divides network traffic into trusted and untrusted zones, allowing legitimate network functionality while preventing malware from compromising the host system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The internal isolation firewall acts as an intermediary between applications and Internet destinations. It mediates all network communications by inspecting traffic, enforcing security policies, and blocking malicious connections while allowing legitimate traffic to pass through, thus maintaining network functionality without exposing the host to security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If an isolation firewall is implemented to block malware communication, then security is improved, but legitimate application functionality may be restricted

Engineering Contradiction:
ImprovesecurityVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The internal isolation firewall implements dynamic security policies that adapt to application needs. It monitors application behavior in real-time and adjusts communication restrictions accordingly, allowing legitimate applications to function normally while blocking malware. The system dynamically evaluates traffic patterns and enforcement rules to maintain both security and functionality.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of network communication by implementing context-aware filtering. It modifies communication parameters based on application trust levels, user permissions, and detected threat patterns, allowing legitimate traffic while blocking malicious connections. This parameter-based control enables fine-tuned security that preserves application functionality.

Inventive Principle:
Principle #35Parameter changes

3Extent of automation

If user authentication is required for network access, then control over communication is improved, but system complexity increases

Engineering Contradiction:
Improvecommunication controlVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The internal isolation firewall implements self-service authentication mechanisms that automatically verify application credentials and enforce access policies without requiring manual user intervention for each connection. The system maintains authentication states and enforcement rules internally, providing automated communication control while minimizing the perceived complexity for users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11178104B2Network isolation with cloud networks
Publication Date: 2021.11.16 CROGA INNOVATIONS LTD
  • US11178104B2 patent drawing
  • US11178104B2 patent drawing
  • US11178104B2 patent drawing

AI summary

Systems and methods are disclosed for a sandbox based network isolation system configured to protect cloud based assets. A host computer system may include a processor and a memory. The host computer system may include a workspace. One or more applications may run in the workspace via a first memory space (e.g., a trusted memory space). The host computer system may include an isolated computing environment. One or more isolated applications may run in the isolated computing environment via a second memory space (e.g., an untrusted memory space). The isolated computing environment may be isolated from the workspace by an internal isolation firewall. The internal isolation firewall may prevent communication between the isolated computing environment and the workspace.