Secure Layered Iterative Gateway for Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in effectively detecting and mitigating sophisticated, automated cyber attacks across networks without requiring external modification of software or hardware configurations, as remote access for information assurance is cumbersome and prone to failure.

Innovation Solution

A distributed intermediary device, the Secure Layered Iterative Gateway (SLIG), is placed within a network to intercept and block cyber activity by using internal information assurance mechanisms, partitioning the network into segments, and employing a round-robin activation of gateway components with attestation to detect and respond to threats without modifying existing systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If remote access is used for information assurance threats assessment, then external detection capability is improved, but operation complexity and failure risk increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidoperation complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent introduces an intermediary device placed within the network that acts as a local information assurance mechanism. This intermediary assesses threats using internal signatures and compares them against known threat patterns, eliminating the need for remote access while maintaining detection capability. The intermediary serves as a mediator between network traffic and security assessment, performing local analysis without external intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If signature modification is implemented in software and hardware configuration, then threat detection accuracy is improved, but system complexity and modification difficulty increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem modification difficulty
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent segments the information assurance function into a separate intermediary device that operates independently from the existing network infrastructure. Rather than modifying software and hardware configurations of protected systems, the segmentation approach places a dedicated security assessment component within the network that maintains detection accuracy without requiring changes to fielded system components.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If network partitioning is implemented for security isolation, then attack surface is reduced, but network complexity increases

Engineering Contradiction:
Improveattack surfaceVSAvoidnetwork structure complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The intermediary device creates a logical security boundary without requiring physical network partitioning. It intercepts and assesses traffic passing through it, providing security isolation through local threat assessment rather than network segmentation. This approach reduces the attack surface by containing potential compromises within the intermediary while maintaining network connectivity and simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9203802B2Secure layered iterative gateway
Publication Date: 2015.12.01 JOHNS HOPKINS UNIVERSITY
  • US9203802B2 patent drawing
  • US9203802B2 patent drawing
  • US9203802B2 patent drawing

AI summary

In methods and a device for mitigating against cyber-attack on a network, a distributed intermediary device is placed into a network between computers or network nodes of the network to mitigate cyber-attacks between the computers or nodes of a network from remote systems. Threats are assessed by utilizing internal information assurance mechanisms of the device to detect such cyber-attacks without requiring external modification of the software and/or hardware of the computers or nodes of the network to be protected. The device prevents attacks at the platform level against the OS and network resources.