Secure Layered Iterative Gateway for Network Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face challenges in effectively detecting and mitigating sophisticated, automated cyber attacks across networks without requiring external modification of software or hardware configurations, as remote access for information assurance is cumbersome and prone to failure.
Innovation Solution
A distributed intermediary device, the Secure Layered Iterative Gateway (SLIG), is placed within a network to intercept and block cyber activity by using internal information assurance mechanisms, partitioning the network into segments, and employing a round-robin activation of gateway components with attestation to detect and respond to threats without modifying existing systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If remote access is used for information assurance threats assessment, then external detection capability is improved, but operation complexity and failure risk increase
Solution Approach 1:
The patent introduces an intermediary device placed within the network that acts as a local information assurance mechanism. This intermediary assesses threats using internal signatures and compares them against known threat patterns, eliminating the need for remote access while maintaining detection capability. The intermediary serves as a mediator between network traffic and security assessment, performing local analysis without external intervention.
2Measurement precision
If signature modification is implemented in software and hardware configuration, then threat detection accuracy is improved, but system complexity and modification difficulty increase
Solution Approach 1:
The patent segments the information assurance function into a separate intermediary device that operates independently from the existing network infrastructure. Rather than modifying software and hardware configurations of protected systems, the segmentation approach places a dedicated security assessment component within the network that maintains detection accuracy without requiring changes to fielded system components.
3Object-affected harmful factors
If network partitioning is implemented for security isolation, then attack surface is reduced, but network complexity increases
Solution Approach 1:
The intermediary device creates a logical security boundary without requiring physical network partitioning. It intercepts and assesses traffic passing through it, providing security isolation through local threat assessment rather than network segmentation. This approach reduces the attack surface by containing potential compromises within the intermediary while maintaining network connectivity and simplicity.
Data Source
AI summary
In methods and a device for mitigating against cyber-attack on a network, a distributed intermediary device is placed into a network between computers or network nodes of the network to mitigate cyber-attacks between the computers or nodes of a network from remote systems. Threats are assessed by utilizing internal information assurance mechanisms of the device to detect such cyber-attacks without requiring external modification of the software and/or hardware of the computers or nodes of the network to be protected. The device prevents attacks at the platform level against the OS and network resources.


