Security Appliance Gateway for Ransomware Lateral Movement Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional enterprise security solutions are inadequate in preventing lateral movement of ransomware within shared VLAN-based network architectures, as they fail to protect against east-west communication and are challenging to deploy on IoT devices and older operating systems.

Innovation Solution

A security appliance is set as the default gateway for intra-LAN communication using a subnet mask of 255.255.255.255, monitoring and controlling traffic between endpoint devices, and enforcing user-based policies in a cloud gateway to access protected resources, thereby preventing unauthorized communication and detecting ransomware attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security appliance is deployed as default gateway with subnet mask 255.255.255.255 to prevent lateral movement of ransomware, then security protection against lateral propagation is improved, but device complexity and difficulty of deployment increase

Engineering Contradiction:
Improvesecurity protectionVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security appliance is introduced as an intermediary device between endpoint devices and the network. The appliance is configured as the default gateway with a subnet mask of 255.255.255.255, which forces all traffic from endpoint devices to route through the security appliance. This intermediary position enables the appliance to monitor, detect, and block lateral movement of ransomware while maintaining network functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network architecture is segmented by implementing individual subnet masks (255.255.255.255) for each endpoint device, effectively isolating each device in its own subnet. This segmentation prevents direct east-west communication between endpoint devices and forces all traffic to pass through the security appliance gateway, thereby containing potential ransomware lateral movement.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If conventional enterprise security solutions are used, then ease of deployment is maintained, but protection against lateral movement of ransomware within shared VLAN is insufficient

Engineering Contradiction:
Improveease of deploymentVSAvoidprotection effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security appliance serves as a mediator that enhances protection effectiveness without requiring fundamental changes to the existing network architecture. By positioning the appliance as the default gateway, it intercepts and inspects all traffic between endpoint devices in the shared VLAN, providing robust lateral movement protection while maintaining compatibility with conventional deployment approaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The solution changes the subnet mask parameter to 255.255.255.255 for each endpoint device, which fundamentally alters traffic routing behavior. This parameter change ensures that all traffic, including lateral communication within the VLAN, must pass through the security appliance gateway, thereby enabling effective ransomware detection and blocking.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If endpoint protection agents are deployed on each device, then detection capability is improved, but ease of deployment and compatibility with IoT devices and older operating systems deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidease of deployment
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of operation

Solution Approach 1:

Instead of deploying detection agents on each endpoint device, the security appliance acts as a centralized intermediary that performs detection and analysis of all traffic passing through it. This approach maintains high detection capability by examining network traffic for signs of ransomware lateral movement, while avoiding the deployment challenges associated with installing and managing agents on diverse devices including IoT devices and older operating systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The solution replaces the mechanical approach of installing software agents on each endpoint device with a network-based detection mechanism. The security appliance monitors and analyzes traffic at the network layer, substituting the need for endpoint agents with centralized network-based detection that is compatible with all devices regardless of their operating system or capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If VLAN segmentation by department is implemented, then network organization is improved, but protection against lateral movement within VLAN domain is insufficient

Engineering Contradiction:
Improvenetwork organizationVSAvoidlateral movement protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security appliance is positioned as an intermediary gateway that all endpoint devices must communicate with, regardless of their departmental VLAN assignments. This intermediary position enables the appliance to monitor and control lateral movement traffic between devices within the same VLAN domain, providing protection that complements the existing VLAN segmentation by department.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The solution implements a second layer of segmentation at the subnet level by assigning each endpoint device a unique subnet mask of 255.255.255.255. This fine-grained segmentation works in conjunction with departmental VLAN segmentation, creating a multi-layered security architecture that prevents lateral movement while preserving organizational structure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12010141B1System gateway while accessing protected non-web resources connected to internet
Publication Date: 2024.06.11 AIRGAP NETWORKS INC
  • US12010141B1 patent drawing
  • US12010141B1 patent drawing
  • US12010141B1 patent drawing

AI summary

A technique to improve security for a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication. Message traffic is analyzed and anomalies are detected relative to normal message traffic that correspond to device health problems that may require service by a field technician. Access to a cloud-based resource may be further protected by enforcing user-based access policies.