Automated Security Gateway for Home Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home networks are vulnerable to malicious attacks and security threats due to unauthorized device behavior and compromised home automation devices, which can lead to privacy invasion and security compromises.

Innovation Solution

An automated security gateway analyzes network traffic to detect and remediate potential security threats by blocking unauthorized traffic, generating alerts, and enforcing security policies based on device behavior and traffic policies, thereby enhancing network security and user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an automated security gateway analyzes network traffic to detect security threats, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidgateway complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an automated security gateway as an intermediary device positioned between the home network and external networks. This gateway acts as a mediator that monitors and controls traffic flow, analyzing packets for security threats without requiring modifications to existing devices. The gateway implements security policies and blocks malicious traffic while allowing legitimate communication, thereby improving network security through this intermediate protective layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security gateway implements feedback mechanisms by continuously monitoring network traffic patterns and device behavior. It compares observed traffic against established security policies and baseline device behavior, generating alerts when anomalies are detected. The system learns from traffic patterns over time, adjusting its analysis parameters and threat detection thresholds based on feedback from blocked threats and legitimate traffic flows, thereby improving detection accuracy while managing complexity through adaptive learning.

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If the security gateway blocks unauthorized traffic, then security threats are reduced, but loss of information increases

Engineering Contradiction:
Improvesecurity threatsVSAvoidlegitimate traffic
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The security gateway performs preliminary actions by establishing security policies and baseline device behavior profiles before threats occur. It pre-configures rules for identifying malicious traffic patterns, device communication norms, and authorized applications. By having these criteria established in advance, the gateway can quickly evaluate incoming traffic against known threat signatures and behavioral baselines, reducing false positives and ensuring legitimate traffic is not mistakenly blocked.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway applies different analysis criteria and security policies to different devices, applications, and traffic types individually. Rather than using a blanket blocking approach, it evaluates each traffic flow based on its specific characteristics, device identity, application context, and established behavioral patterns. This localized analysis ensures that security measures are tailored to each communication scenario, minimizing unnecessary blocking of legitimate traffic while maintaining strong security for identified threats.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If the gateway provides granular traffic analysis, then measurement precision is improved, but use of energy increases

Engineering Contradiction:
Improvetraffic analysis precisionVSAvoidgateway energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The security gateway implements partial analysis by applying different levels of inspection intensity to different traffic flows. For traffic from devices with established clean reputations or for known legitimate applications, the gateway performs lighter analysis. For new devices, suspicious traffic patterns, or high-risk communication types, it applies more intensive granular analysis. This selective approach maintains high measurement precision for critical threats while reducing energy consumption by avoiding exhaustive analysis of all traffic equally.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The gateway uses periodic action by implementing time-based analysis strategies and baseline establishment. It collects traffic data over periodic intervals to establish normal behavioral patterns for each device, then uses these baselines to guide subsequent analysis intensity. During low-activity periods or when traffic matches established patterns, analysis frequency is reduced. When anomalies are detected or during high-risk time windows, the gateway increases analysis precision and frequency, thereby managing energy consumption through temporal variation in analysis intensity.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9548993B2Automated security gateway
Publication Date: 2017.01.17 VERIZON PATENT & LICENSING INC
  • US9548993B2 patent drawing
  • US9548993B2 patent drawing
  • US9548993B2 patent drawing

AI summary

A security device may be configured to receive information regarding traffic that has been outputted by a particular user device; and compare the information regarding the traffic to security information. The security information may include device behavior information, traffic policy information, or device policy information. The security device may determine, based on the comparing, that a security threat exists with regard to the traffic; and take, based on determining that the security threat exists, remedial action with respect to the traffic. Taking the remedial action may include preventing the traffic from being forwarded to an intended destination associated with the traffic, providing an alert, regarding the security threat, to the particular user device, or providing an alert, regarding to the security threat, to another device.