Security System Mitigating Unsecured Network Risks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face security risks when accessing unencrypted websites over unsecured networks, such as open Wi-Fi, due to potential eavesdropping, malware distribution, and data manipulation, with current solutions failing to effectively warn users of these risks and protect their devices.

Innovation Solution

A system that determines the security mode of a Wi-Fi network and the communication security type of a website, performing mitigation actions such as generating visual warnings, halting script execution, and preventing sensitive information transmission when an open and unsecured network is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access unencrypted websites over unsecured networks, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary detection of network security mode and website encryption status before allowing browsing. It proactively identifies unsecured networks and unencrypted websites, and preemptively implements mitigation actions such as blocking connections or displaying warning alerts, thereby preventing security breaches before they occur while maintaining user browsing convenience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security detection system that acts as a mediator between the user's web browser and the network/website. This intermediary layer analyzes network security modes, detects website encryption status, and controls the connection flow, thereby protecting users from security risks without requiring changes to their browsing behavior or adding complexity to the user interface

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system performs security detection and mitigation actions, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security detection system is designed as a multi-functional component that simultaneously performs multiple tasks: detecting network security modes, analyzing website encryption status, determining mitigation actions, and executing protection measures. By consolidating these functions into a single integrated system, the patent avoids the complexity that would arise from multiple separate security tools while maintaining comprehensive security coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the system provides visual warnings and protection, then security reliability is improved, but information loss increases due to blocking legitimate content

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidloss of information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements a feedback mechanism where it continuously monitors the outcomes of mitigation actions. When a mitigation action blocks a connection, the system evaluates whether the blocked content was genuinely malicious or legitimate. Based on this feedback, the system adjusts its detection criteria and mitigation strategies, thereby reducing false positives and minimizing information loss while maintaining high security reliability

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Instead of broadly blocking all unencrypted content, the system applies preliminary anti-action by specifically targeting only those connections that pose actual security risks. It uses intelligent detection to distinguish between malicious unencrypted websites and legitimate ones, applying mitigation actions selectively rather than universally, thereby protecting users from threats while preserving access to legitimate unencrypted content

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11637850B2Mitigating security risks associated with unsecured websites and networks
Publication Date: 2023.04.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11637850B2 patent drawing
  • US11637850B2 patent drawing
  • US11637850B2 patent drawing

AI summary

Security mitigation techniques are presented to protect a user device or a user thereof from attackers, especially in instances when they are most at risk. In an example embodiment, one or more mitigation actions may be performed when it is determined that a website is unsecured and a network with which the user device is connected is open Wi-Fi. The mitigation action may include generating a visual warning in a graphical user interface (GUI) of a web browser that is displaying the website, preventing the transmission of sensitive information, halting execution of scripts and resources of inactive web browser tabs or when there is a change in network connection, or not allowing execution of scripts or resources when the website is unsecured. In another example embodiment, transmission of sensitive information is prevented from being transmitted by an application over an open Wi-Fi network.