Network Security Policy Segmentation for Threat Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network security techniques are inadequate in effectively protecting a subset of computing resources from active threats, particularly in scenarios involving sensitive data transmission and storage, as they fail to differentiate between business and personal resources, leading to potential unauthorized access and data breaches.

Innovation Solution

Implementing a system that includes a security policy to differentiate between supervised and unsupervised resources, utilizing a security event detector to identify active threats, and dynamically blocking or unblocking access to these resources based on threat presence or absence, while also employing a dedicated Internet Protocol space to secure Internet applications by assigning unique IP addresses to entities for isolated network traffic processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current computer network security techniques are used, then basic security protection is provided, but they fail to differentiate between business and personal resources, leading to potential unauthorized access and data breaches

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidunauthorized access to sensitive data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments computing resources into supervised and unsupervised categories, and further divides supervised resources into business and personal resources. This segmentation enables differentiated security policies where business resources receive enhanced protection while personal resources are treated differently, preventing unauthorized access to sensitive business data while maintaining appropriate access to personal resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing resource-specific security policies that differentiate between business and personal resources. Each resource type receives tailored security measures based on its sensitivity and purpose, with business resources receiving stricter access controls and monitoring compared to personal resources.

Inventive Principle:
Principle #3Local quality

2Reliability

If a security policy differentiates between supervised and unsupervised resources is implemented, then access control is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidsecurity policy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust access controls based on the presence or absence of active threats. When a threat is detected, the system dynamically blocks access to supervised resources; when the threat is resolved, access is restored. This dynamic approach maintains effective access control while reducing manual policy management complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security system incorporates feedback mechanisms where the security event detector continuously monitors for active threats and provides feedback to the security policy enforcement. This feedback loop enables automatic adjustment of access controls based on real-time threat assessment, improving access control effectiveness while simplifying policy management through automation.

Inventive Principle:
Principle #23Feedback

3Reliability

If dynamic blocking or unblocking access is implemented based on threat presence, then security responsiveness is improved, but processing time increases

Engineering Contradiction:
Improvesecurity responsivenessVSAvoidaccess control processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring security policies and maintaining continuous monitoring for active threats. The security event detector operates continuously to identify threats before they can execute, and access controls are pre-positioned to block supervised resources immediately upon threat detection, minimizing processing delays while maintaining rapid security responsiveness.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If a dedicated Internet Protocol space is used to secure Internet applications, then network security isolation is improved, but IP address allocation complexity increases

Engineering Contradiction:
Improvenetwork traffic isolationVSAvoidIP address management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the Internet Protocol address space into dedicated ranges for different entities (e.g., first entity, second entity). Each entity is assigned a dedicated IP address or IP range that is isolated from other entities' address spaces. This segmentation provides network security isolation by ensuring that traffic between entities can be differentiated and controlled independently, while the patent manages this complexity through structured allocation protocols.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230101145A1Computer Network Security
Publication Date: 2023.03.30 VENN TECH CORP
  • US20230101145A1 patent drawing
  • US20230101145A1 patent drawing
  • US20230101145A1 patent drawing

AI summary

A computer determines, by a security event detector, that an active threat exists at the computer. The security event detector resides at the computer or in a cloud resource. The security event detector identifies active threats at the computer or a network associated with the computer. The computer prevents, in response to determining that the active threat exists, access to a subset of computing resources accessible via the computer. The subset of computing resources is identified via a security policy that applies to the subset of computing resources. The security policy does not apply to one or more computing resources stored at the computer that are not in the subset. The computer determines, subsequent to determining that the active threat exists, that the active threat no longer exists. The computer allows, in response to determining that the active threat no longer exists, access to the subset of computing resources.