Network Security Policy Segmentation for Threat Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network security techniques are inadequate in effectively protecting a subset of computing resources from active threats, particularly in scenarios involving sensitive data transmission and storage, as they fail to differentiate between business and personal resources, leading to potential unauthorized access and data breaches.
Innovation Solution
Implementing a system that includes a security policy to differentiate between supervised and unsupervised resources, utilizing a security event detector to identify active threats, and dynamically blocking or unblocking access to these resources based on threat presence or absence, while also employing a dedicated Internet Protocol space to secure Internet applications by assigning unique IP addresses to entities for isolated network traffic processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current computer network security techniques are used, then basic security protection is provided, but they fail to differentiate between business and personal resources, leading to potential unauthorized access and data breaches
Solution Approach 1:
The patent segments computing resources into supervised and unsupervised categories, and further divides supervised resources into business and personal resources. This segmentation enables differentiated security policies where business resources receive enhanced protection while personal resources are treated differently, preventing unauthorized access to sensitive business data while maintaining appropriate access to personal resources.
Solution Approach 2:
The patent applies local quality by implementing resource-specific security policies that differentiate between business and personal resources. Each resource type receives tailored security measures based on its sensitivity and purpose, with business resources receiving stricter access controls and monitoring compared to personal resources.
2Reliability
If a security policy differentiates between supervised and unsupervised resources is implemented, then access control is improved, but system complexity increases
Solution Approach 1:
The patent implements dynamic security policies that automatically adjust access controls based on the presence or absence of active threats. When a threat is detected, the system dynamically blocks access to supervised resources; when the threat is resolved, access is restored. This dynamic approach maintains effective access control while reducing manual policy management complexity.
Solution Approach 2:
The security system incorporates feedback mechanisms where the security event detector continuously monitors for active threats and provides feedback to the security policy enforcement. This feedback loop enables automatic adjustment of access controls based on real-time threat assessment, improving access control effectiveness while simplifying policy management through automation.
3Reliability
If dynamic blocking or unblocking access is implemented based on threat presence, then security responsiveness is improved, but processing time increases
Solution Approach 1:
The system performs preliminary actions by pre-configuring security policies and maintaining continuous monitoring for active threats. The security event detector operates continuously to identify threats before they can execute, and access controls are pre-positioned to block supervised resources immediately upon threat detection, minimizing processing delays while maintaining rapid security responsiveness.
4Reliability
If a dedicated Internet Protocol space is used to secure Internet applications, then network security isolation is improved, but IP address allocation complexity increases
Solution Approach 1:
The patent segments the Internet Protocol address space into dedicated ranges for different entities (e.g., first entity, second entity). Each entity is assigned a dedicated IP address or IP range that is isolated from other entities' address spaces. This segmentation provides network security isolation by ensuring that traffic between entities can be differentiated and controlled independently, while the patent manages this complexity through structured allocation protocols.
Data Source
AI summary
A computer determines, by a security event detector, that an active threat exists at the computer. The security event detector resides at the computer or in a cloud resource. The security event detector identifies active threats at the computer or a network associated with the computer. The computer prevents, in response to determining that the active threat exists, access to a subset of computing resources accessible via the computer. The subset of computing resources is identified via a security policy that applies to the subset of computing resources. The security policy does not apply to one or more computing resources stored at the computer that are not in the subset. The computer determines, subsequent to determining that the active threat exists, that the active threat no longer exists. The computer allows, in response to determining that the active threat no longer exists, access to the subset of computing resources.


