Self-Quarantining Network for Automated Threat Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures are slow, labor-intensive, and often disruptive when dealing with spreading threats like worms and viruses, as they require significant human intervention and expertise to detect and mitigate, leading to potential network disruptions.
Innovation Solution
Implementing a self-quarantining network that automatically monitors traffic and isolates infected hosts or specific types of traffic through physical ports, using advanced switches capable of threat detection and response, including statistical analysis and protocol analysis to quickly contain the spread of threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual quarantine techniques are used to isolate infected hosts, then infection spread can be prevented, but the process becomes slow, labor-intensive, and error-prone
Solution Approach 1:
The network device automatically performs quarantine actions based on detected threats without requiring human intervention. The system monitors traffic, identifies spreading threats, and autonomously isolates infected hosts by blocking their traffic, making the quarantine process self-service and eliminating manual labor while maintaining reliability
Solution Approach 2:
The system continuously monitors network traffic for signs of spreading threats and uses this feedback to automatically trigger quarantine actions. When infection indicators are detected, the system responds by blocking traffic from affected hosts, creating a closed-loop feedback mechanism that enables rapid automated response without human intervention
2Reliability
If manual quarantine techniques are used to isolate infected hosts, then infection spread can be prevented, but the process becomes labor-intensive and requires constant human staffing
Solution Approach 1:
The network device autonomously performs the complete quarantine process including threat detection, decision-making, and traffic blocking without human intervention. This automation eliminates the need for constant human staffing while maintaining effective infection prevention through self-service operation
Solution Approach 2:
The patent replaces manual mechanical quarantine actions (physically disconnecting cables or powering off devices) with automated electronic traffic blocking at the network device. This substitution enables rapid automated response while maintaining the effectiveness of isolation, eliminating the need for human physical intervention
3Extent of automation
If existing non-labor-intensive detection techniques are used, then some automation is achieved, but significant time and expertise are still required to respond to new threats
Solution Approach 1:
The network device automatically performs both detection and quarantine actions without human intervention. The system monitors traffic for spreading threats, autonomously identifies infected hosts, and immediately blocks their traffic, eliminating the time delay associated with human analysis and response while maintaining high automation throughout the process
4Reliability
If existing security measures are used, then some protection is provided, but compromised hosts can still adversely affect the network through denial of service and subversion of trust relationships
Solution Approach 1:
The system proactively blocks traffic from hosts exhibiting signs of compromise before they can cause widespread harm. By detecting spreading threats early and immediately isolating affected hosts through traffic blocking, the system prevents compromised hosts from subverting trust relationships or causing denial of service to other network participants
Solution Approach 2:
The system extracts and isolates traffic from compromised hosts by blocking it at the network device. This separation removes the harmful influence of infected hosts from the network while maintaining the ability to detect and respond to new threats, thereby protecting the overall network from adverse effects
Data Source
AI summary
Mitigating network security threats through a self-quarantining network is disclosed. Traffic received from a local source via a physical port is monitored. If a threat is detected, traffic associated with the physical port is restricted. In some embodiments, the monitoring includes one or more of performing a signature check on the traffic, applying statistical analysis to the traffic, performing protocol analysis on the traffic, and aggregating information about the traffic with information about traffic from an outside source.


