Self-Quarantining Network for Automated Threat Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures are slow, labor-intensive, and often disruptive when dealing with spreading threats like worms and viruses, as they require significant human intervention and expertise to detect and mitigate, leading to potential network disruptions.

Innovation Solution

Implementing a self-quarantining network that automatically monitors traffic and isolates infected hosts or specific types of traffic through physical ports, using advanced switches capable of threat detection and response, including statistical analysis and protocol analysis to quickly contain the spread of threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual quarantine techniques are used to isolate infected hosts, then infection spread can be prevented, but the process becomes slow, labor-intensive, and error-prone

Engineering Contradiction:
Improveinfection prevention effectivenessVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network device automatically performs quarantine actions based on detected threats without requiring human intervention. The system monitors traffic, identifies spreading threats, and autonomously isolates infected hosts by blocking their traffic, making the quarantine process self-service and eliminating manual labor while maintaining reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic for signs of spreading threats and uses this feedback to automatically trigger quarantine actions. When infection indicators are detected, the system responds by blocking traffic from affected hosts, creating a closed-loop feedback mechanism that enables rapid automated response without human intervention

Inventive Principle:
Principle #23Feedback

2Reliability

If manual quarantine techniques are used to isolate infected hosts, then infection spread can be prevented, but the process becomes labor-intensive and requires constant human staffing

Engineering Contradiction:
Improveinfection prevention effectivenessVSAvoidautomated response capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The network device autonomously performs the complete quarantine process including threat detection, decision-making, and traffic blocking without human intervention. This automation eliminates the need for constant human staffing while maintaining effective infection prevention through self-service operation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical quarantine actions (physically disconnecting cables or powering off devices) with automated electronic traffic blocking at the network device. This substitution enables rapid automated response while maintaining the effectiveness of isolation, eliminating the need for human physical intervention

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Extent of automation

If existing non-labor-intensive detection techniques are used, then some automation is achieved, but significant time and expertise are still required to respond to new threats

Engineering Contradiction:
Improvedetection automationVSAvoidresponse time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The network device automatically performs both detection and quarantine actions without human intervention. The system monitors traffic for spreading threats, autonomously identifies infected hosts, and immediately blocks their traffic, eliminating the time delay associated with human analysis and response while maintaining high automation throughout the process

Inventive Principle:
Principle #25Self-service

4Reliability

If existing security measures are used, then some protection is provided, but compromised hosts can still adversely affect the network through denial of service and subversion of trust relationships

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork disruption impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system proactively blocks traffic from hosts exhibiting signs of compromise before they can cause widespread harm. By detecting spreading threats early and immediately isolating affected hosts through traffic blocking, the system prevents compromised hosts from subverting trust relationships or causing denial of service to other network participants

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system extracts and isolates traffic from compromised hosts by blocking it at the network device. This separation removes the harmful influence of infected hosts from the network while maintaining the ability to detect and respond to new threats, thereby protecting the overall network from adverse effects

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7617533B1Self-quarantining network
Publication Date: 2009.11.10 CA TECH INC
  • US7617533B1 patent drawing
  • US7617533B1 patent drawing
  • US7617533B1 patent drawing

AI summary

Mitigating network security threats through a self-quarantining network is disclosed. Traffic received from a local source via a physical port is monitored. If a threat is detected, traffic associated with the physical port is restricted. In some embodiments, the monitoring includes one or more of performing a signature check on the traffic, applying statistical analysis to the traffic, performing protocol analysis on the traffic, and aggregating information about the traffic with information about traffic from an outside source.