Reflex-Reaction Server Containment for Data Leak Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security strategies, particularly in flat networks, fail to effectively contain data leaks once the network perimeter is breached, allowing attackers to move laterally and exfiltrate sensitive data, often undetected for days or weeks, and require human intervention.

Innovation Solution

A reflex-reaction server leakage containment system that automatically updates a block list in the perimeter firewall based on LAN server metadata and perimeter firewall traffic data to quickly identify and block unauthorized data transfers from internal servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional perimeter firewall security is used in flat networks, then network connectivity is fast and reliable, but once the perimeter is breached, attackers can move laterally and exfiltrate data undetected for days or weeks

Engineering Contradiction:
Improvenetwork connectivity speedVSAvoidsecurity containment capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent divides the flat network into multiple segments or zones with different security levels, implementing micro-segmentation to prevent lateral movement. This allows maintaining fast connectivity within segments while providing security containment between segments, resolving the contradiction between speed and security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security system that monitors and controls traffic between network segments. This intermediary layer provides real-time detection and containment capabilities without significantly impacting the speed of legitimate communications, thus maintaining both fast connectivity and reliable security containment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual detection and response methods are used, then security analysis can be thorough, but it takes days, weeks, or years to identify infiltrations and requires human intervention

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidtime to detect and respond to breaches
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements an automated security system that performs self-detection, self-analysis, and self-response without human intervention. The system continuously monitors network traffic, automatically identifies suspicious patterns, and executes containment actions, achieving both high detection accuracy and rapid response times by eliminating manual processing delays.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes a closed-loop feedback system where security events are continuously monitored, analyzed, and responded to in real-time. The system uses feedback from network traffic patterns to automatically adjust security measures and contain threats immediately upon detection, eliminating the time loss associated with manual detection and response while maintaining high detection accuracy.

Inventive Principle:
Principle #23Feedback

3Reliability

If network segmentation is implemented to protect internal servers, then security is enhanced, but it requires high sophistication of LAN designers and administrators to configure and maintain

Engineering Contradiction:
Improveinternal server protectionVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security policy framework that applies standardized segmentation rules across all network segments. This multi-functional approach allows a single configuration system to manage multiple segments with consistent security policies, reducing the complexity burden on administrators while maintaining reliable internal server protection through consistent enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter-based security policies that can be dynamically adjusted without changing the underlying network architecture. By changing security parameters rather than reconfiguring the entire segmentation structure, administrators can maintain reliable server protection while significantly reducing configuration and maintenance complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12537795B2Reflex-reaction server leakage containment system
Publication Date: 2026.01.27 CELERIUM INC
  • US12537795B2 patent drawing
  • US12537795B2 patent drawing
  • US12537795B2 patent drawing

AI summary

A segmented local area network with reflex-reaction server leakage containment system includes a segmented local area network (LAN) and a reflex-reaction server leakage containment system. The LAN includes an internal zone with at least one internal server, and a perimeter firewall developing firewall traffic data and being responsive to a block list of internet protocol (IP) addresses. The reflex-reaction server leakage containment system stores a LAN server metadata (LSM) table, is receptive to the firewall traffic data and is operative to automatically update the block list with at least one of an IP address of the at least one internal server and an IP address of an external destination server when a data leakage through the perimeter firewall from the at least one internal server to the external destination server is detected.