Reflex-Reaction Server Leakage Containment via Firewall Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security strategies, particularly in flat networks, fail to effectively contain data leaks once the network perimeter is breached, allowing attackers to move laterally and access sensitive servers, often undetected for days or weeks, and require human intervention.

Innovation Solution

A reflex-reaction server leakage containment system that automatically updates a block list in the perimeter firewall based on LAN server metadata and firewall traffic data to quickly identify and block data leaks from internal servers without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional perimeter firewall security is used in flat networks, then network connectivity is fast and reliable, but once the perimeter is breached, attackers can move laterally to access sensitive servers undetected for days or weeks

Engineering Contradiction:
Improvenetwork connectivity speedVSAvoidsecurity containment capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent divides the flat network into multiple segmented subnets with hierarchical naming conventions (e.g., subnets for different functions like web, database, email). Each subnet is isolated with controlled access, preventing lateral movement of attackers even if one segment is compromised. This maintains connectivity within segments while enhancing security containment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements automated feedback mechanisms where security monitoring continuously tracks network traffic and server status. When anomalies or breaches are detected, the system automatically responds by isolating affected segments, updating firewall rules, and alerting administrators, creating a closed-loop security system that reacts in real-time rather than waiting for manual intervention.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual security monitoring and response is used, then detection can be thorough, but it takes days, weeks, or years to identify and correct security infiltrations

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements self-service automation where security policies are automatically enforced without manual intervention. The hierarchical subnet architecture automatically routes traffic according to predefined rules, and security incidents are automatically contained by isolating affected segments. This eliminates delays associated with human response while maintaining thorough monitoring through automated logging and analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes preliminary security configurations including predefined subnet structures, automated response protocols, and pre-configured firewall rules. When security incidents occur, these pre-established mechanisms are immediately activated, eliminating the need for time-consuming manual analysis and response planning. The system is prepared in advance to detect and contain threats rapidly.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network segmentation is implemented to protect internal servers, then security containment is improved, but the system complexity and difficulty of administration increase

Engineering Contradiction:
Improvesecurity containmentVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the network into hierarchical subnets organized by function (e.g., web-subnet, database-subnet, email-subnet). Each subnet has clearly defined boundaries and access controls, simplifying security management compared to a flat network. The hierarchical structure makes it easier to administer security policies on a per-subnet basis rather than managing a single complex flat network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal security policies that apply across all subnets through the hierarchical architecture. A single security framework manages multiple subnets with consistent rules, reducing administrative burden. The same security mechanisms (firewalls, monitoring, isolation protocols) are reused across different subnets, simplifying management despite the increased segmentation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If physical segmentation is used to create subnets, then security control is straightforward, but the topology is fixed and requires physical wiring changes

Engineering Contradiction:
Improvesecurity control simplicityVSAvoidnetwork topology flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements logical segmentation into subnets using virtualization and software-defined networking rather than physical segmentation. This allows security control through configurable virtual boundaries that can be adjusted without physical wiring changes. Each logical subnet maintains security isolation while enabling flexible topology changes through software configuration rather than physical reconfiguration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12425369B1Reflex-reaction server leakage containment system
Publication Date: 2025.09.23 CELERIUM INC
  • US12425369B1 patent drawing
  • US12425369B1 patent drawing
  • US12425369B1 patent drawing

AI summary

A segmented local area network with reflex-reaction server leakage containment system includes a segmented local area network (LAN) and a reflex-reaction server leakage containment system. The LAN includes an internal zone with at least one internal server, and a perimeter firewall developing firewall traffic data and being responsive to a block list of internet protocol (IP) addresses. The reflex-reaction server leakage containment system stores a LAN server metadata (LSM) table, is receptive to the firewall traffic data and is operative to automatically update the block list with at least one of an IP address of the at least one internal server and an IP address of an external destination server when a data leakage through the perimeter firewall from the at least one internal server to the external destination server is detected.