Reflex-Reaction Server Leakage Containment via Firewall Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security strategies, particularly in flat networks, fail to effectively contain data leaks once the network perimeter is breached, allowing attackers to move laterally and access sensitive servers, often undetected for days or weeks, and require human intervention.
Innovation Solution
A reflex-reaction server leakage containment system that automatically updates a block list in the perimeter firewall based on LAN server metadata and firewall traffic data to quickly identify and block data leaks from internal servers without human intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If traditional perimeter firewall security is used in flat networks, then network connectivity is fast and reliable, but once the perimeter is breached, attackers can move laterally to access sensitive servers undetected for days or weeks
Solution Approach 1:
The patent divides the flat network into multiple segmented subnets with hierarchical naming conventions (e.g., subnets for different functions like web, database, email). Each subnet is isolated with controlled access, preventing lateral movement of attackers even if one segment is compromised. This maintains connectivity within segments while enhancing security containment.
Solution Approach 2:
The system implements automated feedback mechanisms where security monitoring continuously tracks network traffic and server status. When anomalies or breaches are detected, the system automatically responds by isolating affected segments, updating firewall rules, and alerting administrators, creating a closed-loop security system that reacts in real-time rather than waiting for manual intervention.
2Measurement precision
If manual security monitoring and response is used, then detection can be thorough, but it takes days, weeks, or years to identify and correct security infiltrations
Solution Approach 1:
The system implements self-service automation where security policies are automatically enforced without manual intervention. The hierarchical subnet architecture automatically routes traffic according to predefined rules, and security incidents are automatically contained by isolating affected segments. This eliminates delays associated with human response while maintaining thorough monitoring through automated logging and analysis.
Solution Approach 2:
The patent establishes preliminary security configurations including predefined subnet structures, automated response protocols, and pre-configured firewall rules. When security incidents occur, these pre-established mechanisms are immediately activated, eliminating the need for time-consuming manual analysis and response planning. The system is prepared in advance to detect and contain threats rapidly.
3Reliability
If network segmentation is implemented to protect internal servers, then security containment is improved, but the system complexity and difficulty of administration increase
Solution Approach 1:
The patent applies segmentation by dividing the network into hierarchical subnets organized by function (e.g., web-subnet, database-subnet, email-subnet). Each subnet has clearly defined boundaries and access controls, simplifying security management compared to a flat network. The hierarchical structure makes it easier to administer security policies on a per-subnet basis rather than managing a single complex flat network.
Solution Approach 2:
The system implements universal security policies that apply across all subnets through the hierarchical architecture. A single security framework manages multiple subnets with consistent rules, reducing administrative burden. The same security mechanisms (firewalls, monitoring, isolation protocols) are reused across different subnets, simplifying management despite the increased segmentation.
4Ease of operation
If physical segmentation is used to create subnets, then security control is straightforward, but the topology is fixed and requires physical wiring changes
Solution Approach 1:
The patent implements logical segmentation into subnets using virtualization and software-defined networking rather than physical segmentation. This allows security control through configurable virtual boundaries that can be adjusted without physical wiring changes. Each logical subnet maintains security isolation while enabling flexible topology changes through software configuration rather than physical reconfiguration.
Data Source
AI summary
A segmented local area network with reflex-reaction server leakage containment system includes a segmented local area network (LAN) and a reflex-reaction server leakage containment system. The LAN includes an internal zone with at least one internal server, and a perimeter firewall developing firewall traffic data and being responsive to a block list of internet protocol (IP) addresses. The reflex-reaction server leakage containment system stores a LAN server metadata (LSM) table, is receptive to the firewall traffic data and is operative to automatically update the block list with at least one of an IP address of the at least one internal server and an IP address of an external destination server when a data leakage through the perimeter firewall from the at least one internal server to the external destination server is detected.


