Subnet Security for Dynamic Device-Based Firewall Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firewalls struggle to provide differentiated security protection for diverse devices, particularly IoT devices with limited processing and memory capabilities, and user devices that require more complex security measures, leading to potential vulnerabilities in local networks.
Innovation Solution
Divide local networks into subnets based on device functionality, applying distinct security rules to each subnet, and monitor intra-subnet communication for anomalies, with the ability to quarantine or isolate potentially malicious devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single uniform security rule set is applied to all devices in the protected network, then the firewall implementation is simple and consistent, but the security protection is insufficient for diverse device types with different capabilities
Solution Approach 1:
The patent segments the protected network into multiple subnets based on device types (e.g., IoT devices, mobile devices, fixed devices). Each subnet is assigned a specific security rule set tailored to the characteristics and security requirements of that device category. This segmentation allows differentiated security protection while maintaining manageable complexity through organized groupings.
Solution Approach 2:
The patent applies the principle of local quality by assigning different security rule sets to different subnets according to the specific needs of each device type. For example, IoT devices may receive more restrictive rules due to their limited security capabilities, while mobile devices receive rules appropriate for their higher security requirements. This localized approach optimizes security protection for each device category without requiring a completely complex system-wide configuration.
2Reliability
If the network is divided into multiple subnets with differentiated security rules, then targeted security protection for different device types is achieved, but the network management complexity increases
Solution Approach 1:
The patent implements dynamic device classification and subnet assignment mechanisms. When devices join the network, the firewall automatically identifies device types and assigns them to appropriate subnets with suitable security rule sets. This dynamic approach reduces manual management complexity while maintaining differentiated security protection, as the system adapts automatically rather than requiring static pre-configuration for every device.
Solution Approach 2:
The firewall system performs self-service by automatically classifying devices and assigning them to appropriate subnets based on their characteristics. The system autonomously manages the complexity of differentiated security rule application without requiring manual intervention for each device, thereby reducing operational burden while maintaining targeted security protection.
3Measurement precision
If uniform security monitoring is applied across the entire network, then the monitoring system is simple to implement, but it cannot effectively detect anomalies specific to different device types
Solution Approach 1:
The security monitoring system is segmented to monitor different subnets separately with device-type-specific anomaly detection rules. This allows the system to detect anomalies tailored to each device category's normal behavior patterns, improving detection accuracy while organizing complexity through structured subnet-based monitoring groups.
Data Source
AI summary
A method, apparatus and product for sub-networks based cyber security. One method includes detecting a device connecting to a local network, wherein the local network is divided into an initial set of subnets, identifying the device by performing a fingerprinting operation on the device, determining an expected usage of the device and updating the initial set of subnets based on the expected usage of the device to generate an updated set of subnets. The method further includes selecting a subnet of the updated set of subnets of the local network to connect the device based on the expected usage of the device, the selected subnet corresponding to the expected usage of the device and connecting the device to the selected subnet in the local network.


