Subnet Security for Dynamic Device-Based Firewall Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewalls struggle to provide differentiated security protection for diverse devices, particularly IoT devices with limited processing and memory capabilities, and user devices that require more complex security measures, leading to potential vulnerabilities in local networks.

Innovation Solution

Divide local networks into subnets based on device functionality, applying distinct security rules to each subnet, and monitor intra-subnet communication for anomalies, with the ability to quarantine or isolate potentially malicious devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single uniform security rule set is applied to all devices in the protected network, then the firewall implementation is simple and consistent, but the security protection is insufficient for diverse device types with different capabilities

Engineering Contradiction:
Improvesecurity protectionVSAvoidfirewall configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the protected network into multiple subnets based on device types (e.g., IoT devices, mobile devices, fixed devices). Each subnet is assigned a specific security rule set tailored to the characteristics and security requirements of that device category. This segmentation allows differentiated security protection while maintaining manageable complexity through organized groupings.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies the principle of local quality by assigning different security rule sets to different subnets according to the specific needs of each device type. For example, IoT devices may receive more restrictive rules due to their limited security capabilities, while mobile devices receive rules appropriate for their higher security requirements. This localized approach optimizes security protection for each device category without requiring a completely complex system-wide configuration.

Inventive Principle:
Principle #3Local quality

2Reliability

If the network is divided into multiple subnets with differentiated security rules, then targeted security protection for different device types is achieved, but the network management complexity increases

Engineering Contradiction:
Improvedifferentiated security protectionVSAvoidnetwork management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic device classification and subnet assignment mechanisms. When devices join the network, the firewall automatically identifies device types and assigns them to appropriate subnets with suitable security rule sets. This dynamic approach reduces manual management complexity while maintaining differentiated security protection, as the system adapts automatically rather than requiring static pre-configuration for every device.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The firewall system performs self-service by automatically classifying devices and assigning them to appropriate subnets based on their characteristics. The system autonomously manages the complexity of differentiated security rule application without requiring manual intervention for each device, thereby reducing operational burden while maintaining targeted security protection.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If uniform security monitoring is applied across the entire network, then the monitoring system is simple to implement, but it cannot effectively detect anomalies specific to different device types

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidmonitoring system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security monitoring system is segmented to monitor different subnets separately with device-type-specific anomaly detection rules. This allows the system to detect anomalies tailored to each device category's normal behavior patterns, improving detection accuracy while organizing complexity through structured subnet-based monitoring groups.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12375565B2Sub-networks based security method, apparatus and product
Publication Date: 2025.07.29 FORESCOUT TECHNOLOGIES INC
  • US12375565B2 patent drawing
  • US12375565B2 patent drawing
  • US12375565B2 patent drawing

AI summary

A method, apparatus and product for sub-networks based cyber security. One method includes detecting a device connecting to a local network, wherein the local network is divided into an initial set of subnets, identifying the device by performing a fingerprinting operation on the device, determining an expected usage of the device and updating the initial set of subnets based on the expected usage of the device to generate an updated set of subnets. The method further includes selecting a subnet of the updated set of subnets of the local network to connect the device based on the expected usage of the device, the selected subnet corresponding to the expected usage of the device and connecting the device to the selected subnet in the local network.