Subnet Segmentation for Internal Network Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems are vulnerable to internal network attacks once compromised, as malicious actors can exploit internal security barriers to launch further attacks from within the network, compromising additional host systems and sensitive data.
Innovation Solution
A computer-implemented method and system that identifies intrusions on host systems within subnets capable of facilitating attacks, implementing security measures such as transmitting instructions to endpoint agents, adding firewall restrictions, and modifying security policies to prevent further attacks, even when the original intrusion cannot be automatically remediated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If internal security barriers are lowered to allow easier communication within the network, then network operation efficiency is improved, but vulnerability to internal attacks increases
Solution Approach 1:
The network is divided into subnets with hierarchical security boundaries. When an intrusion is detected on a host system, the security system segments the affected subnet by implementing firewall restrictions that isolate the compromised host from other hosts within the same subnet, preventing lateral movement while maintaining overall network functionality.
Solution Approach 2:
Different security measures are applied to different locations within the network based on intrusion detection. When malware is detected on a specific host, firewall restrictions are selectively applied to that host's communication with other hosts in the subnet, while other parts of the network continue to operate with normal security policies.
2Reliability
If security measures are applied to all hosts in the network, then security coverage is improved, but network performance degradation increases
Solution Approach 1:
Firewall restrictions are applied partially rather than universally. When an intrusion is detected, security measures are applied only to the specific subnet containing the compromised host and only to communications from that host to other hosts within the subnet, rather than applying restrictions across the entire network.
Solution Approach 2:
The network is segmented into subnets, and security restrictions are applied at the subnet level rather than network-wide. This allows isolated containment of security measures to affected areas while maintaining normal operations in unaffected subnets.
3Object-affected harmful factors
If firewall restrictions are applied to isolate compromised hosts, then attack propagation is prevented, but communication between legitimate hosts is blocked
Solution Approach 1:
Firewall restrictions are applied selectively to block only malicious communications while allowing legitimate traffic. The security system monitors network traffic and applies restrictions based on detected intrusion patterns, blocking only the specific communication paths used by malware while permitting normal host-to-host communication.
Solution Approach 2:
The security system continuously monitors network traffic and host behavior to detect intrusions. When malware communication patterns are detected, firewall rules are dynamically adjusted to block those specific communication paths while maintaining openness for legitimate traffic based on ongoing monitoring feedback.
Data Source
AI summary
A computer-implemented method for preventing internal network attacks may include 1) identifying a host system that is within a subnet of a network, 2) detecting an intrusion on the host system, the intrusion on the host system being capable of facilitating an attack via the host system on at least one additional system of the network, 3) identifying at least one additional host system within the subnet of the network, and 4) implementing a security measure on the additional host system to prevent the attack based at least in part on detecting the intrusion and at least in part on the host system and additional host system being within the subnet. Various other methods, systems, and computer-readable media are also disclosed.


