Switch Port Leasing for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network systems are unable to preemptively identify and block malicious network devices, allowing unauthorized access and data leakage, as they typically detect malicious activity after it has occurred, limiting their ability to provide effective information security and data access control.
Innovation Solution
The system identifies and blocks potentially malicious network devices by comparing device and location information from device logs with actual switch data, activating temporary port leases based on device authentication status, and enabling port authentication to monitor and control access, thereby preventing malicious activities before they occur.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional detection systems are used to identify malicious network devices, then detection capability is provided, but detection occurs only after malicious activity has already taken place
Solution Approach 1:
The system performs preliminary actions by comparing device information against logs and assigning risk scores before malicious activity occurs. This allows the system to identify and block potentially malicious devices proactively, preventing data exfiltration and malicious activities before they can take place, rather than detecting them only after damage has been done.
Solution Approach 2:
The system applies preliminary anti-action by blocking network access for devices with high risk scores before they can perform malicious activities. This preemptive blocking prevents malicious devices from extracting data or performing harmful actions, directly counteracting potential threats before they materialize.
2Ease of operation
If network access is freely provided to all devices, then network usability is improved, but security vulnerability increases due to unauthorized access
Solution Approach 1:
The system applies local quality by providing differentiated network access based on individual device risk assessments. Rather than uniform access control, each device receives appropriate access rights according to its calculated risk score and authentication results, allowing legitimate devices full access while restricting potentially malicious ones.
Solution Approach 2:
The system changes the access parameter dynamically based on device risk scores. Devices undergo authentication and information comparison, and their network access rights are adjusted according to the results - high-risk devices are blocked while low-risk devices receive normal access, creating adaptive security control.
3Reliability
If comprehensive device monitoring is implemented to improve security detection, then security capability is enhanced, but system complexity increases
Solution Approach 1:
The system implements self-service by having devices automatically undergo authentication and information comparison processes without manual intervention. The automated workflow collects device information, compares it against logs, calculates risk scores, and makes access decisions autonomously, reducing the need for complex manual security management while maintaining high security capability.
Solution Approach 2:
The system uses feedback mechanisms where device information is continuously collected, compared against historical logs, and used to update risk assessments. This closed-loop feedback process enables the system to learn from past devices and improve its detection accuracy over time without requiring proportional increases in system complexity.
Data Source
AI summary
A system that includes a switch, a network authentication server (NAS), and a threat management server. The threat management server receives a port lease request for the endpoint device identifying a port and the endpoint device. The threat management server determines whether the endpoint device has previously failed authentication with the NAS. In response to determining the endpoint device has not previously failed authentication, the threat management server selects a first port lease duration when a device identifier for the endpoint device is present in the port lease. The threat management server selected a second port lease duration that is a shorter amount of time than the first port lease duration when the device identifier for the endpoint device is not present in the port lease request. The threat management server activates a port lease for the selected port lease duration.


