Threat Management Server Network Device Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network systems are unable to preemptively identify and block unauthorized or malicious network devices, allowing them to extract data or perform malicious activities before detection, which compromises network security and data access control.
Innovation Solution
The system employs a threat management server that uses historical data to identify and block untrusted network devices from accessing the network by authenticating devices through a network authentication server and maintaining blacklists, isolating them within a safe zone for monitoring, and preventing reconnection attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional monitoring systems are used to detect malicious devices, then detection capability is provided, but the malicious device can already extract data and perform malicious activities before detection
Solution Approach 1:
The system performs preliminary actions by establishing baseline network behavior profiles for all devices before they can cause harm. Historical data collection and analysis are conducted continuously in the background, creating a repository of normal device behavior that enables rapid identification of deviations. This preliminary preparation allows the system to detect and respond to malicious activities immediately upon occurrence, rather than after damage has been done.
Solution Approach 2:
The system implements continuous feedback loops where network traffic is monitored, analyzed, and used to update behavioral profiles in real-time. When anomalies are detected, the system provides immediate feedback by triggering alerts and automated responses. This feedback mechanism ensures that the system learns from each incident and improves its detection capabilities continuously, maintaining high reliability while minimizing response time.
2Object-affected harmful factors
If the system blocks devices failing authentication, then unauthorized access is prevented, but legitimate devices may be incorrectly blocked
Solution Approach 1:
The system introduces behavioral analysis as an intermediary layer between authentication failure and blocking actions. Instead of directly blocking devices that fail authentication, the system first evaluates their historical behavior patterns, network traffic characteristics, and deviation from established baselines. This intermediary assessment mechanism reduces false positives by distinguishing between legitimate authentication issues and actual malicious activities, thereby maintaining ease of operation while preventing unauthorized access.
Solution Approach 2:
The system dynamically adjusts blocking parameters and thresholds based on contextual information. Rather than using fixed authentication failure counts, the system modifies blocking criteria based on behavioral risk scores, time-of-day patterns, and network conditions. This parameter adaptation allows the system to be more lenient with legitimate devices experiencing temporary issues while maintaining strict blocking for high-risk devices, balancing security with operational ease.
Data Source
AI summary
A system that includes a switch, a network authentication server (NAS), and a threat management server. The NAS sends a device identifier for an endpoint device to the threat management server in response to the endpoint device connecting to a port on the switch. The threat management server determines the endpoint device is present in a blacklist based on the device identifier in response to receiving the device identifier. The threat management server determines the endpoint device is blocked from one or more second ports on the switch. The threat management server blocks the endpoint device from accessing the network via the first port on the switch in response to determining the endpoint device is blocked from the one or more other ports on the switch.


