Transparent Security Appliance for High Availability Device Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
High availability devices in computer networks, such as those in wafer fabrication, banking, and medical applications, are vulnerable to virus attacks due to their inability to be taken offline for patch updates, leading to potential spread of malicious content within the network.
Innovation Solution
Deploying a low-cost, transparent security appliance with a scanning engine between high availability devices and network connections, which receives patch updates via removable storage or a secure server to block malicious content, allowing for continuous protection without requiring devices to be taken offline.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If high availability devices are kept online continuously, then device availability and operational continuity are improved, but vulnerability to virus attacks increases due to inability to apply patch updates
Solution Approach 1:
The patent introduces a transparent security appliance as an intermediary device positioned between the high availability device and the network. This appliance performs virus scanning and filtering of network traffic without requiring the high availability device to be taken offline, thus maintaining device availability while protecting against virus attacks through the intermediary's independent patch update capability
Solution Approach 2:
The security functionality is segmented into a separate transparent appliance distinct from the high availability device. This segmentation allows the appliance to be updated independently while the high availability device remains operational, resolving the contradiction by separating the update requirement from the device operation requirement
2Object-affected harmful factors
If traditional virus protection software is installed on high availability devices, then protection capability is improved, but device complexity and maintenance difficulty increase
Solution Approach 1:
By moving the virus protection functionality to an external transparent appliance, the patent reduces the complexity on the high availability device while maintaining protection capability. The appliance handles all scanning and filtering operations independently, simplifying the overall system architecture and reducing maintenance burden on critical devices
Solution Approach 2:
The patent implements a transparent copy of the network traffic that is scanned by the security appliance without modifying the original traffic flow to the high availability device. This copying approach allows virus detection and blocking without adding complexity to the device's operational software
3Object-affected harmful factors
If high availability devices are taken offline for patch updates, then virus protection effectiveness is improved, but device availability and operational continuity deteriorate
Solution Approach 1:
The transparent security appliance serves as a mediator that can be updated independently of the high availability device. Patch updates are applied to the appliance without affecting the operational status of the high availability device, thus maintaining both protection effectiveness and operational continuity simultaneously
Solution Approach 2:
The patent implements preliminary virus signature updates in the transparent appliance before they are needed by the high availability device. The appliance proactively receives and applies patch updates in advance, ensuring protection is already in place when new threats emerge, without requiring the high availability device to be taken offline
Data Source
AI summary
A technique for protecting a high availability device in a computer network includes deploying an appliance between the high availability device and a network connection. The high availability device may be a device configured for a manufacturing operation, such as wafer fabrication, for example. The appliance may be a transparent security appliance with a scanning engine for scanning packets for malicious content, such as computer viruses or worms, for example. Scanning control information can be supplied to the appliance by way of either a removable storage medium or a secure server coupled to the appliance, for example. The scanning control information can include a patch update, perhaps with signatures of viruses and associated control instructions. The appliance can then block any malicious content entering the appliance in response to the scanning control information. Among other advantages, the technique allows for low-cost, plug-and-play protection of high availability devices with good scalability to larger network configurations.


