Network Quarantine via VLAN Tag Relay Destruction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network quarantine systems fail to immediately isolate a terminal from the operation network even after the terminal is judged safe, as they allow connection until the quarantine agent is unlawfully uninstalled, leading to potential security breaches.
Innovation Solution
A network quarantine system comprising a quarantine agent, a relay device, and a quarantine server, where the server transmits a connection permission notification with a connection identifier and instructs the relay device to destroy information without the identifier, ensuring the terminal is not kept connected if the agent is uninstalled unlawfully, using VLAN tags to manage network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the terminal is allowed to connect to the operation network until the quarantine agent is unlawfully uninstalled, then the network security is compromised, but the connection stability is improved
Solution Approach 1:
The patent applies preliminary action by requiring the terminal to add a connection identifier (VLAN tag) to transmitted information before actual network communication occurs. The relay device is pre-configured to destroy information lacking this identifier, ensuring that if the quarantine agent is unlawfully uninstalled, the terminal immediately loses network access capability without requiring detection of the uninstallation event
Solution Approach 2:
The patent introduces a connection identifier (VLAN tag) as an intermediary element between the quarantine agent and the network communication. This identifier acts as a mediator that the relay device verifies for each transmitted packet, enabling automatic destruction of unauthorized traffic without direct monitoring of the quarantine agent's operational status
2Reliability
If the relay device destroys all information without connection identifier, then unauthorized access is prevented, but the device complexity increases
Solution Approach 1:
The patent applies local quality by making the relay device's information handling behavior dependent on the local presence of the connection identifier in each transmitted packet. Rather than implementing complex global security policies, the relay device simply checks for the local quality attribute (VLAN tag) in each packet and destroys or forwards accordingly, reducing overall system complexity
Data Source
AI summary
To isolate a terminal from a network immediately after a quarantine agent is uninstalled therefrom, a policy readout unit reads out a policy from a policy database and a policy check unit determines whether or not a terminal satisfies the policy that was read out. If it is determined that the terminal satisfies the read out policy, a quarantine server control unit instructs a bridge to destroy a packet with no VLAN tag among the packets sent from the terminal while controlling a quarantine agent to send a packet with a VLAN tag when sending the packet from the terminal.


