VPN Network Access Monitoring for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN systems are vulnerable to unauthorized access by compromised remote devices, allowing adversaries to access designated network segments without authorization.
Innovation Solution
A network access system that includes a computer executing machine instructions to receive and monitor network traffic from discrete VPN connections, storing it in a repository, and using network arbitration programs to validate client and server data through algorithms and manifests to establish encrypted, isolated VPN connections, ensuring only authorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPN connections are established to provide remote access to network segments, then remote access capability is improved, but vulnerability to unauthorized access increases
Solution Approach 1:
The patent introduces a network access system as an intermediary component between VPN connections and network segments. This system receives VPN traffic, validates it against security policies, and selectively permits or blocks access. The intermediary architecture maintains remote access functionality while adding a security layer that prevents unauthorized access to network segments.
2Reliability
If network traffic monitoring is implemented to detect malicious actions, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The network access system performs multiple functions within a single integrated architecture: receiving VPN traffic, validating security policies, monitoring for malicious actions, and controlling network access. By consolidating these functions into one system rather than separate components, the patent improves security detection capability while managing system complexity through functional integration.
Data Source
AI summary
A network access system for detecting intrusions over a network. The network access system includes a computer having non-transitory memory for storing machine instructions that are to be executed by the computer. The machine instructions when executed by the computer implement the following functions: receive network traffic from one or more discrete virtual private network connections, store the network traffic in a repository, and monitor the network traffic for a malicious action.


