VPN Network Access Monitoring for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN systems are vulnerable to unauthorized access by compromised remote devices, allowing adversaries to access designated network segments without authorization.

Innovation Solution

A network access system that includes a computer executing machine instructions to receive and monitor network traffic from discrete VPN connections, storing it in a repository, and using network arbitration programs to validate client and server data through algorithms and manifests to establish encrypted, isolated VPN connections, ensuring only authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPN connections are established to provide remote access to network segments, then remote access capability is improved, but vulnerability to unauthorized access increases

Engineering Contradiction:
Improveremote access capabilityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network access system as an intermediary component between VPN connections and network segments. This system receives VPN traffic, validates it against security policies, and selectively permits or blocks access. The intermediary architecture maintains remote access functionality while adding a security layer that prevents unauthorized access to network segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network traffic monitoring is implemented to detect malicious actions, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network access system performs multiple functions within a single integrated architecture: receiving VPN traffic, validating security policies, monitoring for malicious actions, and controlling network access. By consolidating these functions into one system rather than separate components, the patent improves security detection capability while managing system complexity through functional integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250300968A1Network access system for detecting intrusions over a network
Publication Date: 2025.09.25 DARRIEN VENTURES LLC
  • US20250300968A1 patent drawing
  • US20250300968A1 patent drawing
  • US20250300968A1 patent drawing

AI summary

A network access system for detecting intrusions over a network. The network access system includes a computer having non-transitory memory for storing machine instructions that are to be executed by the computer. The machine instructions when executed by the computer implement the following functions: receive network traffic from one or more discrete virtual private network connections, store the network traffic in a repository, and monitor the network traffic for a malicious action.