Network Whitelist Generation via Multi-Device Activity Intersection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current network security methods are inadequate in managing and applying whitelist information at scale, leading to a lack of trust in the Internet environment due to overwhelming digital compromise and the inability to keep up with rapid technological changes, resulting in a global imperative for secure Internet operations.

Innovation Solution

A system and method for generating a network whitelist by collecting and analyzing network transaction data from multiple devices to identify and intersect 'normal' activity addresses, creating a trustworthy neighborhood of Internet sources and destinations, and applying this whitelist to control network traffic and calculate risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional network security methods are used to identify and prevent malicious activity, then security coverage can be maintained, but the system cannot keep up with rapid technological changes and digital compromise at scale

Engineering Contradiction:
Improveability to adapt to technological changesVSAvoidspeed of responding to digital compromise
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent inverts the traditional security approach by shifting from blacklist-based prevention to whitelist-based verification. Instead of attempting to identify and block all malicious activity (which is impossible at scale), the system proactively establishes what constitutes normal, trusted network behavior through baseline profiling. This inversion allows the system to adapt to technological changes by continuously updating baselines rather than relying on static security rules that cannot keep pace with digital compromise.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system performs preliminary action by establishing network baselines and whitelists before malicious activity occurs. Through continuous monitoring and profiling of normal network transactions, the system creates predictive models of acceptable behavior in advance. This allows real-time detection and response to deviations from established patterns, enabling the system to respond rapidly to digital compromise without needing to analyze each new threat individually.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive network monitoring is implemented to generate accurate whitelists, then trustworthiness and security are improved, but system complexity and data processing requirements increase

Engineering Contradiction:
Improvetrustworthiness of network whitelistVSAvoidcomplexity of whitelist generation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by enabling network entities to automatically generate and maintain their own baseline profiles and whitelists through continuous monitoring of their normal transactions. The baseline generation process is automated, using statistical analysis of historical network data to identify patterns of normal behavior without requiring manual intervention. This self-service approach builds reliability through consistent, objective baseline establishment while managing complexity through automation rather than manual processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges multiple functions into a unified baseline generation system that simultaneously performs network monitoring, statistical analysis, baseline creation, and whitelist generation. By combining these functions into an integrated system rather than separate components, the patent reduces overall system complexity while maintaining high reliability. The merged system processes network transactions once and derives multiple security artifacts (baselines, whitelists, anomaly detections) from a single data pass, improving efficiency and reducing computational overhead.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If whitelist information is applied at scale across multiple network entities, then network security operations are optimized, but the ability to manage and apply whitelist information efficiently becomes a limiting factor

Engineering Contradiction:
Improveoptimization of network security operationsVSAvoidscalability of whitelist management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves universality by creating a scalable whitelist management platform that serves multiple network entities simultaneously through a centralized baseline generation service. The same baseline generation logic and whitelist management mechanisms are applied universally across different organizations and network configurations, allowing the system to scale efficiently. The standardized approach to baseline creation and whitelist application enables consistent security operations across diverse networks without requiring entity-specific customization, thereby optimizing productivity while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12088593B2System and method for trustworthy internet whitelists
Publication Date: 2024.09.10 SANCTUARY NETWORKS LLC
  • US12088593B2 patent drawing
  • US12088593B2 patent drawing
  • US12088593B2 patent drawing

AI summary

Information is received from a first networked device for a first user and from a second networked device for a second user. The first user and the second user are verified and registered. A first set of data for the first user and a second set of data for the second user that each specify one or more network parameters per network address that communicates with each user are received from a networked collector device. Addresses are selected from each of the first set and the second set where each of the one or more network parameters are above a first activity threshold level for that parameter. A first set and a second set of first level activity addresses are produced. A whitelist is generated for the first user from an intersection of the first set of first level activity addresses and the second set of first level activity addresses.