Network Anti-tampering via Fabricated ARP Responses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and preventing tampering with computer networks, such as pattern recognition, signal detection, and virtual execution, are static and non-adaptive, making them ineffective against determined attackers who can evade detection by using various combinations of malformed input.

Innovation Solution

A system that intercepts and responds to Address Resolution Protocol (ARP) messages by providing fabricated information, disrupting unauthorized access attempts by sending false ARP replies, thereby making it difficult for attackers to map network resources and communicate effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pattern recognition, signal detection, or virtual execution methods are used to detect tampering, then detection capability is provided, but attackers can evade detection by using various combinations of malformed input

Engineering Contradiction:
Improvedetection capabilityVSAvoidevasion capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically alters network behavior by randomly changing ARP response behavior, IP address assignments, and network topology information in real-time. This dynamic adaptation prevents attackers from using static pattern recognition or predetermined evasion techniques, as the network characteristics continuously change during the attack window.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple network parameters simultaneously including ARP response timing, IP address allocations, MAC address assignments, and network topology information. By varying these parameters dynamically, the system ensures that malformed input patterns that work against static systems become ineffective against the adaptive network environment.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If static security mechanisms are implemented, then implementation simplicity is maintained, but effectiveness against determined attackers deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system implements self-service security where the network automatically detects, responds to, and adapts against attacks without requiring external intervention. The network monitors its own state, identifies potential threats through anomalies in communication patterns, and autonomously adjusts its behavior to maintain security, combining simplicity with effectiveness.

Inventive Principle:
Principle #25Self-service

3Reliability

If ARP messages are intercepted and fabricated responses are sent, then unauthorized access is disrupted, but network communication complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidnetwork protocol handling
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary layer that sits between ARP requests and legitimate responses. This intermediary monitors ARP traffic, identifies suspicious patterns, and inserts fabricated responses to disrupt attacks. By positioning this security mechanism as an intermediary rather than modifying core protocol handling, the system maintains relatively simple implementation while achieving effective access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20220231987A1Network Anti-tampering system
Publication Date: 2022.07.21 RIDGEBACK NETWORK DEFENSE INC
  • US20220231987A1 patent drawing
  • US20220231987A1 patent drawing
  • US20220231987A1 patent drawing

AI summary

A system and method detects or prevents tampering of computer networks by transmitting address messages indicating that unused network addresses are in use. The systems and method handles requests for network resources, such as Address Resolution Protocol (ARP) messages, and provides fabricated information to a potential attacker to disrupt an attack on an information system.