Network Anti-tampering via Fabricated ARP Responses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting and preventing tampering with computer networks, such as pattern recognition, signal detection, and virtual execution, are static and non-adaptive, making them ineffective against determined attackers who can evade detection by using various combinations of malformed input.
Innovation Solution
A system that intercepts and responds to Address Resolution Protocol (ARP) messages by providing fabricated information, disrupting unauthorized access attempts by sending false ARP replies, thereby making it difficult for attackers to map network resources and communicate effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pattern recognition, signal detection, or virtual execution methods are used to detect tampering, then detection capability is provided, but attackers can evade detection by using various combinations of malformed input
Solution Approach 1:
The system dynamically alters network behavior by randomly changing ARP response behavior, IP address assignments, and network topology information in real-time. This dynamic adaptation prevents attackers from using static pattern recognition or predetermined evasion techniques, as the network characteristics continuously change during the attack window.
Solution Approach 2:
The system changes multiple network parameters simultaneously including ARP response timing, IP address allocations, MAC address assignments, and network topology information. By varying these parameters dynamically, the system ensures that malformed input patterns that work against static systems become ineffective against the adaptive network environment.
2Ease of manufacture
If static security mechanisms are implemented, then implementation simplicity is maintained, but effectiveness against determined attackers deteriorates
Solution Approach 1:
The system implements self-service security where the network automatically detects, responds to, and adapts against attacks without requiring external intervention. The network monitors its own state, identifies potential threats through anomalies in communication patterns, and autonomously adjusts its behavior to maintain security, combining simplicity with effectiveness.
3Reliability
If ARP messages are intercepted and fabricated responses are sent, then unauthorized access is disrupted, but network communication complexity increases
Solution Approach 1:
The system introduces an intermediary layer that sits between ARP requests and legitimate responses. This intermediary monitors ARP traffic, identifies suspicious patterns, and inserts fabricated responses to disrupt attacks. By positioning this security mechanism as an intermediary rather than modifying core protocol handling, the system maintains relatively simple implementation while achieving effective access control.
Data Source
AI summary
A system and method detects or prevents tampering of computer networks by transmitting address messages indicating that unused network addresses are in use. The systems and method handles requests for network resources, such as Address Resolution Protocol (ARP) messages, and provides fabricated information to a potential attacker to disrupt an attack on an information system.


