Network Terminal Management Using ARP Probe Theft Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication networks, theft terminals that duplicate and use IP/MAC addresses of normal terminals cause IP conflicts and security issues like hacking and wiretapping, as existing systems lack effective methods to identify and block such malicious activity.

Innovation Solution

An apparatus and method that analyzes network packets to collect and store address data, uses ARP probe packets to identify theft terminals by comparing IP/MAC addresses, and applies automatic private IP addressing (APIPA) to reset the theft terminal's IP address, blocking network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IP/MAC addresses are used for terminal identification without verification procedures, then communication simplicity is improved, but network security deteriorates due to easy address duplication by malicious users

Engineering Contradiction:
Improvecommunication simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by collecting and storing address data of normal terminals before theft terminals can duplicate them. When an ARP probe packet is received, the system checks against pre-stored address data to identify theft terminals, preventing security breaches before they can cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by monitoring ARP probe packets and comparing them against stored address data. When a theft terminal is detected, the system provides feedback by transmitting reply packets that trigger APIPA function to reset the theft terminal's IP address, creating a closed-loop security response system.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If theft terminals are allowed to duplicate IP/MAC addresses, then device compatibility is improved, but network reliability deteriorates due to IP conflicts and security breaches

Engineering Contradiction:
Improvedevice compatibilityVSAvoidnetwork reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies preliminary anti-action by proactively detecting theft terminals through ARP probe packet analysis and comparing them against pre-stored address data. Before theft terminals can cause IP conflicts or security breaches, the system transmits reply packets that trigger IP address resetting, preventing harmful effects in advance.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system converts the harmful behavior of theft terminals into a beneficial detection mechanism. By analyzing ARP probe packets that theft terminals must send to obtain IP addresses, the system identifies and blocks these malicious devices, transforming their necessary communication protocol into a security detection opportunity.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If ARP probe packets are analyzed to identify theft terminals, then network security is improved, but system complexity increases due to additional packet analysis and address data management

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies self-service by utilizing existing network infrastructure and protocols to perform security functions. It uses standard ARP probe packets already present in network communication, leverages the APIPA function already built into terminal devices for IP address resetting, and employs existing packet analysis capabilities, thereby achieving enhanced security without requiring completely new complex systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12425365B2Apparatus and method for managing terminal in network
Publication Date: 2025.09.23 VIASCOPE INC
  • US12425365B2 patent drawing
  • US12425365B2 patent drawing
  • US12425365B2 patent drawing

AI summary

A method for managing a terminal, according to one embodiment, may comprise the steps of: collecting, from packets received from a plurality of terminals connected to a network, address data of the plurality of terminals and state information indicating a network connection state of each of the plurality of terminals; obtaining, from a received ARP probe packet, a first IP address and a first MAC address of a first terminal that has transmitted the ARP probe packet; and, when address data including the same IP address and MAC address as the first IP address and the first MAC address is retrieved from among pre-stored address data, determining whether the first terminal is a stolen terminal that has copied address data of another terminal, according to the state information of a terminal having the same address data as the first IP address and the first MAC address from among the plurality of terminals.