ARP Spoofing for Unauthorized Network Access Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network unauthorized access prevention systems are costly, require multiple hardware components like hubs and routers with varying filtering functions, and fail to prevent internal network access and fast data transmission protocols effectively.

Innovation Solution

A network unauthorized access preventing system that uses a single apparatus to send a false MAC address ARP response packet to unauthorized devices, preventing access by rewriting their ARP tables and not relying on specific hardware configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple hubs with filtering functions are deployed to prevent unauthorized access, then network security is improved, but system cost and complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts the access control function from multiple hubs and concentrates it in a single unauthorized access preventing apparatus. This apparatus independently determines whether packets are from unauthorized apparatuses and sends spoof ARP packets to prevent access, eliminating the need for filtering functions in each hub and reducing overall system complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The unauthorized access preventing apparatus acts as an intermediary between unauthorized apparatuses and the network. It intercepts ARP requests, determines authorization status, and sends spoof ARP response packets to prevent unauthorized access without requiring changes to existing hub functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If different companies provide hubs with varying filtering functions, then network compatibility is improved, but managing complexity and cost increase

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidmanaging complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The unauthorized access preventing apparatus provides a universal solution that works across networks with hubs from different companies. It implements a standardized ARP spoofing mechanism that is compatible with various hub types and filtering functions, eliminating the need for company-specific managing procedures

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If TCP reset packets are sent to prevent unauthorized access, then access prevention is achieved, but data transmission may be completed too quickly for the reset to take effect

Engineering Contradiction:
Improveaccess prevention effectivenessVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The invention performs preliminary action by sending spoof ARP response packets before the unauthorized apparatus can complete its data transmission. By corrupting the ARP table entries in advance, the apparatus ensures that subsequent data packets are sent to incorrect destinations, preventing data leakage even in fast protocols

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7552478B2Network unauthorized access preventing system and network unauthorized access preventing apparatus
Publication Date: 2009.06.23 NEC CORP
  • US7552478B2 patent drawing
  • US7552478B2 patent drawing
  • US7552478B2 patent drawing

AI summary

There is disclosed a network unauthorized access preventing system in which in a network to which one or more information processing apparatuses and a network unauthorized access preventing apparatus are connected, an unauthorized apparatus which is not authorized to access the network is prevented from accessing the network. The system includes an information processing apparatus which sends a correct ARP response packet to the unauthorized apparatus in response to an ARP request broadcast from the unauthorized apparatus, and a network unauthorized access preventing apparatus which sends an ARP response packet containing a false MAC address as the MAC address of the information processing apparatus to the unauthorized apparatus immediately after the correct ARP response packet is sent to the unauthorized apparatus.