Automated Netblock Validation Through Statistical IP Sampling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures and tools are inadequate in addressing the increasing complexity and vulnerability of enterprise and internet service provider assets due to the rapid growth of online services, interconnected systems, and the rise in cyber-attacks, especially with the advent of digitization and 5G, leading to a larger 'attack surface' and exploitation of security vulnerabilities.
Innovation Solution
A method and system for automated validation of netblocks, using statistical methods and machine learning to efficiently identify and validate IP addresses belonging to a company, enabling comprehensive security assessments by clustering and validating netblocks, and utilizing external data sources for port scans to determine the validity of IP addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If automated validation of netblocks is implemented, then measurement precision of IP address ownership is improved, but device complexity increases
Solution Approach 1:
The validation process is divided into multiple stages: first checking RIR database records, then performing port scans only on netblocks that pass the initial check, and finally applying statistical evaluation only to a subset of IP addresses. This segmentation allows the system to achieve high measurement precision without requiring full computational resources to be used at every step.
Solution Approach 2:
The patent applies partial action by performing port scans on only a subset of IP addresses within a netblock rather than all addresses. The statistical evaluation method determines validity based on sampling a portion of the netblock, which reduces computational complexity while maintaining acceptable accuracy through statistical inference.
2Reliability
If comprehensive security assessments are performed on all netblocks, then reliability of security posture analysis is improved, but loss of time increases
Solution Approach 1:
The system performs preliminary checks using RIR database records before conducting more time-consuming port scans. Netblocks that fail the preliminary database check are eliminated immediately, preventing time loss on invalid netblocks. This preliminary filtering action ensures that subsequent comprehensive assessments are only performed on potentially valid netblocks.
Solution Approach 2:
Instead of assessing all IP addresses within valid netblocks, the patent uses statistical methods to evaluate a subset of addresses. This partial assessment approach maintains reliability of security posture analysis while significantly reducing the time required compared to exhaustive assessment of every IP address.
3Productivity
If statistical methods are used to validate netblocks, then productivity of validation process is improved, but measurement precision may be reduced
Solution Approach 1:
The statistical method validates a subset of IP addresses within a netblock rather than all addresses, improving productivity. The system determines netblock validity based on sampling, which accelerates the validation process while maintaining acceptable precision through statistical confidence intervals.
Solution Approach 2:
The validation process segments the netblock into multiple IP addresses and validates only a portion of them using statistical sampling. This segmentation enables the system to process larger numbers of netblocks efficiently while maintaining measurement precision through the statistical evaluation of the sampled subset.
Data Source
Figure 1
Figure 2
Figure 3a~3b
AI summary
The invention relates to techniques for automated validation of netblocks of IT-services and/or IT-systems, comprising the following steps performed by a computer system: - as an inputting step: inputting a netblock, wherein the netblock comprises multiple IP addresses as an address range; - as a validation step: validating IP Addresses of the netblock and calculate the number of valid IP Addresses to the number of invalid IP Addresses as a first result; - as an evaluation step: evaluating based on the outcome of the first result if a netblock is valid or invalid; - as a marking step: marking the netblock as valid or invalid based on evaluation.