Automated Netblock Validation Through Statistical IP Sampling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures and tools are inadequate in addressing the increasing complexity and vulnerability of enterprise and internet service provider assets due to the rapid growth of online services, interconnected systems, and the rise in cyber-attacks, especially with the advent of digitization and 5G, leading to a larger 'attack surface' and exploitation of security vulnerabilities.

Innovation Solution

A method and system for automated validation of netblocks, using statistical methods and machine learning to efficiently identify and validate IP addresses belonging to a company, enabling comprehensive security assessments by clustering and validating netblocks, and utilizing external data sources for port scans to determine the validity of IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If automated validation of netblocks is implemented, then measurement precision of IP address ownership is improved, but device complexity increases

Engineering Contradiction:
Improveaccuracy of security assessmentsVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The validation process is divided into multiple stages: first checking RIR database records, then performing port scans only on netblocks that pass the initial check, and finally applying statistical evaluation only to a subset of IP addresses. This segmentation allows the system to achieve high measurement precision without requiring full computational resources to be used at every step.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing port scans on only a subset of IP addresses within a netblock rather than all addresses. The statistical evaluation method determines validity based on sampling a portion of the netblock, which reduces computational complexity while maintaining acceptable accuracy through statistical inference.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If comprehensive security assessments are performed on all netblocks, then reliability of security posture analysis is improved, but loss of time increases

Engineering Contradiction:
Improvesecurity posture analysisVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary checks using RIR database records before conducting more time-consuming port scans. Netblocks that fail the preliminary database check are eliminated immediately, preventing time loss on invalid netblocks. This preliminary filtering action ensures that subsequent comprehensive assessments are only performed on potentially valid netblocks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of assessing all IP addresses within valid netblocks, the patent uses statistical methods to evaluate a subset of addresses. This partial assessment approach maintains reliability of security posture analysis while significantly reducing the time required compared to exhaustive assessment of every IP address.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If statistical methods are used to validate netblocks, then productivity of validation process is improved, but measurement precision may be reduced

Engineering Contradiction:
Improvevalidation efficiencyVSAvoidaccuracy of IP address validation
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The statistical method validates a subset of IP addresses within a netblock rather than all addresses, improving productivity. The system determines netblock validity based on sampling, which accelerates the validation process while maintaining acceptable precision through statistical confidence intervals.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The validation process segments the netblock into multiple IP addresses and validates only a portion of them using statistical sampling. This segmentation enables the system to process larger numbers of netblocks efficiently while maintaining measurement precision through the statistical evaluation of the sampled subset.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3968593B1Method of automated validation of netblocks of a company
Publication Date: 2025.07.02 DEUTSCHE TELEKOM AG
  • EP3968593B1 patent drawingFigure 1
  • EP3968593B1 patent drawingFigure 2
  • EP3968593B1 patent drawingFigure 3a~3b

AI summary

The invention relates to techniques for automated validation of netblocks of IT-services and/or IT-systems, comprising the following steps performed by a computer system: - as an inputting step: inputting a netblock, wherein the netblock comprises multiple IP addresses as an address range; - as a validation step: validating IP Addresses of the netblock and calculate the number of valid IP Addresses to the number of invalid IP Addresses as a first result; - as an evaluation step: evaluating based on the outcome of the first result if a netblock is valid or invalid; - as a marking step: marking the netblock as valid or invalid based on evaluation.