Digital Certificate Reputation System for IP Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems face challenges in effectively identifying and mitigating risks associated with IP addresses that frequently change, as malicious actors use valid digital certificates to evade detection, and digital certificates from reputable sources may be compromised or improperly issued, leading to inconsistencies that complicate security assessments.

Innovation Solution

Implementing a digital certificate reputation system that assesses the security risk level of IP addresses by correlating received IP addresses with known malicious addresses and analyzing digital certificates for inconsistencies, assigning risk levels based on reputation and usage history to inform security policies and enhance network protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP address blacklisting is used to prevent communication with malicious sites, then security protection is improved, but malicious actors can evade detection by frequently changing IP addresses

Engineering Contradiction:
Improvesecurity protectionVSAvoidevasion capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces digital certificates as an intermediary identifier to bridge the gap between IP addresses and trusted entities. Instead of relying solely on IP addresses which change frequently, the system uses digital certificates as a stable mediator that binds identity to communication, allowing consistent tracking and reputation assessment across multiple IP addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension to security assessment by incorporating digital certificate information alongside IP address reputation. This multi-dimensional approach evaluates both the network layer (IP address) and the application/identity layer (digital certificate), creating a more robust security framework that cannot be easily evaded through IP changes alone.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If digital certificates from reputable sources are trusted, then authentication is improved, but compromised or improperly issued certificates create security inconsistencies

Engineering Contradiction:
ImproveauthenticationVSAvoidsecurity assessment accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where digital certificates are continuously monitored and evaluated based on the reputation of associated IP addresses and communication patterns. When inconsistencies or compromises are detected, the system provides feedback to revoke or downgrade certificate trust, creating a dynamic authentication system that adapts to emerging threats.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary verification and reputation assessment of digital certificates before fully trusting them for authentication. By pre-evaluating certificate validity, issuer reputation, and associated IP address trustworthiness, the system prevents compromised certificates from being accepted, thereby maintaining authentication reliability despite the existence of potentially malicious certificates.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security policies are strictly enforced to block malicious communications, then network security is improved, but legitimate communications may be inadvertently blocked

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication flow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing differentiated security policies based on the specific reputation scores of individual IP addresses and digital certificates. Instead of uniform blocking, the system assigns varying levels of trust and applies appropriate security measures locally to each communication entity, allowing legitimate traffic to flow smoothly while blocking only truly malicious communications.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11516206B2Cybersecurity system having digital certificate reputation system
Publication Date: 2022.11.29 FORCEPOINT LLC
  • US11516206B2 patent drawing
  • US11516206B2 patent drawing
  • US11516206B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for implementing a cybersecurity system having a digital certificate reputation system. At least one embodiment is directed to a computer-implemented method executing operations including receiving a communication having an internet protocol (IP) address and a digital certificate at a device within the secured network; determining whether the IP address is identified as having a high-security risk level; if the IP address has a high-security risk level, assigning a security risk level to the digital certificate based on the security risk level of the IP address; and using the security risk level for the digital certificate in executing the one or more security policies. Other embodiments include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices.