Covert Routing Detection via Latency Perturbation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Covert routing in network systems is difficult to detect and prevent, as it involves secret cooperation between users or devices and covert routers, which can redirect traffic to restricted systems, making it challenging to identify malicious activity and distinguish it from non-malicious activity, especially when packet data is encrypted or inaccessible due to legal or contractual reasons.

Innovation Solution

A filtering device is used to perturb the routing path between local and remote computer systems, utilizing connection-oriented protocol responses to detect covert activity by comparing latency measurements and updating a fraud metric associated with potential malicious activity, and by temporarily changing routing preferences to avoid covert routers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If covert routing is used to redirect traffic, then access to restricted systems is achieved, but detection and prevention become difficult

Engineering Contradiction:
Improveaccess capabilityVSAvoiddetection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary actions by establishing a baseline routing path and measuring latency before any potential covert routing occurs. This baseline is stored and used for future comparison to detect deviations that indicate covert routing activity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors latency measurements and compares them against the baseline, providing feedback when deviations are detected. This feedback mechanism enables real-time detection of covert routing by identifying anomalies in round-trip time measurements

Inventive Principle:
Principle #23Feedback

2Reliability

If packet data is encrypted or inaccessible, then privacy and security are maintained, but monitoring and detection capabilities are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidmonitoring capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system uses latency measurements as an intermediary indicator to detect covert routing without needing to access or decrypt packet data. By measuring round-trip time as a proxy metric, the system can identify suspicious routing behavior while maintaining encryption and privacy protections

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If routing paths are perturbed to detect covert activity, then detection accuracy is improved, but network performance may be affected

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial probing actions by sending a limited number of test packets at intervals rather than continuously monitoring all traffic. This approach achieves sufficient detection accuracy while minimizing the impact on network performance and throughput

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10574682B2Latency-based detection of covert routing
Publication Date: 2020.02.25 AMAZON TECH INC
  • US10574682B2 patent drawing
  • US10574682B2 patent drawing
  • US10574682B2 patent drawing

AI summary

A method and apparatus for detecting covert routing is disclosed. In the method and apparatus, data addressed to a remote computer system are forwarded over a first network path, whereby the data is associated with a computer system of a plurality of computer systems. Further, a plurality of first network performance metrics is obtained. A likelihood of covert routing is determined based at least in part on the plurality of first network performance metrics.