Dark Address Network Traffic Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection systems are ineffective in addressing the diverse and voluminous hacking attacks, particularly in virtual private networks (VPNs), which pose a significant security threat while increasing costs for network providers.
Innovation Solution
A method and system that utilize a 'dark address' space within a VPN to monitor and classify network traffic, employing a honeypot or decoy server to attract and identify unauthorized traffic, allowing for proactive detection and response to potential threats, including the use of unassigned IP addresses to set traps and gather data for enhanced security and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional intrusion detection systems are used to monitor network traffic, then security monitoring is provided, but the systems are unsuccessful due to the diversity and volume of hacking attacks
Solution Approach 1:
The patent segments the address space into dark addresses (unassigned, reserved for trapping) and regular addresses. This segmentation allows the system to isolate and monitor suspicious traffic by directing it to specific dark addresses, making the monitoring more effective against diverse attacks without overwhelming the entire system.
Solution Approach 2:
The patent introduces dark addresses as intermediary elements between the network traffic and the intrusion detection system. These dark addresses act as traps that intercept suspicious traffic before it reaches legitimate systems, allowing the IDS to analyze attack patterns without being directly targeted by the volume of attacks.
2Reliability
If VPN is used to provide secure connectivity, then security and cost-efficiency are improved, but the network becomes vulnerable to unauthorized attacks
Solution Approach 1:
The patent implements preliminary action by pre-assigning dark addresses to potential attack targets within the VPN address space. These dark addresses are reserved in advance and configured with trap rules before any attacks occur, enabling the system to proactively detect and respond to unauthorized access attempts rather than reacting after breaches occur.
Solution Approach 2:
The patent converts the vulnerability of the VPN to attacks into a benefit by using dark addresses as deliberate traps. Instead of trying to prevent all attacks, the system allows attacks to occur but directs them to dark addresses where they can be safely monitored and analyzed, transforming the harmful attack traffic into valuable security intelligence.
3Measurement precision
If dark addresses are used to monitor network traffic, then unauthorized traffic identification is improved, but the system complexity increases
Solution Approach 1:
The patent applies local quality by assigning specific properties to dark addresses that differ from regular addresses. Dark addresses have the property of being unassigned and reserved for trapping, while regular addresses have the property of being assigned to legitimate systems. This localized differentiation simplifies the monitoring system by creating clear distinctions between trap targets and legitimate resources.
Solution Approach 2:
The patent changes the parameter of address assignment by introducing a new state: unassigned dark addresses. This parameter change creates a distinct category of addresses that can be specifically targeted by trap rules, simplifying the identification and monitoring of unauthorized traffic without requiring complex analysis of all network traffic.
Data Source
AI summary
Described is a method of assigning a network address to a trap, the network address being a dark address of a virtual private network. The network traffic destined for the network address is monitored and a classification of the network traffic is determined. After the classification, a predetermined response is executed based on the classification of the traffic.


