Dark Address Network Traffic Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems are ineffective in addressing the diverse and voluminous hacking attacks, particularly in virtual private networks (VPNs), which pose a significant security threat while increasing costs for network providers.

Innovation Solution

A method and system that utilize a 'dark address' space within a VPN to monitor and classify network traffic, employing a honeypot or decoy server to attract and identify unauthorized traffic, allowing for proactive detection and response to potential threats, including the use of unassigned IP addresses to set traps and gather data for enhanced security and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional intrusion detection systems are used to monitor network traffic, then security monitoring is provided, but the systems are unsuccessful due to the diversity and volume of hacking attacks

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoiddiversity and volume of hacking attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the address space into dark addresses (unassigned, reserved for trapping) and regular addresses. This segmentation allows the system to isolate and monitor suspicious traffic by directing it to specific dark addresses, making the monitoring more effective against diverse attacks without overwhelming the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dark addresses as intermediary elements between the network traffic and the intrusion detection system. These dark addresses act as traps that intercept suspicious traffic before it reaches legitimate systems, allowing the IDS to analyze attack patterns without being directly targeted by the volume of attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If VPN is used to provide secure connectivity, then security and cost-efficiency are improved, but the network becomes vulnerable to unauthorized attacks

Engineering Contradiction:
ImproveVPN security and cost-efficiencyVSAvoidunauthorized attacks on VPN
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-assigning dark addresses to potential attack targets within the VPN address space. These dark addresses are reserved in advance and configured with trap rules before any attacks occur, enabling the system to proactively detect and respond to unauthorized access attempts rather than reacting after breaches occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the vulnerability of the VPN to attacks into a benefit by using dark addresses as deliberate traps. Instead of trying to prevent all attacks, the system allows attacks to occur but directs them to dark addresses where they can be safely monitored and analyzed, transforming the harmful attack traffic into valuable security intelligence.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Measurement precision

If dark addresses are used to monitor network traffic, then unauthorized traffic identification is improved, but the system complexity increases

Engineering Contradiction:
Improveunauthorized traffic identificationVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning specific properties to dark addresses that differ from regular addresses. Dark addresses have the property of being unassigned and reserved for trapping, while regular addresses have the property of being assigned to legitimate systems. This localized differentiation simplifies the monitoring system by creating clear distinctions between trap targets and legitimate resources.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of address assignment by introducing a new state: unassigned dark addresses. This parameter change creates a distinct category of addresses that can be specifically targeted by trap rules, simplifying the identification and monitoring of unauthorized traffic without requiring complex analysis of all network traffic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7657735B2System and method for monitoring network traffic
Publication Date: 2010.02.02 AT&T CORP
  • US7657735B2 patent drawing
  • US7657735B2 patent drawing
  • US7657735B2 patent drawing

AI summary

Described is a method of assigning a network address to a trap, the network address being a dark address of a virtual private network. The network traffic destined for the network address is monitored and a classification of the network traffic is determined. After the classification, a predetermined response is executed based on the classification of the traffic.