Dynamic Dark IP Address Scheduling for Network Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in detecting stealthy and coordinated network intrusions, particularly when adversaries exploit the 'dark' IP address space, making it difficult to distinguish between normal and anomalous behavior.

Innovation Solution

A dynamic host configuration protocol (DHCP) server assigns network addresses based on a schedule that designates parts of the IP address space as 'dark' at various times, using machine learning-based classification engines to analyze network usage and identify anomalous behavior in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network monitoring is used to detect intrusions, then general network activity can be observed, but stealthy and coordinated attacks exploiting dark IP address space cannot be reliably detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidstealthy intrusion
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by scheduling and publishing dark IP address spaces in advance before actual attacks occur. The DHCP server pre-defines time windows during which specific IP addresses will be dark, and this schedule is published to the analytics engine beforehand, enabling proactive detection rather than reactive response

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring network traffic against the scheduled dark IP address patterns. The analytics engine compares observed network usage with expected dark space utilization, and when discrepancies are detected (such as unexpected activity during dark periods or patterns matching coordinated attacks), feedback is generated to alert security systems and trigger responses

Inventive Principle:
Principle #23Feedback

2Reliability

If the entire IP address space is monitored continuously, then all potential threats can be detected, but the complexity and resource consumption of the system increases significantly

Engineering Contradiction:
Improvesecurity detectionVSAvoidmonitoring system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the IP address space into dark and non-dark portions based on time windows and schedules. Instead of monitoring the entire IP address space continuously, the analytics engine focuses only on detecting activity within the scheduled dark IP address spaces, significantly reducing the monitoring scope and system complexity while maintaining detection effectiveness

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs periodic action by scheduling dark IP address spaces at specific time windows rather than continuously. The DHCP server and analytics engine operate on scheduled intervals, activating monitoring and dark space deployment only when needed according to the predetermined schedule, thereby reducing overall system complexity and resource consumption

Inventive Principle:
Principle #19Periodic action

3Object-affected harmful factors

If dark IP address spaces are used to hide adversary activity, then detection becomes more difficult, but this creates opportunities for misconfigured devices to generate false noise

Engineering Contradiction:
Improveadversary detection difficultyVSAvoidsignal-to-noise ratio
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system uses feedback to distinguish between adversary activity and misconfigured devices by comparing observed network behavior against expected patterns during dark periods. Legitimate misconfigurations produce predictable, isolated noise patterns, while coordinated attacks generate anomalous feedback signals that deviate from expected behavior, enabling the system to filter false positives while detecting real threats

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary characterization of normal network behavior and misconfiguration patterns before attacks occur. By establishing baseline expectations for how misconfigured devices behave during dark periods, the system can later distinguish between expected noise from misconfigurations and anomalous signals from coordinated attacks, preserving signal-to-noise ratio

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10812509B2Detecting anomolous network activity based on scheduled dark network addresses
Publication Date: 2020.10.20 MICRO FOCUS LLC
  • US10812509B2 patent drawing
  • US10812509B2 patent drawing
  • US10812509B2 patent drawing

AI summary

A technique includes dynamically assigning, by a server, network addresses selected from a plurality of network addresses to network devices of a network based on a schedule. The schedule represents a time during which a given network address is to remain unassigned. The technique includes, based on the schedule, detecting anomalous behavior associated with the network.