Dynamic Hostname Generation for Network Asset Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access methods for network assets are vulnerable to malicious activities due to static architectures, which do not effectively prevent exposure to denial of service attacks and unauthorized access.

Innovation Solution

A system utilizing a fully qualified domain name with a unique and temporary hostname, generated by both client and server modules, creates temporary virtual machines that act as servers or firewalls, dynamically updating DNS records to enhance security by changing access points periodically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional static access methods are used for network assets, then ease of operation is improved, but security is worsened due to exposure to malicious activities

Engineering Contradiction:
Improveaccess to network assetsVSAvoidsecurity of network assets
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access points by periodically generating new Fully Qualified Domain Names (FQDNs) that resolve to different IP addresses. Instead of using static hostnames or IP addresses, the system creates time-limited FQDNs that automatically expire and are replaced, making the access infrastructure dynamic and resistant to static exploitation by attackers

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic regeneration of access points through automated FQDN creation and expiration cycles. The access infrastructure is continuously renewed with new FQDNs that have limited validity periods, creating a rhythmic pattern of access point rotation that prevents long-term exploitation while maintaining operational continuity

Inventive Principle:
Principle #19Periodic action

2Device complexity

If static architecture is used for network access, then device complexity is reduced, but security is worsened due to vulnerability to denial of service attacks

Engineering Contradiction:
Improveaccess architectureVSAvoiddenial of service attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the static access architecture into a dynamic system where FQDNs are periodically regenerated and resolved to different IP addresses. This dynamic behavior prevents attackers from maintaining persistent denial of service attacks, as the target addresses change over time while the underlying network assets remain accessible to authorized users

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If permanent access points are used for network assets, then ease of operation is improved, but security is worsened due to easy targeting by malicious bots

Engineering Contradiction:
Improvelocation and access to network assetsVSAvoidscanning by bots
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements periodic FQDN regeneration that causes access points to change at regular intervals. This periodic transformation makes it difficult for scanning bots to identify and target network assets, as the FQDNs they discover become invalid by the time they attempt exploitation, while legitimate users experience no disruption due to automated FQDN distribution

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11863565B2System and method for securing access to network assets
Publication Date: 2024.01.02 TACTIKA COM INC
  • US11863565B2 patent drawing
  • US11863565B2 patent drawing
  • US11863565B2 patent drawing

AI summary

A system for securing access to a network asset and including a launcher and a master each configure to generate a new unique and temporary hostname and virtual machines each having an IP address associated to a corresponding generated unique, secret and temporary hostname. Each virtual machine operates either as a server hosting the network asset or a reverse proxy or a firewall between a client device having the launcher stored in the memory thereof and the corresponding network asset. A new virtual machine is created each time a new hostname is generated and is destructed after the corresponding hostname expires. The system also includes a DNS server storing a database of host records each including a public IP address of one of the virtual machines and the corresponding hostname, the database of host records being updated each time a new virtual machine is created in a DNS domain.