Dynamic Network Address Transformation for Cyber Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber infrastructure is static, making it vulnerable to attacks as adversaries can probe networks for extended periods, map vulnerabilities, and capture data, while traditional security measures provide a fixed target for attackers.

Innovation Solution

Implementing dynamic network address transformation (DYNAT) and Moving Target Technology (MTT) to dynamically change identity parameters of packets, such as IP addresses and MAC addresses, based on a mission plan that is modified based on measured effectiveness to thwart cyber-attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static network infrastructure is used, then network stability and ease of operation are improved, but vulnerability to cyber-attacks increases

Engineering Contradiction:
Improvenetwork stabilityVSAvoidvulnerability to cyber-attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic network address transformation that continuously changes IP addresses, port numbers, and other network identifiers. This transforms the static network infrastructure into a dynamic system where identity parameters change over time, making it difficult for attackers to map vulnerabilities while maintaining network operational stability through controlled transformation processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system dynamically modifies network packet parameters including source and destination IP addresses, port numbers, and protocol identifiers. By changing these parameters in real-time according to transformation rules, the network presents a moving target to attackers while maintaining functional connectivity through coordinated parameter transformations.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If dynamic network address transformation is implemented, then vulnerability to cyber-attacks is reduced, but device complexity increases

Engineering Contradiction:
Improvevulnerability to cyber-attacksVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The complex transformation process is divided into separate functional modules: address transformation module, port transformation module, protocol handling module, and effectiveness measurement module. Each module handles specific aspects of the dynamic transformation, making the overall complex system manageable through functional segmentation and independent optimization of each component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system incorporates effectiveness measurement that monitors whether dynamic transformations are successfully preventing attacks. This feedback mechanism allows the system to adjust transformation parameters and strategies based on actual security performance, optimizing security while managing complexity through data-driven decision making.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If identity parameters are frequently transformed, then attacker's ability to map network is reduced, but loss of time for legitimate operations increases

Engineering Contradiction:
Improveattacker's mapping capabilityVSAvoidtime for legitimate operations
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system implements periodic transformation of identity parameters at controlled intervals rather than continuously. This periodic action is frequent enough to prevent attacker mapping but optimized to minimize disruption to legitimate operations. The transformation timing and frequency are adjusted based on security requirements and operational performance.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

Different transformation frequencies and strategies are applied to different network segments, protocols, or traffic types based on their specific security requirements and performance characteristics. This localized approach allows critical time-sensitive operations to use optimized transformation patterns while other segments use more aggressive transformation for maximum security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10547630B2Systems and method for providing dynamic computer networks in which goal induced dynamic modifications to mission plans occur
Publication Date: 2020.01.28 HARRIS CORP
  • US10547630B2 patent drawing
  • US10547630B2 patent drawing
  • US10547630B2 patent drawing

AI summary

Systems and methods for controlling operations of a computer network (100). The methods involve: generating programming instructions implementing a first mission plan (2100) specifying which identity parameters of packets are to be transformed during specific time periods; executing the programming instructions by at least one node (105) of the computer network to dynamically transform true values, which correctly represent the identity parameters of the packets, into false values which incorrectly represent the identity parameters of the packets; measuring an effectiveness of the computer network's behavior with regard to a recognition and prevention of cyber-attack success resulting from the execution of the programming instructions by the node; and dynamically modifying the first mission plan based on the measured effectiveness.