Dynamic Network Defense via IP Address Reassignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber infrastructure is vulnerable due to its static nature, allowing adversaries ample time to probe and exploit network vulnerabilities, with traditional security measures providing a fixed target for attackers.

Innovation Solution

Implementing dynamic network defense systems that dynamically reassigned IP addresses and modify identity parameters (IDPs) based on mission plans, using access control techniques such as smart cards and user authentication to configure network behavior in real-time, thereby creating a moving target for attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional static network security measures (firewalls, intrusion detection systems) are deployed around fixed assets, then network security coverage is provided, but the network creates a fixed target for attackers that can be probed and exploited

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic network address transformation (DYNAT) where IP addresses and other network identifiers are dynamically reassigned and changed over time. Network nodes receive new identifiers periodically, transforming the static network into a dynamic one where attack targets continuously change location, thereby resolving the contradiction between providing security coverage and avoiding fixed targets for attackers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes network parameters (IP addresses, MAC addresses, port numbers) dynamically based on time, location, and mission requirements. By continuously modifying these parameters, the network maintains security coverage while preventing the creation of fixed attack targets, thus resolving the adaptability-reliability contradiction.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If dynamic network address transformation is implemented to confuse adversaries, then attacker effectiveness is reduced, but network complexity increases

Engineering Contradiction:
Improveattacker effectivenessVSAvoidnetwork complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The DYNAT system performs automatic IP address reassignment and network configuration without requiring manual intervention or complex centralized control. Network nodes autonomously receive and apply new identifiers based on pre-established algorithms, reducing the operational complexity burden while maintaining the dynamic security benefits against attackers.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of continuously complex reconfiguration, the system employs periodic reassignment of IP addresses and network parameters at predetermined intervals. This periodic action simplifies implementation compared to continuous dynamic changes, while still effectively confusing attackers who must constantly adapt to changing network topologies.

Inventive Principle:
Principle #19Periodic action

3Reliability

If access control information is verified before granting network access, then user authentication is ensured, but access time is delayed

Engineering Contradiction:
Improveuser authenticationVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Access control information and authentication credentials are verified and processed in advance before the user actually needs network access. By performing authentication actions preliminarily and caching valid credentials, the system ensures reliable authentication while minimizing actual access delay, as subsequent access requests can be granted more quickly.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10122708B2Systems and methods for deployment of mission plans using access control technologies
Publication Date: 2018.11.06 HARRIS CORP
  • US10122708B2 patent drawing
  • US10122708B2 patent drawing
  • US10122708B2 patent drawing

AI summary

Systems (100) and methods (1900) for configuring a computer network (“CN”). The methods comprise: receiving Access Control Information (“ACI”) input to a first network node (101-103, 105-107) by a user assigned to a mission; verifying that the user has a right to have access to the CN (100) based on the ACI; granting the user access to CN in response to the verifying; and obtaining Mission Related Information (“MRI”) by the first network node. The MRI is associated with the user and at least identifies a first mission plan (120) specifying a manner in which an assigned value for at least one first identity parameter is to be dynamically modified by at least one node (105-107, 113, 114) of CN. Thereafter, the first network node or a second network node (105-107, 113, 114) of CN is configured to operate in accordance with the first mission plan.