Dynamic Network Identity Parameters for Moving Target Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security approaches provide a fixed target for attackers due to the static nature of computer networks, making them vulnerable to malicious probes and exploits, as they rely on static IP addresses and fixed network defenses.

Innovation Solution

Implementing a method that dynamically modifies identity parameters such as IP addresses and MAC addresses within a computer network using a mission plan, which can change the location and values of these parameters to create a moving target, thwarting adversary efforts by continuously altering the network's identity and communication patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static IP addresses and fixed network defenses are used, then network infrastructure is simple and easy to operate, but network security is vulnerable to malicious attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by making network identity parameters dynamic instead of static. IP addresses, MAC addresses, and other identifying characteristics are continuously changed according to a mission plan, transforming the network from a fixed target into a moving target that adversaries cannot easily map or exploit

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes network parameters dynamically by modifying identity parameters such as IP addresses, MAC addresses, and device characteristics according to a mission plan. These parameter changes occur without interrupting data communication, creating a dynamic defense mechanism that adapts to threats

Inventive Principle:
Principle #35Parameter changes

2Reliability

If identity parameters are dynamically modified, then network security is enhanced by creating a moving target, but network complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoididentity parameter management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network devices perform self-service by automatically modifying their own identity parameters according to the mission plan without requiring external intervention. Each device dynamically changes its characteristics independently, reducing the need for complex centralized management while enhancing security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mission plan is prepared in advance, outlining the sequence of identity parameter changes. This preliminary action allows the network to execute dynamic modifications systematically without requiring complex real-time decision-making, simplifying the management of network complexity

Inventive Principle:
Principle #10Preliminary action

3Reliability

If dynamic modification of identity parameters is implemented, then adversaries cannot easily map and exploit vulnerabilities, but data communication processes become more complex

Engineering Contradiction:
Improvenetwork defense capabilityVSAvoiddata communication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Identity parameters are modified periodically according to the mission plan, creating regular intervals of change. This periodic action disrupts adversary efforts to map the network while maintaining predictable communication patterns that simplify data transmission processes

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The mission plan acts as an intermediary that coordinates identity parameter changes across the network. It mediates between security requirements and communication needs, ensuring that dynamic modifications do not disrupt data flow while maintaining enhanced defense capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If the network uses fixed targets for security defenses, then the security architecture is simple, but it provides attackers with unlimited time to probe and exploit vulnerabilities

Engineering Contradiction:
Improvenetwork securityVSAvoidtime for adversaries to probe
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network transforms from a static target to a dynamic one by continuously changing identity parameters. This dynamics reduces the time adversaries have to probe and exploit vulnerabilities, as the target configuration changes before attackers can complete their analysis

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The rapid dynamic modification of identity parameters allows the network to skip through different configurations quickly, preventing adversaries from spending unlimited time probing a single static configuration. The network rushes through parameter changes faster than attackers can adapt

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentEP2813052B1Dynamic computer network with variable identity parameters
Publication Date: 2015.12.30 HARRIS CORP
  • EP2813052B1 patent drawingFigure 1
  • EP2813052B1 patent drawingFigure 2
  • EP2813052B1 patent drawingFigure 3

AI summary

Method for communicating data in a computer network (100) involves dynamically modifying at a first location (105) in the computer network a plurality of true values. The true values correctly represent the plurality of identity parameters. These true (120) values are transformed to false values (122), which incorrectly represent the identity parameters. Subsequently, the identity parameters are modified at a second location (106) to transform the false values (122) back to the true values (120). The position of the first and/or second locations varies dynamically as part of this process. A bridge (115) transforms identity parameter values when communicating outside the network. Dynamic modification of the identity parameters occurs in accordance with a mission plan that can be modified without interrupting communication of data in the network.