Dynamic Network Identity Parameters for Moving Target Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber security approaches provide a fixed target for attackers due to the static nature of computer networks, making them vulnerable to malicious probes and exploits, as they rely on static IP addresses and fixed network defenses.
Innovation Solution
Implementing a method that dynamically modifies identity parameters such as IP addresses and MAC addresses within a computer network using a mission plan, which can change the location and values of these parameters to create a moving target, thwarting adversary efforts by continuously altering the network's identity and communication patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static IP addresses and fixed network defenses are used, then network infrastructure is simple and easy to operate, but network security is vulnerable to malicious attacks
Solution Approach 1:
The patent applies dynamics by making network identity parameters dynamic instead of static. IP addresses, MAC addresses, and other identifying characteristics are continuously changed according to a mission plan, transforming the network from a fixed target into a moving target that adversaries cannot easily map or exploit
Solution Approach 2:
The patent changes network parameters dynamically by modifying identity parameters such as IP addresses, MAC addresses, and device characteristics according to a mission plan. These parameter changes occur without interrupting data communication, creating a dynamic defense mechanism that adapts to threats
2Reliability
If identity parameters are dynamically modified, then network security is enhanced by creating a moving target, but network complexity increases
Solution Approach 1:
The network devices perform self-service by automatically modifying their own identity parameters according to the mission plan without requiring external intervention. Each device dynamically changes its characteristics independently, reducing the need for complex centralized management while enhancing security
Solution Approach 2:
The mission plan is prepared in advance, outlining the sequence of identity parameter changes. This preliminary action allows the network to execute dynamic modifications systematically without requiring complex real-time decision-making, simplifying the management of network complexity
3Reliability
If dynamic modification of identity parameters is implemented, then adversaries cannot easily map and exploit vulnerabilities, but data communication processes become more complex
Solution Approach 1:
Identity parameters are modified periodically according to the mission plan, creating regular intervals of change. This periodic action disrupts adversary efforts to map the network while maintaining predictable communication patterns that simplify data transmission processes
Solution Approach 2:
The mission plan acts as an intermediary that coordinates identity parameter changes across the network. It mediates between security requirements and communication needs, ensuring that dynamic modifications do not disrupt data flow while maintaining enhanced defense capabilities
4Reliability
If the network uses fixed targets for security defenses, then the security architecture is simple, but it provides attackers with unlimited time to probe and exploit vulnerabilities
Solution Approach 1:
The network transforms from a static target to a dynamic one by continuously changing identity parameters. This dynamics reduces the time adversaries have to probe and exploit vulnerabilities, as the target configuration changes before attackers can complete their analysis
Solution Approach 2:
The rapid dynamic modification of identity parameters allows the network to skip through different configurations quickly, preventing adversaries from spending unlimited time probing a single static configuration. The network rushes through parameter changes faster than attackers can adapt
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Method for communicating data in a computer network (100) involves dynamically modifying at a first location (105) in the computer network a plurality of true values. The true values correctly represent the plurality of identity parameters. These true (120) values are transformed to false values (122), which incorrectly represent the identity parameters. Subsequently, the identity parameters are modified at a second location (106) to transform the false values (122) back to the true values (120). The position of the first and/or second locations varies dynamically as part of this process. A bridge (115) transforms identity parameter values when communicating outside the network. Dynamic modification of the identity parameters occurs in accordance with a mission plan that can be modified without interrupting communication of data in the network.