FTTH Network Mitigating MAC Spoofing and DoS Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fiber-to-the-home network systems are vulnerable to media access control address spoofing and denial of service attacks, which hinder data services by making it difficult to identify the source of malicious packets and disrupt network operations.

Innovation Solution

Implementing a method that involves maintaining virtual addresses and inserting identifiers or codes into information packets to track and filter out spoofed MAC addresses and excessive packet flooding, allowing for the identification and isolation of source computers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If PPPoE protocol is used to allow multiple subscribers to share a common connection, then network resource utilization is improved, but the system becomes vulnerable to MAC address spoofing attacks and denial of service attacks

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidsecurity against spoofing and DoS attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by inserting unique identifiers into information packets before they are transmitted through the network. This proactive measure allows the system to track packet origins and detect spoofing or denial of service attacks before they can cause significant harm, thereby maintaining security while allowing multiple subscribers to share network resources

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (unique identifiers inserted into packets) that acts as a mediator between the PPPoE protocol and security requirements. This intermediary allows the system to maintain the benefits of resource sharing while adding a layer of security that can identify and isolate malicious activity without disrupting legitimate traffic

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If MAC address spoofing occurs, then attackers can hide their identity, but this makes source identification difficult and disrupts network management

Engineering Contradiction:
Improveanonymity of attackersVSAvoidsource identification difficulty
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary mechanism (unique identifiers inserted into packets) that acts as a mediator between the PPPoE protocol and security requirements. This intermediary allows the system to maintain the benefits of resource sharing while adding a layer of security that can identify and isolate malicious activity without disrupting legitimate traffic

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of relying on the original MAC address which can be spoofed, the system creates a copy mechanism by inserting unique identifiers into information packets. This copied identification method provides a reliable way to track packet origins and identify attackers even when MAC addresses are falsified

Inventive Principle:
Principle #26Copying

3Productivity

If excessive PADI packets are sent to a file server, then denial of service attack occurs, but detecting and isolating the source takes time and resources

Engineering Contradiction:
Improvenetwork traffic volumeVSAvoidtime to detect and isolate attacker
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by inserting unique identifiers into information packets before they are transmitted through the network. This proactive measure allows the system to track packet origins and detect spoofing or denial of service attacks before they can cause significant harm, thereby maintaining security while allowing multiple subscribers to share network resources

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where unique identifiers in packets provide immediate information about packet origins. When excessive traffic is detected, the system can quickly trace it back to the source using these identifiers, enabling rapid response and isolation of attackers without time-consuming investigation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8347075B1Methods to mitigate attacks against fiber-to-the-home network systems
Publication Date: 2013.01.01 VERIZON PATENT & LICENSING INC
  • US8347075B1 patent drawing
  • US8347075B1 patent drawing
  • US8347075B1 patent drawing

AI summary

The present invention provides methods to mitigate the problems associated with MAC address spoofing and denial of service attacks in an FTTH network system. The MAC address spoofing attack may occur when a computer hacker configures his computer to change the MAC address of a data signal to deceive the receiver of the signal's source address. The denial of service may occur when a computer hacker floods a file server with data packets. The present invention mitigates these attacks by modifying the software of certain components of the FTTH network system to enable the components to insert virtual MAC addresses, tags and codes into the data packets that identify a component of the communication related to the address of the source computer.