Network Intrusion Detection via Gateway IP Geolocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network intrusion detection mechanisms fail to geolocate and detect changes or falsification of geolocation of gateway network devices, making it difficult to identify potential network breaches, especially in wireless connections.

Innovation Solution

The system determines the geolocation of a network device using its public-facing IP address or other identifiers and compares it to an expected value to determine whether the geographic location is suspicious, employing a method that can be implemented across various coupling types, including wireless and wired connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network intrusion detection methods are used, then network security monitoring is performed, but the ability to detect geolocation-based intrusions is insufficient

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidgeolocation detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent uses IP address geolocation databases as an intermediary to translate network device IP addresses into geographic location information. This mediator enables the detection system to compare expected versus actual gelocations of network devices, thereby identifying potential intrusions without requiring direct geolocation measurement capabilities in the endpoint devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If geolocation comparison methods are implemented, then network intrusion detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidsystem implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal geolocation detection mechanism that works across multiple platform types (mobile devices, PCs, tablets) and network connection types (wireless, wired). The same core methodology of comparing expected versus actual geolocation derived from IP addresses is applied universally across different devices and scenarios, reducing the need for device-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-service by automatically obtaining the device's current geolocation through IP address lookup and comparing it with the expected geolocation of the network device. This automated comparison and alert generation eliminates the need for manual configuration or user intervention, simplifying the user experience while maintaining detection accuracy.

Inventive Principle:
Principle #25Self-service

3Reliability

If real-time geolocation monitoring is performed, then intrusion detection capability is enhanced, but energy consumption increases

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic geolocation monitoring rather than continuous monitoring. The system checks the geolocation of network devices at intervals (such as when connecting to new networks or at scheduled times) rather than continuously tracking location data. This periodic approach maintains intrusion detection capability while significantly reducing energy consumption compared to real-time continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10009316B1Method or mechanism for detecting network intrusion with gateway IP geolocation
Publication Date: 2018.06.26 GEN DIGITAL INC
  • US10009316B1 patent drawing
  • US10009316B1 patent drawing
  • US10009316B1 patent drawing

AI summary

A method for detecting network intrusion, performed by a processor is provided. The method includes coupling a computing or communication device to a network device and determining a geolocation of the network device. The method includes comparing the geolocation of the network device to an expected value and determining whether to connect to a network based on the comparing. A computer readable media containing instructions and a device are also provided.