Network Intrusion Detection via Gateway IP Geolocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network intrusion detection mechanisms fail to geolocate and detect changes or falsification of geolocation of gateway network devices, making it difficult to identify potential network breaches, especially in wireless connections.
Innovation Solution
The system determines the geolocation of a network device using its public-facing IP address or other identifiers and compares it to an expected value to determine whether the geographic location is suspicious, employing a method that can be implemented across various coupling types, including wireless and wired connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network intrusion detection methods are used, then network security monitoring is performed, but the ability to detect geolocation-based intrusions is insufficient
Solution Approach 1:
The patent uses IP address geolocation databases as an intermediary to translate network device IP addresses into geographic location information. This mediator enables the detection system to compare expected versus actual gelocations of network devices, thereby identifying potential intrusions without requiring direct geolocation measurement capabilities in the endpoint devices.
2Reliability
If geolocation comparison methods are implemented, then network intrusion detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal geolocation detection mechanism that works across multiple platform types (mobile devices, PCs, tablets) and network connection types (wireless, wired). The same core methodology of comparing expected versus actual geolocation derived from IP addresses is applied universally across different devices and scenarios, reducing the need for device-specific implementations.
Solution Approach 2:
The system performs self-service by automatically obtaining the device's current geolocation through IP address lookup and comparing it with the expected geolocation of the network device. This automated comparison and alert generation eliminates the need for manual configuration or user intervention, simplifying the user experience while maintaining detection accuracy.
3Reliability
If real-time geolocation monitoring is performed, then intrusion detection capability is enhanced, but energy consumption increases
Solution Approach 1:
The patent implements periodic geolocation monitoring rather than continuous monitoring. The system checks the geolocation of network devices at intervals (such as when connecting to new networks or at scheduled times) rather than continuously tracking location data. This periodic approach maintains intrusion detection capability while significantly reducing energy consumption compared to real-time continuous monitoring.
Data Source
AI summary
A method for detecting network intrusion, performed by a processor is provided. The method includes coupling a computing or communication device to a network device and determining a geolocation of the network device. The method includes comparing the geolocation of the network device to an expected value and determining whether to connect to a network based on the comparing. A computer readable media containing instructions and a device are also provided.


