Geo-location Detector for Network Security Threat Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security management systems face difficulties in identifying the origin of computer network attacks due to variable and cloaked Internet Protocol (IP) addresses, making it challenging to obtain useful information for trend analysis and threat assessment.
Innovation Solution
A geo-location detector processes source addresses to generate a location identifier, which categorizes security threats based on geographical location, enabling correlation, trend analysis, and search key usage in network security assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If IP source address is used as identity for attack identification, then precise location information is obtained, but the information becomes unreliable due to variable and cloaked IP addresses
Solution Approach 1:
The patent introduces a geo-location database as an intermediary between the IP source address and the attacker identity. Instead of directly using the IP address as identity, the system queries the geo-location database to obtain geographic region information, which serves as a more reliable indicator of the attacker's origin. This intermediary layer resolves the contradiction by decoupling the transient IP address from the stable geographic location.
Solution Approach 2:
The patent changes the identification parameter from the IP source address (which is variable and unreliable) to geographic location information (which is more stable and reliable). By transforming the identification basis from network-layer addressing to geographic-region-based identification, the system achieves both reliability and useful precision for security analysis.
2Measurement precision
If geo-location detector is introduced to process source addresses, then location accuracy for threat assessment is improved, but system complexity increases
Solution Approach 1:
The patent segments the security analysis system into distinct functional modules: the original security event detection component and the newly added geo-location detector component. This segmentation allows the geo-location functionality to be added independently without redesigning the entire system, thereby managing complexity while improving location accuracy.
Solution Approach 2:
The geo-location detector acts as an intermediary component that processes source address information and enriches it with geographic context. By positioning this detector as a separate intermediary module in the data flow, the system achieves improved location accuracy without creating monolithic complexity, as each component remains independently manageable.
Data Source
AI summary
Information, e.g., a source address, in packets on a network is processed by a geo-location detector The geo-location detector generates a related location identifier, which, for example, is inclusive of one or more source addresses, known or unknown. The location identifier serves as a less precise indicator than the exact location of the system associated with the particular source address of interest, but a more accurate location indicator than was previously available. One of the addresses in a set of source addresses represented by the location identifier is the source address of interest. Although other source addresses represented by the location identifier may not be attacker sources, the location identifier is an identity that can be used as a variable for correlation, trend analysis, or search keys in accessing a network security threat.


