IP Address Controlling-Entity Tracking for Real-Time Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems fail to accurately determine the identity and security threat status of entities controlling Internet Protocol (IP) addresses in real-time, allowing cyberattacks to exploit multiple IP addresses from reputable providers, and there is a need for systems to verify entity identities and assess security threats to disposition data packets effectively.

Innovation Solution

A system that verifies the identity of entities controlling IP addresses by checking physical location, individual identities, and chain-of-control, determines a security threat status, and disposes data packets based on this status, using a computing platform to track and manage IP address provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion detection systems use lists of known malicious IP addresses, then they can block known threats, but they fail to detect new attacks from reputable providers

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary identity verification and security assessment on entities before they can use IP addresses for attacks. By verifying entity identities and determining security threat statuses in advance, the system proactively prevents malicious activities rather than merely reacting to known malicious IP addresses, thus improving both detection accuracy and adaptability to new threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary security verification layer between IP addresses and their controlling entities. Instead of directly trusting IP address ownership, the system uses identity verification mechanisms and security threat status databases as intermediaries to assess whether the entity controlling an IP address is legitimate, enabling detection of attacks from previously reputable providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system performs real-time identity verification of entities controlling IP addresses, then security threat detection improves, but system complexity increases

Engineering Contradiction:
Improvesecurity verification accuracyVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification system is segmented into distinct functional modules: entity identification module, identity verification module, security threat status determination module, and data packet disposition module. Each module performs a specific function, making the overall complex system manageable and maintainable while achieving high verification accuracy through specialized processing in each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system maintains its own security threat status database and performs self-verification by comparing entity identities against stored information. This self-service capability reduces dependency on external verification services, simplifying the system architecture while maintaining high reliability through autonomous security assessment.

Inventive Principle:
Principle #25Self-service

3Reliability

If the system tracks entity identities over time to detect changes, then security monitoring improves, but processing time increases

Engineering Contradiction:
Improvesecurity monitoring accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs periodic identity verification and security status updates at predetermined intervals rather than continuously monitoring every data packet. This periodic action maintains accurate security monitoring by refreshing entity identity information regularly while significantly reducing processing time compared to continuous real-time tracking of all network traffic.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system performs preliminary identity verification and stores security threat status information in advance before actual data packet processing occurs. This preliminary action creates a ready-reference database of verified entity identities, enabling rapid security decisions during data packet disposition without time-consuming verification during critical security events.

Inventive Principle:
Principle #10Preliminary action

4Object-affected harmful factors

If the system blocks data packets from entities with high security threat status, then network security improves, but legitimate traffic may be blocked

Engineering Contradiction:
Improvecyberattack preventionVSAvoidnetwork traffic flow
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system implements feedback mechanisms where data packet disposition decisions are continuously refined based on verified entity identities and security threat statuses. By providing feedback loops that allow for verification of entity legitimacy and adjustment of security threat assessments, the system minimizes false positives while maintaining strong protection against actual cyberattacks, thus balancing security with network traffic flow.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12418561B2System for tracking the controlling entity of internet protocol (IP) addresses and implementing security threat mitigation based on the controlling entity
Publication Date: 2025.09.16 BANK OF AMERICA CORP
  • US12418561B2 patent drawing
  • US12418561B2 patent drawing
  • US12418561B2 patent drawing

AI summary

Systematically verifying the identities of entities in control of Internet Protocol (IP) addresses and determining a security threat status for each of the entities based at least on the verified identity. As incoming data packets are received from an originating IP address, the entity in control of the originating IP address and their corresponding security threat status are identified and data packets are dispositioned i.e., blocked/dropped, sequestered or authorized for further transmission, based on the security threat status of the entity in control of the IP address.