MitM Protection Module Detecting Packet Delay Anomalies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity measures are inadequate for protecting against man-in-the-middle (MitM) attacks in virtualized environments, where data traffic can be compromised, leading to potential data theft and security breaches.

Innovation Solution

A distributed MitM protection (MitMP) system that monitors data traffic using traffic probe packets to detect abnormal packet delays, decommissions compromised virtual machines, and creates fake data traffic to mislead attackers, while utilizing a distributed ledger for secure communication and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity measures are used in virtualized environments, then existing security protocols are maintained, but they are inadequate against MitM attacks and lead to potential data theft

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoiddata theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by continuously monitoring packet delay values and establishing baseline normal values before attacks occur. The MitMP module proactively detects abnormal delays and preemptively decommissions compromised virtual machines before data theft can complete, preventing rather than reacting to security breaches.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary MitMP module that sits between the virtual machine and the network communication. This module acts as a mediator that monitors traffic, detects MitM attacks through packet delay analysis, and intercepts compromised communications before data can be stolen, adding a protective layer without disrupting normal operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the MitMP module monitors data traffic using packet delay detection, then MitM attacks are detected, but the system complexity increases

Engineering Contradiction:
ImproveMitM attack detection capabilityVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The MitMP module performs self-service by autonomously monitoring its own environment, detecting attacks through packet delay measurements, and automatically decommissioning compromised virtual machines without requiring external intervention. The system serves itself by maintaining security through automated detection and response mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system detects MitM attacks by monitoring changes in packet delay parameters. The MitMP module measures packet delay values and compares them against established normal values, detecting attacks through parameter variation rather than complex protocol analysis, simplifying the detection mechanism while maintaining effectiveness.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If compromised virtual machines are decommissioned and traffic is rerouted, then security is maintained, but service continuity may be affected

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system establishes baseline packet delay values and detection thresholds in advance through preliminary monitoring. When attacks are detected, the pre-configured response mechanisms immediately decommission compromised machines and reroute traffic, minimizing service disruption by having response protocols ready beforehand rather than establishing them during the attack.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The MitMP module implements continuous feedback by monitoring packet delay values and automatically adjusting system state based on detected conditions. When abnormal delays indicate MitM attacks, the feedback loop triggers automatic decommissioning and traffic rerouting, then continues monitoring to ensure security while maintaining service through dynamic adaptation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11503069B2Protection against man-in-the-middle attacks in virtualization environments
Publication Date: 2022.11.15 AT&T INTELLECTUAL PROPERTY I L P
  • US11503069B2 patent drawing
  • US11503069B2 patent drawing
  • US11503069B2 patent drawing

AI summary

A man-in-the-middle protection module can monitor data traffic exchanged between a source and destination nodes over a source-destination link via a network. The module can utilize a traffic probe packet to determine a packet delay associated with the data traffic. The module can store the packet delay and can determine that the packet delay is greater than a normal packet delay. If so, the module can determine that an attacker has compromised the source-destination link. The module can command a virtual machine associated with the source node to be decommissioned. The module can instruct a virtualization orchestrator to create a new source node. The data traffic can be rerouted to be exchanged between the new source node and the destination node over a new source-destination link via the network. The module can create and send fake data traffic towards the MitM attacker over the source-destination link via the network.