Moving Target Network Security via Dynamic Identity Parameter Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber infrastructure is vulnerable due to its static nature, allowing adversaries ample time to probe and exploit network vulnerabilities, as traditional security measures provide a fixed target for attackers.

Innovation Solution

Implementing Moving Target Technology (MTT) within computer networks to dynamically modify identity parameters such as IP addresses, MAC addresses, and port numbers in response to reactive trigger events, thereby changing communication patterns and network addresses, making it difficult for adversaries to infiltrate or map the network effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static network configurations and fixed identity parameters are used, then network infrastructure is simple and stable, but network security deteriorates because adversaries can probe and exploit vulnerabilities over time

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic modification of identity parameters (IP addresses, MAC addresses, port numbers) at network nodes in response to reactive trigger events. This transforms the static network configuration into a dynamic system where network identities and communication patterns continuously change, preventing adversaries from mapping and exploiting fixed vulnerabilities while maintaining operational stability through automated reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system pre-configures multiple identity parameters and communication paths in advance. When a reactive trigger event occurs (such as detecting a probe or attack), the system immediately switches to pre-prepared alternative configurations, enabling rapid response without requiring complex real-time decision-making or configuration changes during an active threat.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If dynamic modification of identity parameters is implemented, then network security improves by confusing attackers, but network operation complexity increases due to spontaneous reconfiguration

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network nodes autonomously detect reactive trigger events and automatically reconfigure their identity parameters without requiring manual intervention or complex centralized control. Each node independently monitors for attack indicators and executes pre-programmed reconfiguration routines, simplifying operation while maintaining dynamic security responses.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic and node states for reactive trigger events, using this feedback to dynamically adjust identity parameters. This closed-loop control enables automatic adaptation to threats while maintaining simple operation, as the system self-regulates based on real-time conditions without requiring complex external management.

Inventive Principle:
Principle #23Feedback

3Ease of manufacture

If fixed targets are used in traditional security measures, then security technologies can be deployed around specific assets, but vulnerability to attacks increases because attackers have unlimited time to probe and exploit

Engineering Contradiction:
Improvesecurity deployment simplicityVSAvoidresistance to cyber attacks
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent transforms fixed security targets into dynamic moving targets by continuously changing identity parameters at network nodes. Security measures remain simple to deploy around specific assets, but the assets themselves dynamically change their network identities and communication patterns, preventing attackers from probing and exploiting fixed vulnerabilities while maintaining ease of initial security deployment.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8898782B2Systems and methods for spontaneously configuring a computer network
Publication Date: 2014.11.25 HARRIS CORP
  • US8898782B2 patent drawing
  • US8898782B2 patent drawing
  • US8898782B2 patent drawing

AI summary

Systems (100) and methods (1300, 1400) for spontaneously configuring operations of a Computer Network (“CN”). The methods involve: configuring CN to operate in accordance with a first Mission Plan (“MP”); and detecting a reactive trigger event. The first MP specifies a manner in which an assigned value for an IDentity Parameter (“IDP”) is to be dynamically modified by a node (105-107, 113, 114) of CN. The reactive trigger event is a spontaneous event for causing a change to occur in relation to the dynamic modification of IDP. In response to the detection of the reactive trigger event, a second MP is selected. Thereafter, the operations of CN are automatically modified in accordance with the second MP plan such that IDP is dynamically modified in a manner that is different than that specified in the first MP.