Multicast Source IP Obfuscation via Intermediary Address Rewriting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing situational awareness applications can analyze source IP addresses of multicast packets to gather information about devices on a network, posing a security risk as the source addresses are visible, and there is a need to protect this information.
Innovation Solution
A method and device configuration to change the source IP address of multicast packets to an address other than the true source, obfuscating the origin, which can be implemented in a networking device's data plane to receive and forward packets, allowing for multiple or pseudo-random IP addresses to be assigned.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If source IP addresses of multicast packets are made visible for monitoring purposes, then situational awareness applications can perform traffic analysis to gather information about devices, but network security is compromised as device identities and locations can be elicited
Solution Approach 1:
The patent introduces a networking device as an intermediary between multicast sources and destinations. This device receives multicast packets with original source IP addresses, modifies the source address field to display a different IP address, and forwards the packets. The intermediary preserves the ability to monitor traffic while protecting the true source identities, thus resolving the contradiction between information visibility and security.
2Object-affected harmful factors
If source IP addresses are obfuscated to protect device identities, then network security is enhanced, but the ability to perform traffic analysis for situational awareness is reduced
Solution Approach 1:
The networking device acts as a mediator that simultaneously achieves both security and monitoring goals. It obfuscates source IP addresses to protect device identities while maintaining traffic flow information that can still be analyzed for situational awareness. The intermediary preserves packet metadata and routing information while replacing only the source address field, thus protecting security without completely eliminating analytical capabilities.
3Object-affected harmful factors
If multiple different source IP addresses are assigned to obfuscate the true source, then security is enhanced by making traffic analysis more difficult, but the complexity of the networking device increases
Solution Approach 1:
The patent employs parameter changes by modifying the source IP address field of multicast packets. The networking device changes this specific parameter to different values to obfuscate the true source. This targeted parameter modification provides security enhancement without requiring complex system-wide changes, thus resolving the contradiction between security improvement and device complexity.
Data Source
AI summary
A method of obfuscating a source of a multicast packet is provided. The method includes receiving a plurality of multicast packets at a first device from one or more second devices, the multicast packets received over one or more network links. A source internet protocol (IP) address of each multicast packet of the plurality of multicast packets is an IP address of the one or more second devices that sent the multicast packet. The source IP address of each of the plurality of multicast packets is changed to an IP address other than an IP address of the first device or an IP address of the one or more second devices. The plurality of multicast packets can then be sent.


