Network Data Tagging for Illicit Source Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Anonymizing processes, such as Tor and I2P, make it difficult for law enforcement to track and identify the source of illicit data, as they conceal the identity and location of individuals or organizations accessing computer networks, hindering investigations.

Innovation Solution

A method of tagging network data with a unique sequence of bits, injected into network packets, allowing law enforcement to identify and track unauthorized access by inserting tags into network traffic, even when anonymizing processes are used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anonymizing processes are used to conceal identity and location, then privacy and security are improved, but the ability to track and identify illicit data is worsened

Engineering Contradiction:
Improveprivacy protectionVSAvoidtracking ability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system applies preliminary action by inserting tracking tags into network packets before the data traverses anonymizing networks. These tags are embedded in advance in fields such as TCP window size or IP identification, allowing law enforcement to trace illicit data back to its source even after anonymization occurs. The tag insertion happens proactively at the point of detecting unauthorized access, before the criminal can fully exploit the anonymizing process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The tracking tag serves as an intermediary element that bridges the gap between anonymized data and its original source. By embedding these tags in network packets, the system creates a mediator that can be detected by intermediate systems along the network path, enabling identification of illicit data without requiring direct observation of the criminal's identity or location.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If network data is tagged with unique sequences to enable tracking, then the ability to identify illicit data is improved, but the complexity of the network system is worsened

Engineering Contradiction:
Improveidentification capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system applies local quality by modifying only specific fields within network packets rather than the entire data structure. Tags are inserted into localized areas such as TCP window size fields or IP identification fields, which are standard components of network protocols. This approach enables tracking functionality without fundamentally altering the overall network system architecture or requiring complex new infrastructure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The invention utilizes parameter changes by modifying existing network packet parameters to embed tracking information. Instead of creating entirely new complex systems, the patent changes the values of standard network parameters (such as TCP window size or IP identification fields) to include tag elements. This allows the system to leverage existing network infrastructure while adding tracking capability through parameter modification.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11743291B2Tagging network data
Publication Date: 2023.08.29 RIDGEBACK NETWORK DEFENSE INC
  • US11743291B2 patent drawing
  • US11743291B2 patent drawing
  • US11743291B2 patent drawing

AI summary

Systems and methods mark or identify network data as being of interest by modifying the network data with a tag. A tag may be an unordered set of tag elements, and each tag element may be an ordered sequence of bits. For each data segment or packet transmitted, one or more fields of a network packet may be masked with a randomly chosen tag element.