Network Data Tagging for Illicit Source Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Anonymizing processes, such as Tor and I2P, make it difficult for law enforcement to track and identify the source of illicit data, as they conceal the identity and location of individuals or organizations accessing computer networks, hindering investigations.
Innovation Solution
A method of tagging network data with a unique sequence of bits, injected into network packets, allowing law enforcement to identify and track unauthorized access by inserting tags into network traffic, even when anonymizing processes are used.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anonymizing processes are used to conceal identity and location, then privacy and security are improved, but the ability to track and identify illicit data is worsened
Solution Approach 1:
The system applies preliminary action by inserting tracking tags into network packets before the data traverses anonymizing networks. These tags are embedded in advance in fields such as TCP window size or IP identification, allowing law enforcement to trace illicit data back to its source even after anonymization occurs. The tag insertion happens proactively at the point of detecting unauthorized access, before the criminal can fully exploit the anonymizing process.
Solution Approach 2:
The tracking tag serves as an intermediary element that bridges the gap between anonymized data and its original source. By embedding these tags in network packets, the system creates a mediator that can be detected by intermediate systems along the network path, enabling identification of illicit data without requiring direct observation of the criminal's identity or location.
2Difficulty of detecting and measuring
If network data is tagged with unique sequences to enable tracking, then the ability to identify illicit data is improved, but the complexity of the network system is worsened
Solution Approach 1:
The system applies local quality by modifying only specific fields within network packets rather than the entire data structure. Tags are inserted into localized areas such as TCP window size fields or IP identification fields, which are standard components of network protocols. This approach enables tracking functionality without fundamentally altering the overall network system architecture or requiring complex new infrastructure.
Solution Approach 2:
The invention utilizes parameter changes by modifying existing network packet parameters to embed tracking information. Instead of creating entirely new complex systems, the patent changes the values of standard network parameters (such as TCP window size or IP identification fields) to include tag elements. This allows the system to leverage existing network infrastructure while adding tracking capability through parameter modification.
Data Source
AI summary
Systems and methods mark or identify network data as being of interest by modifying the network data with a tag. A tag may be an unordered set of tag elements, and each tag element may be an ordered sequence of bits. For each data segment or packet transmitted, one or more fields of a network packet may be masked with a randomly chosen tag element.


