Network Node Address Hopping for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network protection technologies are inadequate in preventing service attacks that rely on discovering and exploiting network addresses, as they often limit network capabilities and are ineffective against advanced mapping and fingerprinting techniques.

Innovation Solution

Implementing a network address hopping method where a network node changes its address upon recognizing a trigger, using a 'hopping' scheme to establish logical channels and render nodes unreachable to most current exploits, optionally incorporating a honeypot for additional protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network protection technologies such as firewalls and virtual private networks are deployed to block discovery and exploitation, then network security is improved, but network capabilities are limited

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork capabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network node dynamically changes its network address over time through address hopping, transitioning from a static address to a dynamic, time-varying address. This allows the node to maintain security while preserving network capabilities, as the address changes are controlled and predictable for legitimate communications

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the network address parameter of the node periodically or based on triggers, transforming the address from a constant value to a time-dependent variable. This parameter change enables the node to evade discovery-based attacks while maintaining functional network access through coordinated address updates

Inventive Principle:
Principle #35Parameter changes

2Reliability

If existing tools are used to limit reachability and block malicious activity, then protection against exploitation is improved, but effectiveness against advanced mapping and fingerprinting techniques deteriorates

Engineering Contradiction:
Improveprotection against exploitationVSAvoidadvanced mapping and fingerprinting attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By implementing dynamic address hopping, the node becomes unpredictable to mapping and fingerprinting tools that rely on scanning and identifying static addresses. The continuous address changes render traditional discovery techniques ineffective while maintaining protection against exploitation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The address hopping mechanism operates periodically or based on time intervals, creating a rhythmic pattern of address changes that disrupts mapping and fingerprinting attempts. This periodic action ensures that attackers cannot establish persistent connections or accurately map the node's presence in the network

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8495738B2Stealth network node
Publication Date: 2013.07.23 LOCKHEED MARTIN CORP
  • US8495738B2 patent drawing
  • US8495738B2 patent drawing
  • US8495738B2 patent drawing

AI summary

A method, a network node, and a set of instructions are disclosed. A network interface 260 may have a precedent network address to represent the network node 104 in the network 100. A processor 210 may recognize an address hop trigger. The processor 210 may change to a successor network address to represent the network node 104 in the network 100.