Passive Network Sensor Emulating Client Addresses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital communication network security detection methods are often detectable by malicious actors, leading to detection avoidance actions, and require prior knowledge of network configurations, making them ineffective in hostile or contested environments.

Innovation Solution

A sensor device that can automatically discover and participate in network communications by determining and emulating network addresses, allowing it to monitor and filter data without being detectable, using a router to connect to an external network and adapt to changing conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If overt threat detection techniques are used, then detection capabilities are provided, but malicious actors can detect the presence and take avoidance actions

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection avoidance by malicious actors
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The sensor device uses an emulated network address of a legitimate client as an intermediary to mask its true identity. By routing communications through this intermediary address, the sensor can monitor network traffic and detect threats without malicious actors knowing it is a detection device, thus preventing detection avoidance actions

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The sensor creates a copy of a legitimate client's network address and uses this copied identity to participate in network communications. This copying allows the sensor to blend in with legitimate traffic, maintaining detection capabilities while avoiding detection by malicious actors who cannot distinguish the sensor from the emulated client

Inventive Principle:
Principle #26Copying

2Measurement precision

If prior knowledge of network configuration is required, then detection accuracy may be improved, but the method becomes ineffective in hostile or contested environments

Engineering Contradiction:
Improvedetection accuracyVSAvoideffectiveness in hostile environments
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The sensor device automatically discovers network addresses and configures itself by monitoring network traffic and identifying active clients. It performs reassessment to determine when emulated clients are no longer active and selects new targets autonomously. This self-service capability eliminates the need for prior network configuration knowledge while maintaining detection accuracy in hostile environments

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The sensor dynamically adapts to changing network conditions by continuously monitoring client activity and reassessing which addresses to emulate. When network conditions change or emulated clients become inactive, the sensor automatically updates its emulation targets. This dynamic adaptation maintains both detection accuracy and effectiveness in evolving hostile environments without requiring pre-configured network knowledge

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If the sensor emulates client addresses to remain undetected, then stealth is achieved, but network communication complexity increases

Engineering Contradiction:
Improvedetectability by malicious actorsVSAvoidcommunication emulation complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The sensor performs partial emulation by only copying network address identifiers (MAC addresses) rather than fully replicating client behavior and application-layer communications. This partial action achieves the essential stealth function of masking identity while avoiding the complexity of complete behavior emulation, maintaining simplicity in the communication mechanism

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12095625B2Passive assessment of signal relays amongst bystanders
Publication Date: 2024.09.17 PACKET FORENSICS LLC
  • US12095625B2 patent drawing
  • US12095625B2 patent drawing
  • US12095625B2 patent drawing

AI summary

Techniques for discovering a network using a sensor installed in the network, where the network is communicatively coupled to an external network by a router, are presented. The techniques can include: determining, automatically and by the sensor, a network address of the router; detecting, automatically and by the sensor, a network address of a client in the network; assessing, automatically and by the sensor, that the client in the network is actively communicating on the network; communicating, by the sensor, with the network address of the router; and participating, by the sensor, in communications on the network by emulating the network address of the client and by using the network address of the router.