Dynamic Router Address Manipulation for Moving Target Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber infrastructure is vulnerable due to its static nature, allowing adversaries ample time to probe and exploit network vulnerabilities, as traditional security measures like firewalls and intrusion detection systems provide a fixed target for attackers.
Innovation Solution
A router and method for dynamically manipulating identity parameters, such as IP and MAC addresses, using pseudorandom functions to create a moving target, thereby confusing adversaries and enhancing network security by varying communication patterns and network addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static network infrastructure is used, then network operations are simple and stable, but network security is vulnerable to attacks
Solution Approach 1:
The patent implements dynamic network address transformation (DYNAT) that continuously changes network address mappings between internal and external networks. The router dynamically translates internal network addresses to external addresses and vice versa, creating a moving target for attackers. This dynamic address translation prevents adversaries from mapping network vulnerabilities and exploiting static attack vectors.
Solution Approach 2:
The system changes the network address parameters dynamically over time. The address translation mappings are not fixed but are continuously updated, transforming the network's external appearance. This parameter change ensures that even if an attacker identifies a vulnerability at one moment, the network configuration has changed by the time the attack is executed.
2Reliability
If dynamic network address transformation is implemented, then network security is enhanced, but routing complexity increases
Solution Approach 1:
The router acts as an intermediary device that implements the dynamic address transformation. It sits between the internal network and external network, performing the complex translation operations without requiring changes to end systems. The router's translation layer handles the complexity internally while presenting simplified interfaces to both internal and external networks.
Solution Approach 2:
The system employs feedback mechanisms where the router monitors incoming and outgoing traffic patterns and dynamically adjusts address translations based on observed communication flows. This feedback-driven approach allows the system to adapt to changing network conditions and maintain security while optimizing routing efficiency.
3Difficulty of detecting and measuring
If pseudorandom route selection is used, then attacker mapping is confused, but routing determination becomes more complex
Solution Approach 1:
The system implements periodic changes in address translation mappings and route selections. Rather than random changes, the transformations occur at regular intervals or in response to periodic triggers, creating predictable chaos that confuses attackers while allowing the system to maintain internal state consistency. This periodic action makes it difficult for attackers to establish stable mapping relationships.
Data Source
AI summary
A router and methods for its use are disclosed. The router includes input and output circuitry for receiving and routing data packets to computing devices connected to the network. The router also includes a memory configured to store a number of tables relating the destinations of particular packets with routes for the packets to follow. The router is capable of correctly routing data packets which specify false identity parameters. The router is also capable of dynamically varying routing protocols used to route data packets. The router is also capable of routing data packets to one of a number of output ports based on a comparison of at least one of the identity parameters that specifies false information to a table stored in the router's memory.


