Dynamic Router Address Manipulation for Moving Target Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber infrastructure is vulnerable due to its static nature, allowing adversaries ample time to probe and exploit network vulnerabilities, as traditional security measures like firewalls and intrusion detection systems provide a fixed target for attackers.

Innovation Solution

A router and method for dynamically manipulating identity parameters, such as IP and MAC addresses, using pseudorandom functions to create a moving target, thereby confusing adversaries and enhancing network security by varying communication patterns and network addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static network infrastructure is used, then network operations are simple and stable, but network security is vulnerable to attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic network address transformation (DYNAT) that continuously changes network address mappings between internal and external networks. The router dynamically translates internal network addresses to external addresses and vice versa, creating a moving target for attackers. This dynamic address translation prevents adversaries from mapping network vulnerabilities and exploiting static attack vectors.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the network address parameters dynamically over time. The address translation mappings are not fixed but are continuously updated, transforming the network's external appearance. This parameter change ensures that even if an attacker identifies a vulnerability at one moment, the network configuration has changed by the time the attack is executed.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic network address transformation is implemented, then network security is enhanced, but routing complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidrouter complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The router acts as an intermediary device that implements the dynamic address transformation. It sits between the internal network and external network, performing the complex translation operations without requiring changes to end systems. The router's translation layer handles the complexity internally while presenting simplified interfaces to both internal and external networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system employs feedback mechanisms where the router monitors incoming and outgoing traffic patterns and dynamically adjusts address translations based on observed communication flows. This feedback-driven approach allows the system to adapt to changing network conditions and maintain security while optimizing routing efficiency.

Inventive Principle:
Principle #23Feedback

3Difficulty of detecting and measuring

If pseudorandom route selection is used, then attacker mapping is confused, but routing determination becomes more complex

Engineering Contradiction:
Improveattacker network mapping difficultyVSAvoidrouting logic complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system implements periodic changes in address translation mappings and route selections. Rather than random changes, the transformations occur at regular intervals or in response to periodic triggers, creating predictable chaos that confuses attackers while allowing the system to maintain internal state consistency. This periodic action makes it difficult for attackers to establish stable mapping relationships.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8966626B2Router for communicating data in a dynamic computer network
Publication Date: 2015.02.24 HARRIS CORP
  • US8966626B2 patent drawing
  • US8966626B2 patent drawing
  • US8966626B2 patent drawing

AI summary

A router and methods for its use are disclosed. The router includes input and output circuitry for receiving and routing data packets to computing devices connected to the network. The router also includes a memory configured to store a number of tables relating the destinations of particular packets with routes for the packets to follow. The router is capable of correctly routing data packets which specify false identity parameters. The router is also capable of dynamically varying routing protocols used to route data packets. The router is also capable of routing data packets to one of a number of output ports based on a comparison of at least one of the identity parameters that specifies false information to a table stored in the router's memory.