Stealth Network Security Device Using Dynamic IP Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures, such as firewalls, can be detected by hackers, allowing them to probe and potentially breach the system, and current stealth firewalls may still be identifiable through changes in packet data, compromising network security.

Innovation Solution

A network security device dynamically assigns itself a temporary IP address using DNS resolution and intercepts data traffic without a separate IP address, remaining invisible to clients and hackers, while also resetting to factory defaults and handling invalid traffic and detecting worm propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall is installed to protect the network, then network security is improved, but the firewall can be detected by hackers allowing them to probe and potentially breach the system

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall detectability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a network security device that acts as an intermediary between the external network and the internal network. This device intercepts and analyzes packets before they reach the firewall, preventing hackers from directly probing the firewall. The security device modifies packet characteristics (such as time-to-live fields) to mask the firewall's presence, thereby improving security while reducing detectability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes key parameters of network packets, particularly the time-to-live (TTL) field, to prevent hacker detection. By dynamically adjusting packet TTL values and other characteristics, the security device makes it difficult for hackers to probe and detect the firewall's presence, thus resolving the contradiction between security effectiveness and stealth capability.

Inventive Principle:
Principle #35Parameter changes

2Difficulty of detecting and measuring

If a stealth firewall is used to remain undetectable, then firewall detectability is reduced, but the firewall may still be identifiable through changes in packet data

Engineering Contradiction:
Improvefirewall stealth capabilityVSAvoidpacket data integrity
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent segments the network security function into two parts: a network security device that handles packet interception and analysis, and the firewall that performs access control. This segmentation allows the security device to mask packet modifications, preventing hackers from detecting firewall presence through packet data changes while maintaining the firewall's stealth capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network security device serves as an intermediary that restores or modifies packet data (such as TTL fields) before packets reach the firewall. This intermediary function prevents information loss that would otherwise reveal the firewall's presence, thereby maintaining stealth capability without compromising packet integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the network security device intercepts and analyzes packets, then unauthorized access is prevented, but the device requires an IP address which compromises stealth

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiddevice visibility
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The network security device uses self-service mechanisms to obtain temporary IP addresses through DNS resolution when needed for packet interception, and then releases these addresses when not needed. This allows the device to perform security functions only when required, maintaining stealth during normal operation while preventing unauthorized access when threats are detected.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements dynamic IP address assignment where the network security device obtains and releases IP addresses based on real-time security needs. The device resolves DNS names to IP addresses when packet interception is required, uses the address for security analysis, then releases the address when complete. This dynamic behavior allows the device to maintain stealth during normal operation while providing security services when needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8181237B2Method for improving security of computer networks
Publication Date: 2012.05.15 JAPAN COMM INC
  • US8181237B2 patent drawing
  • US8181237B2 patent drawing
  • US8181237B2 patent drawing

AI summary

A method of preventing unauthorized user access to a computer network has been developed. The method includes receiving a domain name server resolution request at the computer network from a requesting user. Next a reply to the requesting user is generated with a domain name server resolution and internet protocol address of a target device within the computer network. The reply is inspected with a network security device, where the network security device does not have an assigned internet protocol address so that it remains undetected by the requesting user. The network security device then monitors data traffic to the computer network to detect a reply from the requesting user. Once detected, the reply to the internet protocol address is intercepted with the network security device. Finally, the network security device verifies that the requesting user is authorized to access the computer network with the network security device.