Stream Splitting Moving Target Defense for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cyber-attacks pose a significant threat to computing systems by intercepting and unauthorized capture of data, particularly through network sniffing and data acquisition, which existing technologies fail to adequately protect.
Innovation Solution
The implementation of stream splitting moving target defense (MTD) systems, which split data streams into multiple paths, encrypt, and resequence data units for secure transmission, utilizing redundant links for continuous uptime and failover, and employing cryptographic authentication to verify integrity and confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is transmitted through a single network path, then transmission speed is maintained, but data security and confidentiality are compromised due to interception risks
Solution Approach 1:
The patent divides a single data stream into multiple separate data streams, each transmitted through different network paths. This segmentation prevents any single interception point from capturing the complete data, thereby improving security while managing complexity through systematic distribution
2Reliability
If multiple paths are used for data transmission, then data security is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent introduces intermediary components including a stream splitter that divides data streams and a stream reassembler that reconstructs them at the destination. These intermediaries manage the complexity of multi-path transmission by providing structured interfaces for splitting, encrypting, and reassembling data, thereby improving confidentiality while controlling system complexity
3Object-affected harmful factors
If data streams are split into multiple paths, then resistance to cyber-attacks is improved, but data transmission integrity becomes more difficult to maintain
Solution Approach 1:
The patent implements feedback mechanisms where the stream reassembler verifies the integrity of received data streams from multiple paths, identifies missing or corrupted segments, and requests retransmission as needed. This feedback loop maintains data transmission integrity while the multi-path structure provides resistance to cyber-attacks
4Duration of action of stationary object
If redundant transmission paths are implemented, then system availability and uptime are improved, but resource consumption and bandwidth usage increase
Solution Approach 1:
The patent employs dynamic path selection and adaptive stream routing where data streams are actively directed through available paths based on real-time network conditions. This dynamic approach ensures system availability by adapting to changing network states while optimizing resource consumption by avoiding redundant transmissions through congested or failed paths
Data Source
AI summary
Systems and methods for utilizing stream splitting Moving Target Defense (MTD) to provide enhanced computer system communication system security by splitting a data stream in to a plurality of paths is described. In some implementations, Stream splitting MTD, involves splitting a single data stream (e.g., TCP stream) into a plurality of discrete units, then sending and receiving those discrete units from and to different (ideally geographically disparate) receiving servers, with the stream being reassembled on the receiving end. The plurality of discrete units of data include resequencing data. The size of each discrete unit may vary depending on the specific implementation, even down to small unit sizes (e.g., a single packet).


