Stream Splitting Moving Target Defense for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber-attacks pose a significant threat to computing systems by intercepting and unauthorized capture of data, particularly through network sniffing and data acquisition, which existing technologies fail to adequately protect.

Innovation Solution

The implementation of stream splitting moving target defense (MTD) systems, which split data streams into multiple paths, encrypt, and resequence data units for secure transmission, utilizing redundant links for continuous uptime and failover, and employing cryptographic authentication to verify integrity and confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted through a single network path, then transmission speed is maintained, but data security and confidentiality are compromised due to interception risks

Engineering Contradiction:
Improvedata securityVSAvoidtransmission system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides a single data stream into multiple separate data streams, each transmitted through different network paths. This segmentation prevents any single interception point from capturing the complete data, thereby improving security while managing complexity through systematic distribution

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple paths are used for data transmission, then data security is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedata confidentialityVSAvoidpath management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces intermediary components including a stream splitter that divides data streams and a stream reassembler that reconstructs them at the destination. These intermediaries manage the complexity of multi-path transmission by providing structured interfaces for splitting, encrypting, and reassembling data, thereby improving confidentiality while controlling system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If data streams are split into multiple paths, then resistance to cyber-attacks is improved, but data transmission integrity becomes more difficult to maintain

Engineering Contradiction:
Improvecyber-attack resistanceVSAvoiddata transmission integrity
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the stream reassembler verifies the integrity of received data streams from multiple paths, identifies missing or corrupted segments, and requests retransmission as needed. This feedback loop maintains data transmission integrity while the multi-path structure provides resistance to cyber-attacks

Inventive Principle:
Principle #23Feedback

4Duration of action of stationary object

If redundant transmission paths are implemented, then system availability and uptime are improved, but resource consumption and bandwidth usage increase

Engineering Contradiction:
Improvesystem availabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
Duration of action of stationary objectVSUse of energy by moving object

Solution Approach 1:

The patent employs dynamic path selection and adaptive stream routing where data streams are actively directed through available paths based on real-time network conditions. This dynamic approach ensures system availability by adapting to changing network states while optimizing resource consumption by avoiding redundant transmissions through congested or failed paths

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10305868B2Stream splitting moving target defense
Publication Date: 2019.05.28 UCHICAGO ARGONNE LLC
  • US10305868B2 patent drawing
  • US10305868B2 patent drawing
  • US10305868B2 patent drawing

AI summary

Systems and methods for utilizing stream splitting Moving Target Defense (MTD) to provide enhanced computer system communication system security by splitting a data stream in to a plurality of paths is described. In some implementations, Stream splitting MTD, involves splitting a single data stream (e.g., TCP stream) into a plurality of discrete units, then sending and receiving those discrete units from and to different (ideally geographically disparate) receiving servers, with the stream being reassembled on the receiving end. The plurality of discrete units of data include resequencing data. The size of each discrete unit may vary depending on the specific implementation, even down to small unit sizes (e.g., a single packet).