Subnet Threat Scoring for NAT-Aware Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security vulnerabilities present opportunities for cyber attackers, leading to significant data breaches and high detection and escalation costs, with existing solutions like NAT and CGNAT failing to effectively identify and mitigate threats from subnets.

Innovation Solution

A system and method for threat policy fine-tuning that involves detecting internet protocol addresses in a subnet, computing threat metrics, determining threat scores based on these metrics, and sending representative threat scores to indicate vulnerabilities as sources of malicious attacks, using a Compute, Analysis, and Reputation components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If NAT and CGNAT are used to share public IP addresses, then IPv4 exhaustion is solved and network connectivity is maintained, but the ability to identify and mitigate threats from subnets is lost

Engineering Contradiction:
Improvepublic IP address availabilityVSAvoidthreat identification capability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the threat assessment at the subnet level rather than relying on individual IP addresses. By computing threat metrics for each IP in a subnet and aggregating them into a subnet-level threat score, the system maintains the ability to identify threats even when multiple IPs share the same public address through NAT/CGNAT.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension of analysis by moving from IP-level threat assessment to subnet-level threat assessment. This dimensional shift enables the system to identify malicious subnets regardless of IP address sharing, resolving the contradiction between IP address scarcity and threat identification capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If threat metrics are computed for each IP address in a subnet, then threat detection precision is improved, but computational complexity increases

Engineering Contradiction:
Improvethreat detection precisionVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the threat assessment of multiple individual IP addresses into a single subnet-level threat score. By aggregating threat metrics across all IPs in a subnet, the system achieves high detection precision while reducing the practical computational burden through consolidation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system pre-computes and stores threat metrics for IP addresses, enabling rapid aggregation into subnet threat scores when needed. This preliminary computation reduces real-time computational complexity while maintaining high detection precision.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If subnet-level threat scoring is implemented, then false positives and negatives are reduced, but system response time increases

Engineering Contradiction:
Improvefalse positive rateVSAvoidsystem response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary computation and caching of threat metrics for IP addresses and aggregation results for subnets. This pre-processing reduces the time required for real-time threat assessment while maintaining high reliability through comprehensive subnet-level analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system computes threat metrics for all IP addresses in a subnet (excessive action) but only performs full subnet threat scoring when necessary (partial action). This approach reduces false positives by thorough analysis while minimizing response time by avoiding unnecessary comprehensive scoring.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250294045A1Threat policy fine-tuning based on the vulnerability of a subnet as a source of a malicious attack
Publication Date: 2025.09.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250294045A1 patent drawing
  • US20250294045A1 patent drawing
  • US20250294045A1 patent drawing

AI summary

An embodiment includes detecting by a system a request, responsive to the detecting of the request, computing by a Compute component of the system a plurality of internet protocol addresses in a subnet. The embodiment includes computing by an Analysis component of the system a threat metric for each of the plurality of internet protocol addresses. The embodiment includes determining by the Reputation component of the system a threat score for the subnet where the threat score is based on the threat metric. The embodiment also includes sending by the system the threat score representative of a vulnerability of the subnet as a source of a malicious attack.