Subnet Threat Scoring for NAT-Aware Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security vulnerabilities present opportunities for cyber attackers, leading to significant data breaches and high detection and escalation costs, with existing solutions like NAT and CGNAT failing to effectively identify and mitigate threats from subnets.
Innovation Solution
A system and method for threat policy fine-tuning that involves detecting internet protocol addresses in a subnet, computing threat metrics, determining threat scores based on these metrics, and sending representative threat scores to indicate vulnerabilities as sources of malicious attacks, using a Compute, Analysis, and Reputation components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If NAT and CGNAT are used to share public IP addresses, then IPv4 exhaustion is solved and network connectivity is maintained, but the ability to identify and mitigate threats from subnets is lost
Solution Approach 1:
The patent segments the threat assessment at the subnet level rather than relying on individual IP addresses. By computing threat metrics for each IP in a subnet and aggregating them into a subnet-level threat score, the system maintains the ability to identify threats even when multiple IPs share the same public address through NAT/CGNAT.
Solution Approach 2:
The patent adds a new dimension of analysis by moving from IP-level threat assessment to subnet-level threat assessment. This dimensional shift enables the system to identify malicious subnets regardless of IP address sharing, resolving the contradiction between IP address scarcity and threat identification capability.
2Measurement precision
If threat metrics are computed for each IP address in a subnet, then threat detection precision is improved, but computational complexity increases
Solution Approach 1:
The patent merges the threat assessment of multiple individual IP addresses into a single subnet-level threat score. By aggregating threat metrics across all IPs in a subnet, the system achieves high detection precision while reducing the practical computational burden through consolidation.
Solution Approach 2:
The system pre-computes and stores threat metrics for IP addresses, enabling rapid aggregation into subnet threat scores when needed. This preliminary computation reduces real-time computational complexity while maintaining high detection precision.
3Reliability
If subnet-level threat scoring is implemented, then false positives and negatives are reduced, but system response time increases
Solution Approach 1:
The patent implements preliminary computation and caching of threat metrics for IP addresses and aggregation results for subnets. This pre-processing reduces the time required for real-time threat assessment while maintaining high reliability through comprehensive subnet-level analysis.
Solution Approach 2:
The system computes threat metrics for all IP addresses in a subnet (excessive action) but only performs full subnet threat scoring when necessary (partial action). This approach reduces false positives by thorough analysis while minimizing response time by avoiding unnecessary comprehensive scoring.
Data Source
AI summary
An embodiment includes detecting by a system a request, responsive to the detecting of the request, computing by a Compute component of the system a plurality of internet protocol addresses in a subnet. The embodiment includes computing by an Analysis component of the system a threat metric for each of the plurality of internet protocol addresses. The embodiment includes determining by the Reputation component of the system a threat score for the subnet where the threat score is based on the threat metric. The embodiment also includes sending by the system the threat score representative of a vulnerability of the subnet as a source of a malicious attack.


