Trap IP Address Hacking Detection for Low-Frequency Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional antivirus software is ineffective in detecting new types of hacking that use low-frequency scanning methods, as these methods mimic normal behavior and are not easily recognizable.
Innovation Solution
Deploying a list of trap IP addresses and collecting access logs to create a connection record list, then comparing these lists to identify suspicious source IP addresses that match the trap IP addresses, thereby flagging potential hacking activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional antivirus software uses feature extraction and behavior database comparison, then it can detect wide scanning and real-time sabotage, but it cannot effectively detect new types of hacking that use low-frequency scanning methods
Solution Approach 1:
The patent deploys trap IP addresses in advance before any hacking activity occurs. These trap IPs are pre-positioned throughout the network subnet, creating a detection network that passively waits for hackers to initiate contact. This preliminary action allows the system to detect low-frequency scanning behaviors that conventional real-time analysis would miss, as the traps are already in place to capture any connection attempts.
Solution Approach 2:
The patent introduces trap IP addresses as intermediary elements between legitimate network traffic and hacking activities. These trap IPs act as decoys that hackers cannot distinguish from real network devices. When hackers scan or attack, they inadvertently connect to these intermediaries, allowing detection without requiring direct analysis of the hacker's original target or behavior patterns.
2Difficulty of detecting and measuring
If conventional antivirus software performs wide scanning, then it can identify obvious attack patterns, but it fails to recognize low-frequency scanning behavior that mimics normal access
Solution Approach 1:
The patent extracts the detection function from active scanning and real-time behavior analysis, and relocates it to passive trap IP addresses. Instead of trying to detect hacking by analyzing every network packet and behavior pattern, the system extracts only the essential detection function and embeds it in simple, static trap IPs throughout the network. This extraction allows the system to miss nothing while requiring minimal computational resources.
3Object-affected harmful factors
If new type of hacking uses low-frequency scanning to steal user data, then it can avoid direct system attacks, but it becomes undetectable by conventional antivirus software
Solution Approach 1:
The patent changes the 'color' or visibility of the detection mechanism by using trap IP addresses that blend seamlessly into the legitimate network infrastructure. These trap IPs appear identical to real network devices to hackers, using the same IP addressing schemes and network protocols. This color change allows the detection system to remain invisible to hackers while maintaining full detection capability, solving the problem of undetectable low-frequency scanning.
Data Source
AI summary
The present invention discloses a hacking detection method, including: deploying a plurality of trap IP addresses in a trap IP address list; collecting access logs from a plurality of network devices to create a connection record list, wherein the connection record list includes a plurality of connection records; and comparing the trap IP address list and the connection record list to obtain a suspicious source list. The suspicious source list includes a plurality of suspicious source IP addresses. The suspicious source IP addresses match a portion of the trap IP addresses in the trap IP address list.


