Trap IP Address Hacking Detection for Low-Frequency Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional antivirus software is ineffective in detecting new types of hacking that use low-frequency scanning methods, as these methods mimic normal behavior and are not easily recognizable.

Innovation Solution

Deploying a list of trap IP addresses and collecting access logs to create a connection record list, then comparing these lists to identify suspicious source IP addresses that match the trap IP addresses, thereby flagging potential hacking activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional antivirus software uses feature extraction and behavior database comparison, then it can detect wide scanning and real-time sabotage, but it cannot effectively detect new types of hacking that use low-frequency scanning methods

Engineering Contradiction:
Improvedetection effectivenessVSAvoidability to detect new hacking types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent deploys trap IP addresses in advance before any hacking activity occurs. These trap IPs are pre-positioned throughout the network subnet, creating a detection network that passively waits for hackers to initiate contact. This preliminary action allows the system to detect low-frequency scanning behaviors that conventional real-time analysis would miss, as the traps are already in place to capture any connection attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces trap IP addresses as intermediary elements between legitimate network traffic and hacking activities. These trap IPs act as decoys that hackers cannot distinguish from real network devices. When hackers scan or attack, they inadvertently connect to these intermediaries, allowing detection without requiring direct analysis of the hacker's original target or behavior patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If conventional antivirus software performs wide scanning, then it can identify obvious attack patterns, but it fails to recognize low-frequency scanning behavior that mimics normal access

Engineering Contradiction:
Improvedetection capabilityVSAvoidmissed hacking behaviors
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent extracts the detection function from active scanning and real-time behavior analysis, and relocates it to passive trap IP addresses. Instead of trying to detect hacking by analyzing every network packet and behavior pattern, the system extracts only the essential detection function and embeds it in simple, static trap IPs throughout the network. This extraction allows the system to miss nothing while requiring minimal computational resources.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If new type of hacking uses low-frequency scanning to steal user data, then it can avoid direct system attacks, but it becomes undetectable by conventional antivirus software

Engineering Contradiction:
Improvehacking impactVSAvoiddetection accuracy
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent changes the 'color' or visibility of the detection mechanism by using trap IP addresses that blend seamlessly into the legitimate network infrastructure. These trap IPs appear identical to real network devices to hackers, using the same IP addressing schemes and network protocols. This color change allows the detection system to remain invisible to hackers while maintaining full detection capability, solving the problem of undetectable low-frequency scanning.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS12212599B2Method and computer program product for hacking detection
Publication Date: 2025.01.28 QUANTA COMPUTER INC
  • US12212599B2 patent drawing
  • US12212599B2 patent drawing
  • US12212599B2 patent drawing

AI summary

The present invention discloses a hacking detection method, including: deploying a plurality of trap IP addresses in a trap IP address list; collecting access logs from a plurality of network devices to create a connection record list, wherein the connection record list includes a plurality of connection records; and comparing the trap IP address list and the connection record list to obtain a suspicious source list. The suspicious source list includes a plurality of suspicious source IP addresses. The suspicious source IP addresses match a portion of the trap IP addresses in the trap IP address list.