EP1533700A2

Method and system for protecting a communication device from intrusion

Abstract

The intrusion protection method and system for a communication network provides address agility wherein the cyber coordinates of a target host (14) are changed both on a determined time schedule and when an intrusion attempt is detected. The system includes a management unit (18) which generates a random sequence of cyber coordinates and maintains a series of tables containing the current and next set of cyber coordinates. These cyber coordinates are distributed to authorized users (12) under an encryption process to prevent unauthorized access.

EP1533700A2, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 15 May 2020, 6.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

23 claims: 13 independent, 10 dependent

  1. 1
    Computer-implemented method for communicating with a communications device or object, the method comprising:assigning a valid variable cyber coordinate associated with a permanent identifier of the communications device or object, wherein the cyber coordinate defines a location or position of the communications device or object in a cyber space;determining if a received identifier, received during a communication attempt, with the communications device or object, based on the permanent identifier, is the valid variable cyber coordinate associated with the permanent identifier;enabling a communication with the communications device or object, if the received identifier is determined to be the valid variable cyber coordinate associated with the permanent identifier;not enabling a communication with the communications device or object, if the received identifier is determined not to be the valid variable cyber coordinate associated with the permanent identifier;changing the variable cyber coordinate;and repeating the determining and enabling steps to at least one of maintain uninterrupted communications with the communications device or object and maintain communications capabilities with the communications device or object.
  2. 9
    Method according to any one of the preceding claims, wherein the communications device or object is a telephony device in a telephony communications system, the variable cyber coordinate is based on a telephone number of the telephony device, and the permanent identifier is based on a name of a user of the telephony device, preferably wherein the communications device or object is a host computer in a computer network, and the devices or objects authorized to communicate, with the host computer, based on the permanent identifier are authorized computers.
  3. 10
    Method according to any one of the preceding claims, further comprising:changing the valid variable cyber coordinate for the host computer on a regular or irregular basis;and providing the changed valid variable cyber coordinate to the authorized computers.
  4. 12
    Method according to any one of the preceding claims, further comprising not responding to the communication attempt, with the communications device or object, based on the permanent identifier, if the received identifier is not the valid variable cyber coordinate associated with the permanent identifier.
  5. 13
    Method according to any one of the preceding claims, wherein the communications device or object is a computer file in a computer network, or a database within a computer network.
  6. 14
    Method according to any one of the preceding claims, wherein the variable cyber coordinate is based on an IP address of the communications device or object, and the permanent identifier is based on a DNS name of the communications device or object, or wherein the variable cyber coordinate is based on a port identifier of the communications device or object, and the permanent identifier is based on a DNS name of the communications device or object.
  7. 15
    Method according to any one of the preceding claims, further comprising:protecting the communications device or object against intrusion, including: granting access to the communications device or object, if the received identifier is the valid variable cyber coordinate associated with the permanent identifier;and denying access to the communications device or object, if the received identifier is not the valid variable cyber coordinate associated with the permanent identifier.
  8. 16
    Method according to any one of the preceding claims, further comprising generating the valid variable cyber coordinate associated with the permanent identifier, and/or wherein the variable cyber coordinate is based on a physical address of the communications device or object.
  9. 17
    Method according to any one of the preceding claims, wherein the communications device or object is a software device or object, or a hardware device or object.
  10. 18
    Method according to any one of the preceding claims, wherein the authorized devices or objects are software devices or objects, or hardware devices or objects.
  11. 19
    Method for protecting a communications device (14) which is connected to a communications system (10) against an unauthorized intrusion, preferably according to any one of the preceding claims, wherein the method includes:providing the communications device (14) with at least one identifier, providing the at least one identifier for use in accessing the communications device (14) to entities authorized to access said communications device (14), sensing the presence or absence of said identifier before granting access to said communications device (14), providing access to said communications device (14) when the use of said at least one correct identifier is sensed, denying access to said communications device (14) and providing said communications device (14) with at least one new identifier when the absence of the correct at least one identifier is sensed during an attempt to access said communications device (14), and/or providing said communications device (14) with at least one new identifier periodically, and providing said at least one new identifier to entities authorized to access said communications device (14).
  12. 20
    Method of communication with a remote entity over a communications system (10), preferably according to any one of the preceding claims, wherein the method includes:providing the remote entity with at least one remote entity cyber coordinate identifier;providing the remote entity cyber coordinate identifier to one or more base entities authorized to communicate with said remote entity;periodically changing the remote entity cyber coordinate identifier to a new remote entity cyber coordinate identifier;and providing the new remote entity cyber coordinate identifier to said one or more base entities.
  13. 21
    Communications system (10) with a connected communications device (14), wherein said system (10) is designed to perform the method of any one of the preceding claims.