Mission management for dynamic computer networks
Abstract
A method for communicating data in a computer network involves dynamically modifying a plurality of truth values at a first location in the computer network. These true values correctly represent a plurality of identification parameters. These true values are transformed into false values that incorrectly represent the identification parameters. Subsequently, the identification parameters are modified at a second position to transform the false values back to the true values. The positioning of the first and/or second positions changes dynamically as part of this processing procedure. When communicated outside the network, a bridge transform identifies the parameter value. The dynamic modification of the identification parameters occurs according to a mission plan, which can be modified without interrupting the data transmission in the network.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 2 independent, 8 dependent
- 1一種用於在一電腦網路中傳達資料之方法,其包括:在該電腦網路上從一第一計算裝置傳達資料至一第二計算裝置,該資料指定與該等第一及第二計算裝置之至少一者相關聯之複數個識別參數;在該電腦網路中之一第一位置處動態地修改正確地表示該複數個識別參數之複數個真值,以將該等真值變換為不正確地表示該複數個識別參數之複數個假值;在該電腦網路中之一第二位置處動態地修改該資料通訊中之該複數個識別參數,以將該複數個假值變換回至該等真值;根據一第一任務計劃在該等第一及第二位置處執行該動態修改;及在不中斷該網路中之資料傳達之情況下將該第一任務計劃選擇性地改變為不同於該第一任務計劃之一第二任務計劃。
- 2如請求項1之方法,其進一步包括將該第二任務計劃傳達至分別在該等第一及第二位置處執行該動態修改之一第一模組及一第二模組之至少一者。
- 3如請求項2之方法,其中該選擇性地改變進一步包括在該等第一及第二模組處於其中該等第一及第二模組經組態以主動執行該等動態修改步驟之一作用中操作模式時將該第二任務計劃傳達至該等第一及第二模組之至少一者。
- 4如請求項2之方法,其中該選擇性地改變進一步包括:暫時導致該等第一及第二模組之至少一者進入一旁通模式中,其中包括該資料之資料封包傳遞通過該等第一及第二模組而免除任何修改;及 在該第一模組及該第二模組處於該旁通模式中時載入該第二任務計劃。
- 5如請求項1之方法,其進一步包括動態地變更將要根據該任務計劃而修改之該複數個識別參數之一選擇。
- 6如請求項1之方法,其進一步包括根據該任務計劃而動態地變更該電腦網路內之該等第一及第二位置之至少一者之一定位。
- 7如請求項6之方法,其中變更該等第一及第二位置之至少一者之該定位變更該第一位置與該第二位置之間之一距離向量。
- 8如請求項7之方法,其中變更該距離向量變更包含於該第一位置與該第二位置之間之節點數目。
- 9如請求項6之方法,其進一步包括回應於至少一觸發事件而變更該等識別參數之該修改及該等第一及第二位置之該定位之至少一者。
- 10一種電腦網路,其包括:複數個計算裝置,其等包含一第一計算裝置,該第一計算裝置經組態以與至少一第二計算裝置傳達資料,該資料指定與該等第一及第二計算裝置之至少一者相關聯之複數個識別參數;複數個模組,其等分佈於該電腦網路中之複數個位置處以攔截經傳達之該資料,該等模組包含一第一模組,其安置於一第一位置處,該第一模組經組態以在該第一位置處動態地修改正確地表示該複數個識別參數之複數個真值,且將該等真值變換為不正確地表示該複數個識別參數之複數個假值;一第二模組,其安置於該電腦網路中之一第二位置處,該第二模組經組態以在該第二位置處動態地修改該資料通訊中之該複數個識別參數,以將該複數個假值變換回至該等真 值;其中該等第一及第二模組之各者經組態以根據一任務計劃而執行該動態修改,且在不中斷該網路中之資料傳達之情況下從一第一該任務計劃選擇性地改變為不同於該第一該任務計劃之一第二該任務計劃。
Independent claims10
101 paragraphs in 1 section, as filed
Task management of dynamic computer network
MISSION MANAGEMENT FOR DYNAMIC COMPUTER NETWORKS
The configuration of the present invention relates to computer network security, and more specifically relates to a method and system for controlling a dynamic computer network for maneuvering to defeat malicious attacks.
The main weakness of the current network infrastructure is its static nature. Assets receive permanent or infrequently changing identifiers, allowing adversaries to have almost unlimited time to explore the network, map, and maliciously explore vulnerabilities. In addition, the data transferred between these fixed entities can be captured and attributed. The current approach to network security is to set up technologies such as firewalls and intrusion detection systems around fixed assets, and use encryption to protect data on the way. However, this traditional approach is fundamentally flawed because it provides fixed targets for attackers. In today's global connectivity communications infrastructure, static networks are vulnerable networks.
The Defense Advanced Research Projects Agency (DARPA) Information Assurance (IA) project has conducted preliminary research in the field of dynamic cyber defense. Develop a technology under the Information Assurance Project to dynamically reassign the Internet Protocol (IP) address space of the feed to a pre-designated network enclave to confuse any potential adversaries who observe the network. This technology is called Dynamic Network Address Translation (DYNAT). An overview of DYNAT technology has been presented in a paper titled Dynamic Approaches to Thwart Adversary Intelligence (2001) published by DARPA.
The embodiment of the present invention relates to a method for communicating data in a computer network. The method includes transmitting data from a first computing device to a second computing device on the computer network. The data includes one or more identification parameters associated with one or both of the first and second computing devices. The method continues the step of dynamically modifying a plurality of truth values at a first location in the computer network. These true values correctly represent a plurality of identification parameters. Transform these true values into false values that incorrectly represent the identification parameters. Subsequently, the identification parameters contained in the data communication are dynamically modified at a second location in the computer network. The modification at this second position involves transforming the false value back to the true value. Note that the positioning of the first and/or second locations in the computer network also changes dynamically with the part of this processing procedure.
According to another aspect of the invention, the method may further involve performing dynamic modification of identification parameters at the first and second locations according to a mission plan. In these embodiments, the method further involves changing the mission plan to a second mission plan (different from the first mission plan) to change the dynamic manipulation performed at the first location and/or the second location. The process of changing the mission plan into a second mission plan is executed without interrupting the data transmission in the network. Multiple mission plans can be defined by the user and stored so that they can be accessed to the network device. Therefore, the user can change from a mission plan to a different mission plan as needed or desired to maintain network security.
The present invention also relates to a method for transmitting data from a first computing device included in a first computer network to a second computing device included in a second computer network. The method can start by transmitting a data communication on the first computer network. The data communication will include a first group of identification parameters that specify a true value associated with at least one of the first and second computing devices. Thereafter, the processing procedure is continued by dynamically modifying a first group of the first group of identification parameters at a first location in the first computer network. The dynamic modification involves transforming the first group to specify fake information. This transformation is to re- Execute before transferring to a bridge position. At the bridging position, the processing procedure is continued by dynamically modifying the first group to transform the first group to specify true information. After transforming the first set at the bridge location to specify true information, the method continues by transmitting the data communication from the bridge location to the second computer network. The method further includes dynamically changing the positioning of the first position in the computer network.
<p>100Computer network</p><p>101Client computer</p><p>102Client computer</p><p>103Client computer</p><p>104Network Management Computer (NAC)</p><p>105Module</p><p>106Module</p><p>107Module</p><p>108Network Hub/Network Node</p><p>109Network Hub/Network Node</p><p>110Router/Network Node</p><p>111Server</p><p>112Server</p><p>113Module</p><p>114Module</p><p>115Bridge</p><p>120Identification parameter (IDP) group</p><p>122Identification parameter (IDP) group</p><p>124Second Network</p><p>201Data port</p><p>202Data Port</p><p>204Network Interface Device</p><p>205Network Interface Device</p><p>206Output buffer</p><p>208Input buffer</p><p>210Input buffer</p><p>212Output buffer</p><p>215Processor</p><p>218Memory</p><p>220Mission Plan</p><p>300Working space</p><p>302Network Components</p><p>304Cursor</p><p>306Data connection</p><p>400Dialog</p><p>401 check box</p><p>402label</p><p>404Tag</p><p>406label</p><p>408User Interface Controls/Check Boxes</p><p>410User Interface Control/Source Address Box</p><p>412User Interface Control/Destination Address Box</p><p>414User Interface Control/Box</p><p>415User Interface Control/Box</p><p>416User Interface Control/Box</p><p>418User Interface Controls/Check Boxes</p><p>420User interface control/sliding axis</p><p>422List box</p><p>424List box</p><p>428 check box</p><p>430check box</p><p>432Dropdown menu</p><p>500Dialog</p><p>502Control Item</p><p>503table</p><p>504<sub>1</sub>-504<sub>n</sub>Time slot</p><p>506Time Era</p><p>508Cursor</p><p>510Button</p><p>602Network Control Software Application</p><p>604Mission Plan</p><p>606Communication media</p><p>700Dialog</p><p>702Mission Plan</p><p>704Send task plan button</p><p>1000Module/Computer System</p><p>1002Display unit</p><p>1008Command</p><p>1010Computer readable storage media</p><p>1012Processor</p><p>1016Network Interface Device</p><p>1017Network Interface Device</p><p>1018Static memory</p><p>1020Main memory</p><p>1022Bus</p><p>1102Display unit</p><p>1104User input device</p><p>1106Disk Drive Unit</p><p>1108Command</p><p>1110Computer readable storage media</p><p>1112Processor</p><p>1114Cursor control device</p><p>1116Network Interface Device</p><p>1118Static memory</p><p>1120Main memory</p><p>1122Bus</p>
The embodiments will be described with reference to the following drawings, in which the same numbers refer to the same items throughout the drawings.
Figure 1 is an example for understanding a computer network of the present invention.
Figure 2 is an example of a module that can be used in the present invention to perform specific manipulations of identifying parameters.
Figure 3 is a diagram useful for understanding the tools that can be used to help characterize the network in Figure 1.
FIG. 4 is an example of a graphical user interface dialog box that can be used to select dynamic settings for the module in FIG. 1.
FIG. 5 is an example of a dialog box of a graphical user interface that can be used to select a sequence active state and a bypass state associated with each module in FIG. 1.
FIG. 6 is a diagram for understanding how a mission plan can be communicated to multiple modules in the network in FIG. 1.
FIG. 7 is an example of a dialog box that can be used to select a mission plan and communicate the mission plan to a graphical user interface of the module as shown in FIG. 6.
Fig. 8 is a flowchart for understanding the operation of the module in Fig. 1.
Figure 9 is a flow chart for understanding the operation of a network control software application (NCSA) about creating and loading a task plan.
FIG. 10 is a block diagram of a computer architecture that can be used to implement the module in FIG. 1.
FIG. 11 is a block diagram of a computer architecture that can be used to implement the network management computer (NAC) in FIG. 1.
Fig. 12 is a flowchart for understanding the operation of the bridge in Fig. 1.
Figure 13 is a table for understanding some types of identification parameters that can be modified.
The present invention is described with reference to the drawings. The figures are not drawn to scale and they are provided only to illustrate the present invention. For illustration purposes, several aspects of the invention are described below with reference to exemplary applications. It should be understood that many specific details, relationships, and methods are clarified to provide a comprehensive understanding of the present invention. However, those skilled in the related art will readily recognize that the present invention can be practiced without one or more of these specific details or using other methods. In other examples, well-known structures or operations are not shown in detail to avoid obscuring the present invention. The present invention is not limited by the illustrated sequence of actions or events, because some actions can occur in a different sequence and/or occur simultaneously with other actions or events. In addition, all the illustrated actions or events are not required to implement the method according to the present invention.
It should also be understood that the terms used herein are only for describing specific embodiments and are not intended to limit the present invention. As used herein, the singular forms "a", "an" and "the" are intended to also include the plural forms, unless the context clearly dictates otherwise. In addition, the terms "including", "includes", "having", "has" and "with" are used in the detailed description and/or the scope of the patent application. In terms of or variants thereof, these terms are intended to be included in a manner similar to the term "comprising."
In addition, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meanings commonly understood by ordinary persons of the technology to which the present invention belongs. It should be further understood that terms (such as those defined in commonly used dictionaries) should be interpreted as having meanings consistent with their meanings in the context of related technologies and should not be interpreted in an idealized or overly formal sense, unless this text Clearly defined as such.
Identify Agile Computer Network
Referring now to FIG. 1, a schematic diagram of an exemplary network 100 including a plurality of computing devices is shown. These computing devices may include client computers 101 to 103, a network management computer (NAC) 104, servers 111, 112, network hubs 108, 109, routers 110, and bridges Take 115. The client computer can be any type of computing device that may require network services, such as a conventional tablet computer, a notebook computer, a laptop computer, or a desktop computer. The router 110 may be a conventional routing device that forwards data packets between computer networks. The hubs 108 and 109 are conventional hub devices (for example, Ethernet hubs) well known in the art. The servers 111 and 112 can provide various computing services utilized by the client computers 101 to 103. For example, the servers 111 and 112 may be file servers, which provide locations for shared storage of computer files used by the client computers 101 to 103.
The communication medium of the network 100 can be wired, wireless, or both, but for simplicity and to avoid obscuring the present invention, it should be described as a wired network in this text. The network will use a communication protocol to communicate data. As is well known in the art, the communication protocol defines the format and rules used to communicate data throughout the network. The network in Figure 1 can use any communication protocol or combination of protocols known now or in the future. For example, the network can use the well-known Ethernet protocol suitable for such communications. Alternatively, the network can utilize other protocols, such as Internet Protocol Suite (commonly referred to as TCP/IP), SONET/SDH, or Asynchronous Transfer Mode (ATM) communication protocol. In some embodiments, one or more of these communication protocols can be used in combination. Although FIG. 1 shows a network topology, the present invention is not limited in this respect. Instead, any type of suitable network topology can be used, such as a bus network, a star network, a ring network, or a mesh network.
The present invention generally relates to a method for communicating data in a computer network (such as the computer network 100), wherein the data is communicated from a first computing device to a second computing device. The computing devices in the network are represented by multiple identification parameters. The phrase "identification parameter" as used herein may include items such as Internet Protocol (IP) address, Media Access Control (MAC) address, port, and so on. However, the present invention is not limited in this respect, and the identification parameters may also include various other information used to characterize a network node. The various types of identification parameters contemplated in this article are discussed in more detail below. The configuration of the present invention involves the use of mobile target technology (MTT) to manipulate these identification parameters of one or more computing devices in the network. One or more of them. This technology disguises the communication mode and network address of these computing devices. The manipulation of the identification parameters as described in this article is usually in conjunction with the data communication in the network (that is, when the data is to be transmitted from a first computer in the network (for example, the client computer 101) to the network One of the second computer (for example, the client computer 102) is executed. Therefore, the manipulated identification parameters can include the identification parameters of the source computing device (the data is derived from) and the destination computing device (the data is sent to the device). The communicated set of identification parameters is referred to herein as an identification parameter set (IDP set). This concept is illustrated in FIG. 1, which shows that the IDP group 120 is transmitted by the client computer 101 as part of a data packet (not shown).
The processing procedure configured according to the present invention involves selectively modifying one or more identification parameters of a data packet or a designated source and/or destination computing device contained in a data packet at a first location in a computer network value. Modify the identification parameters according to a mission plan. The location where this modification is performed will usually coincide with the location of one of the modules 105 to 107, 113, and 114. Referring again to FIG. 1, it can be observed that the modules 105, 106, 107, 113, and 114 are inserted in the network between various computing devices (which constitute the nodes in this network). In these locations, the module intercepts data packet communication, performs the necessary manipulation of identification parameters, and retransmits the data packet along a transmission path. In alternative embodiments, the modules 105, 106, 107, 113, 114 can perform a similar function, but can be directly integrated into one or more computing devices. For example, the module can be integrated in the client computers 101, 102, 103, the servers 111, 112, the hubs 108, 109, and/or the router 110.
An example of the functional block diagram of the module 105 is shown in FIG. 2. The modules 106 to 107, 113, and 114 may have similar functional block diagrams, but it should be understood that the present invention is not limited in this respect. As shown in FIG. 2, the module 105 has at least two data ports 201, 202, each of which can correspond to a respective network interface device 204, 205. The data received at the port 201 is processed at the network interface device 204 and temporarily stored in an input buffer 210. The processor 215 accesses the input data packets contained in the input buffer 210 and performs any necessary manipulation of the identification parameters as described herein. The modified data packet is passed to the output buffer The device 212 then uses the network interface device 205 to transmit from the port 202. Similarly, the data received at the port 202 is processed at the network interface device 205 and temporarily stored in an input buffer 208. The processor 215 accesses the input data packets contained in the input buffer 208 and performs any necessary manipulation of the identification parameters as described herein. The modified data packet is passed to the output buffer 206 and then transmitted from the port 201 using the network interface device 204. In each module, the processor 215 executes the manipulation of the identification parameters according to a task plan 220 stored in a memory 218.
It will be understood from Figure 2 that a module is preferably configured for bidirectional operation. In these embodiments, the module can implement different modification functions depending on the source of the specific data packet. The dynamic modification function of each module can be specified in the mission plan according to the source computing device of a specific data packet. The module can determine the source of the data packet by any suitable method. For example, the source address of a data packet can be used for this purpose.
At a selected module in the network 100, the processor 215 will determine that one or more false identification parameter values are to be used instead of the true identification parameter values. The processor transforms one or more true identification parameter values into one or more false identification parameter values preferably specified by a pseudo-random function. After this transformation, the module will forward the modified packet or data packet to a node under the network along a transmission path. At subsequent nodes in the communication path, the adversary who is monitoring these network communications will observe false or incorrect information about the identification of the computing device communicated on the network.
In a preferred embodiment, the false identification parameters specified by the pseudo-random function change according to the occurrence of one or more trigger events. The trigger event causes the processor 215 to use the pseudo-random function to generate a new set of false recognition parameter values transformed from the true recognition parameters. Therefore, the trigger event is used as the basis for the dynamic change of the false identification parameters described in this article. The trigger event is discussed in more detail below. It should be noted, however, that the trigger event used to select a new set of false identification parameter values may be based on the elapsed time and/or the occurrence of a specific network event. Trigger events can also be initiated by user commands.
The above-mentioned transformation of identification parameters provides a way of maneuvering the computer network 100 to prevent network attacks. In a preferred embodiment, the task plan 220 implemented by the processor 215 will also control some other aspects of the way the computer network can be manipulated. For example, the mission plan may specify dynamic selection of one of the manipulation identification parameters. The dynamic selection may include a selection of which identification parameters to modify, and/or the number of selected identification parameters. This variable selection process provides additional uncertainty or change dimensions, which can be used to further prevent an adversary from attempting to invade or learn about the computer network 100. As an example of this technique, it is considered that during a first period, a module can modify a destination IP address and a destination MAC address of each data packet. During a second period, the module can manipulate the source IP address and source host name in each data packet. During a third period, the module can manipulate a source port number and a source user name. The change of the recognition parameter selection can happen simultaneously (all the selected recognition parameters change at the same time). Alternatively, the change in the selection of identification parameters can occur asynchronously (as individual identification parameters are added or removed from the selected identification parameter group, the selected identification parameter group changes incrementally).
The pseudo-random function is preferably used to determine the selection of the identification value to be manipulated or transformed into a false value. In other words, the module will only transform the identification parameters selected by the pseudo-random function. In a preferred embodiment, the selection of the identification parameters specified by the pseudo-random function changes according to the occurrence of the trigger event. The trigger event causes the processor 215 to use a pseudo-random function to generate a new selection of the recognition parameter to be transformed into a false recognition parameter. Therefore, the trigger event is used as the basis for the dynamic change of the selection of the identification parameters described in this article. Note that the value of the identification parameter can also be changed according to a pseudo-random algorithm.
These modules can also advantageously provide a third method of controlling the computer network to prevent cyber attacks. Specifically, the mission plan loaded in each module can dynamically change the location in the network where the modification or transformation of the identification parameters occurs. It is considered that the modification of the identification parameters in one of the IDP groups 120 sent from the client computer 101 to the client computer 102 can occur in the module 105. This condition is shown in Figure 1, where the identification parameters contained in the IDP group 120 are in the module 105 is manipulated so that the IDP group 120 is transformed into a new or modified IDP group 122. Compared with the identification parameters in the IDP group 120, at least some of the identification parameters in the IDP group 122 are different. However, the location where this change occurs is preferably also controlled by the mission plan. Therefore, the manipulation of the IDP group 120 may sometimes occur at the module 113 or 114 instead of the module 105, for example. The ability to selectively change the location where the manipulation of the identification parameter occurs adds a more important dimension to the manipulation capability of the computer network.
By selectively controlling the operating state of each module, the dynamic change of the position of the modified identification parameter is promoted. For this reason, the operating state of each module preferably includes (1) active state, in which data is processed according to the current task plan, and (2) bypass state, in which packets can flow through the module as if the module does not exist. By selectively causing a specific module to be in an active state and a specific module to be in a standby state, the position of dynamic modification is controlled. The position can be dynamically changed by dynamically changing the current state of the module in a coordinated manner.
The mission plan may include a predefined sequence for determining the location within the computer network 100 where the identification parameters are to be manipulated. The position where the identification parameter is to be manipulated will change according to the time sequence indicated by a trigger event. For example, a trigger event can cause a transition to a new location to manipulate or transform the identification parameters as described herein. Therefore, the trigger event is used as the basis for the location of the modified identification parameter to change, and the predefined sequence determines where the new location will be.
It should be understood from the foregoing that a data packet is modified at a module to include false identification parameters. Sometimes in a computer network, it is necessary to restore the identification parameters to their true values, so that the identification parameters can be used to properly perform their expected functions according to a specific network protocol. Therefore, the configuration of the present invention also includes dynamically modifying the assigned value of the identification parameter at a second location (ie, a second module) according to the mission plan. The modification at the second position basically includes the inverse processing procedure of one of the processing procedures used at the first position to modify the identification parameters. The module at the second position can thus restore or transform the false value identification parameter back to its true value. In order to complete this action, the module at the second position must be able to determine at least (1) the selection of the identification parameter value to be transformed, and (2) the positive value of the selected identification parameter from a false value to a true value Really change. In fact, this processing procedure involves the pseudo-random processing procedure used to determine the selection of the identification parameter or the inverse processing procedure of a number of pseudo-random processing procedures and the realization of the change of the identification parameter values. 1 shows the inverse transformation step, in which the IDP group 122 is received at the module 106, and the identification parameter values in the IDP group 122 are transformed or manipulated back to their original or true values. In this case, the module 106 converts the identification parameter value back to the identification parameter value of the IDP group 120.
Note that the module must have some way of determining the appropriate transformation or manipulation to apply to each data communication it receives. In a preferred embodiment, this determination is performed by checking at least one source address identification parameter contained in the received data communication. For example, the source address identification parameter may include the IP address of a source computing device. Once the true identification of the known source computing device, the module consults the mission plan (or information derived from the mission plan) to determine the action it needs to take. For example, these actions may include converting certain true recognition parameter values into false recognition parameter values. Alternatively, these changes may include converting false recognition parameter values back to true recognition parameter values.
Note that there will be cases where the source address identification parameter information contained in the received data communication has been changed to a false value. In these circumstances, the module receiving the data communication will not be able to determine the identification of the source of the data communication immediately. However, the module receiving the communication can still identify the source computing device in these examples. This is done at the receiving module by comparing the false source address identification parameter values with a look-up table (LUT) listing all the false source address identification parameter values put into use during a specific time period. The LUT also includes a list of true source address identification parameter values corresponding to the false source address value. The LUT can be directly provided by the mission plan, or can be generated from the information contained in the mission plan. In either case, the identifier of a true source address identifying parameter value can be easily determined from the LUT. Once the true source address identification parameters have been determined, the module receiving the data communication can use this information to determine (based on the mission plan) the required manipulation of the identification parameters.
Note that the mission plan can also specify a change in the second position that restores the identification parameters to their true values. For example, suppose that it is dynamically modified at the first position including one of the modules 105 These identification parameters. The mission plan may specify that the restoration of the identification parameters to their true values occurs at module 106 as described, but may alternatively specify that dynamic modification occurs at module 113 or 114 instead. In some embodiments, the location where these manipulations occur is dynamically determined by the mission plan according to a predefined sequence. The predefined sequence can determine the position or the sequence of the module where the manipulation of the identification parameter will occur.
Transitions involving dynamic modifications at different locations preferably occur according to a trigger event. Therefore, the predefined sequence determines the pattern or sequence of the location where data manipulation will occur, and the trigger event is used as the basis for causing the transition from one location to the next. Trigger events are discussed in more detail below; however, it should be noted that trigger events can be based on elapsed time, user control, and/or the occurrence of specific network events. The control of the selection of the second position (ie, the position where the identification parameter returns to its true value) can be achieved in the same manner as described above with respect to the first position. Specifically, the operating states of two or more modules can be switched between an active state and a bypass state. The manipulation of the identification parameters will only occur in the modules with active operating states. Modules with bypass operation status will only transmit data packets without modification.
Alternative methods can also be used to control the location where the manipulation of the identification parameters will occur. For example, a network administrator can define a number of possible modules in a mission plan whose identification parameters can be converted from true values to false values. When a trigger event occurs, a new position can be selected among the modules by using a pseudo-random function, and a trigger time can be used as the seed value of the pseudo-random function. If each module uses the same initial seed value to implement the same pseudo-random function, each module will calculate the same pseudo-random value. The trigger time can be determined based on the clock time, such as GPS time or system clock time. In this way, each module can independently determine whether it is currently one of the active positions where the manipulation of the identification parameters should occur. Similarly, the network administrator can define several possible modules in a mission plan that dynamically manipulate the identification parameters to return the identification parameters to their correct or true values. Which module is selected for this purpose can also be determined based on the trigger time and pseudo-random function as described in this article. Other methods can also be used to determine that recognition will occur Position or module for parameter manipulation. Therefore, the present invention is not intended to be limited to the specific methods described herein.
Note that changing the positioning of the first position and/or the second position of the manipulation identification parameter will usually result in changing the physical distance between the first position and the second position along the network communication path. The distance between the first position and the second position is referred to herein as a distance vector. The distance vector may be an actual physical distance between the first position and the second position along a communication path. However, it is useful to think of the distance vector as representing the number of network nodes present in the communication path between the first location and the second location. It should be understood that dynamically selecting different positions for the first position and the second position in the network can have the effect of changing the number of nodes between the first position and the second position. For example, in FIG. 1, the dynamic modification of the identification parameters is implemented in the selected ones of the modules 105, 106, 107, 113, and 114. As mentioned earlier, it is determined that the modules are actually used to implement dynamic modification separately. If the module 105 is used to convert the identification parameters into false values and the module 106 is used to convert them back to true values, then there are three network nodes (108, 110, 109). However, if the module 113 is used to convert the false value and the module 114 is used to convert the identification parameter back to the true value, there is only one network node (110) between the modules 113 and 114. Therefore, it should be understood that dynamically changing the location of the dynamically modified location can dynamically change the distance vector. This change in the distance vector provides an additional dimension of variability for network manipulation or modification, as described in this article.
In the present invention, each of the manipulation of the identification parameter value, the selection of the identification parameter, and the location of these identification parameters is defined as a manipulation parameter. Whenever one of the three control parameters changes, it can be considered that network control has occurred. Whenever one of these three control parameters changes, we can think that network control has occurred. In order to most effectively prevent the adversary from attempting to invade the computer network 100, it is preferable to control the network manipulation by means of a pseudo-random processing procedure as described above. Those who are familiar with this technique will understand that a chaotic process can also be used to perform this function. Compared with the pseudo-random function, the chaos processing procedure is technically different, but for the purpose of the present invention, either one can be used, and the two are regarded as equivalent. In some real In an embodiment, the same pseudo-random processing procedure can be used to dynamically change two or more of the control parameters. However, in a preferred embodiment of the present invention, two or more different pseudo-random processing procedures are used so that two or more of these control parameters can be modified independently of other control parameters.
trigger event
As mentioned above, the dynamic change of each manipulation parameter is controlled by at least one trigger. A trigger is an event that causes a change related to the dynamic modification described in this article. In other words, it can be considered that the trigger causes the network to be manipulated in a new way different from the previous time (ie, before the trigger occurs). For example, during a first time period, a mission plan may cause an IP address to change from value A to value B; but after a trigger event, the IP address may instead change from value A to value C. Similarly, during a first time period, a mission plan may cause the IP and MAC addresses to be modified; but after a trigger event, the mission plan may instead cause the MAC address and user name to be modified. As a third example, consider that during a first period of time, a mission plan may cause the identification parameters to change when the ID group 120 arrives at the module 105; but after a trigger event, it may cause the identification parameters to alternatively arrive in the ID group 120 Mod 113 changed.
In its simplest form, a trigger can be initiated by the user or based on a simple timing scheme. In this embodiment, one clock time in each module can be used as a trigger. For example, a trigger event can be defined as occurring at the expiry of each 60-second interval. For this configuration, one or more of the control parameters can be changed every 60 seconds according to a predetermined clock time. In some embodiments, all manipulation parameters can be changed at the same time, so that these changes are synchronized. In a slightly more complicated embodiment, a time-based trigger configuration can also be used, but a different unique trigger time interval can be selected for each control parameter. Therefore, the false identification parameter value can be changed according to the time interval X, the selection of the identification parameter will be changed according to the time interval Y, and the position for performing these changes will occur according to the time interval Z, where X, Y, and Z are different values.
It should be understood that in the embodiments of the present invention (which depend on the clock as the trigger mechanism, In time), it is advantageous to provide synchronization between the clocks in the various modules 105, 106, 107, 113, 114 to ensure that packets will not be lost or lost due to unidentified identification parameters. The synchronization method is well known, and any suitable synchronization mechanism can be used for this purpose. For example, the modules can be synchronized by using a highly accurate time reference (such as GPS clock time). Alternatively, a unique wireless synchronization signal can be broadcast from a central control facility to each module.
Other types of triggering are also possible for the present invention. For example, the trigger event can be based on the occurrence or detection of a potential network security threat. According to an embodiment of the present invention, a network security software package can be used to identify potential network security threats. Alternatively, a potential network security threat can be identified when a data packet is received at the modules 105, 106, 107, 113, 114, where the packet contains one or more identification parameters that are inconsistent with the current state of network manipulation. Regardless of the basis for identifying cybersecurity threats, the existence of this threat can be used as a trigger event. A trigger event based on a cyber security threat can result in the same type of network manipulation as the network manipulation caused by the time-based trigger described above. For example, in addition to the detection of a cyber security threat, the false identification parameters, the selection of identification parameters, and the position of identification parameter transformations can remain stable (ie, unchanged). For example, this configuration can be selected in a computer network where frequent network control is not expected.
Alternatively, time-based trigger events can be combined with trigger events based on potential threats to network security. In these embodiments, compared to time-based triggering, a triggering event based on a security threat may have a different impact on network manipulation. For example, triggering events based on security threats can lead to strategic or defensive changes in network manipulation in order to more actively combat this network security threat. The exact nature of these measures can depend on the nature of the threat, but can include multiple responses. For example, different pseudo-random algorithms can be selected, and/or the number of identification parameters selected for manipulation in each IDP group 120 can be increased. In systems that have used time-based triggers, the response may also include increasing the frequency of network control. Therefore, more frequent changes can be made to each of the following: (1) false identification parameter values; (2) each IDP group to be changed Selection of identification parameters; and/or (3) Change the positioning of the first position and the second position of the identification parameters. Therefore, the network manipulation described in this article provides a method for identifying and responding to potential network security threats.
mission plan
According to a preferred embodiment of the present invention, the network control described herein is controlled according to a mission plan. A mission plan is a plan that defines and controls the controllability in the context of the network and security model. Therefore, the mission plan can be expressed as a data file transmitted from the network management computer (NAC) 104 to each module 105 to 107, 113 to 114. After that, each module uses the mission plan to control the manipulation of the identification parameters and coordinate its activities with the actions of other modules in the network.
According to a preferred embodiment, the mission plan can be modified by a network administrator from time to time to update or change the way of network manipulation to thwart potential adversaries. Thus, the mission plan provides the network administrator with a tool that facilitates complete control of when, where, and how network manipulation will occur within the network. This update capability allows the network administrator to customize the behavior of the computer network according to the current operating conditions, and more effectively prevents the adversary from attempting to invade the network. Multiple mission plans can be defined by a user and stored so that they can be accessed to modules in the network. For example, multiple mission plans can be stored at NAC 104 and communicated to the module as needed. Alternatively, multiple mission plans can be stored on each module and can be activated as needed or desired to maintain network security. For example, if the network administrator determines or suspects that the adversary has discovered the current mission plan of the network, the administrator may wish to change the mission plan. Effective safety procedures can also indicate periodic changes to the mission plan.
By modeling the network 100, a task plan processing procedure can be started. Facilitate model creation by running a network control software application (NCSA) on the computer or server at the network command center. For example, in the embodiment shown in FIG. 1, NCSA can be executed on NAC 104. The network model preferably includes information defining data connections and/or relationships among various computing devices included in the network 100. NCSA will provide promotion keys Enter the appropriate interface for this relationship data. According to one embodiment, the NCSA can facilitate the entry of data into a table that can be used to define a mission plan. However, in a preferred embodiment, a graphical user interface is used to facilitate this process. Referring now to Figure 3, NCSA may include a network topology model generator tool. This tool is used to help network administrators define the relationship between various components of the network. The network topology tool provides a workspace 300 in which the administrator can drag and place the network component 302 by using a cursor 304. The network administrator can also establish data connections 306 between various network components 302. As part of this modeling process, the network administrator can provide network address information for various network components (including modules 105 to 107, 113, and 114).
Once the network has been modeled, the network can be saved and used by the network administrator to define the behavior of the various modules 105 to 107, 113, 114 and the way in which they interact with each other. Referring now to FIG. 4, NCSA can generate a dialog box 400, which can be used to further develop a mission plan. The pull-down menu 432 can be used to select a specific module (for example, the module 105) to which the settings in the dialog box 400 will be applied. Alternatively, the network administrator can use the drop-down menu 432 to indicate that the settings in the dialog box 400 are to be applied to all modules in the network (for example, by selecting "All" in the menu 432). The processing procedure can be continued by specifying whether a fixed set of identification parameters will always be modified in each module, or whether the set of identification parameters that are manipulated should be dynamically changed. If it is intended to dynamically change the selection or group of identification parameters to be manipulated in the module, the network administrator can mark the check box 401 to indicate the preference. If the check box 401 is not marked, it will indicate that the group of identification parameters to be changed is a fixed group that does not change over time.
The dialog box 400 includes tags 402, 404, and 406, which allow the user to select the specific identification parameters that he wants to operate to create a mission plan. For the purpose of this disclosure, the dialog box 400 facilitates the dynamic change of only three identification parameters. Specifically, these labels include IP address, MAC address, and port address. More or fewer identification parameters can be dynamically changed by providing additional tags, but the three identification parameters are sufficient to explain the present invention The concept. In FIG. 4, the user has selected the tag 402 to operate with the identification parameters of the IP address type. In the label 402, various user interface control items 408 to 420 are provided to specify details related to the dynamic change of the IP address in the selected module. More or fewer control items can be provided to facilitate the dynamic manipulation of IP address types, and only the control items shown are provided to help readers understand the concept. In the example shown, the network administrator can enable the dynamic change of the IP address by selecting (for example, using a pointing device such as a mouse) the check box 408 marked as enabling IP address hopping. Similarly, the network administrator can indicate whether the source address, destination address, or both will be changed. In this example, both the source address block and the destination address block 410, 412 are marked to indicate that the two types of addresses will be changed. The range of allowable values of the source address and the destination address can be specified by the administrator in the list boxes 422 and 424.
By selecting a pseudo-random processing program, a specific pseudo-random processing program for selecting a fake IP address value is specified. This selection is specified in blocks 414, 415. Different pseudo-random processing procedures can have different levels of complexity for the degree of variability of true randomness, and the administrator can select the processing procedure that best suits the needs of the network 100.
The dialog box 400 also allows the network administrator to set the trigger type to be used for the dynamic change of the IP address identification parameters. In this example, the user has selected block 416, indicating that a time-based trigger will be used to determine when to transition to a new fake IP address value. In addition, check box 418 has been selected to indicate that time-based triggering will occur on a periodic basis. The sliding axis 420 can be adjusted by the user to determine the frequency of periodic time-based triggering. In the example shown, the trigger frequency can be adjusted to be between 6 triggers per hour (triggers every 10 minutes) and 120 triggers per hour (triggers every 30 seconds). In this example, the selection can also be used for other types of triggers. For example, the dialog box 402 includes check boxes 428 and 430, and the network administrator can select event-based triggers through the check boxes 428 and 430. Several different specific event types can be selected to form the basis of these event-based triggers (for example, event type 1, event type 2, etc.). These event types can include the detection of various potential computer network security threats. In Figure 4, tags 404 and 406 are similar to tags 402, but The control item is customized for the dynamic change of MAC address and port value (not IP address). Additional tags can be provided to control the dynamic changes of other types of identification parameters.
The mission plan can also specify a plan for dynamically changing the location of the modified identification parameters. In some embodiments, this variable position feature is facilitated by controlling a sequence that defines when each module is in an active state or a bypass state. Therefore, the mission plan advantageously contains some building blocks that specify this sequence. In some embodiments of the invention, this may involve the use of defined time intervals or time slots separated by the occurrence of a trigger event.
Referring now to FIG. 5, a dialog box 500 may be provided by NCSA to facilitate the coordination and input of position sequence and timing information. The dialog box 500 may include a control item 502 for selecting a number of time slots 504 to be included in a time epoch 506<sub>1</sub>To 504<sub>n</sub>. In the example shown, the network administrator has defined 4 time slots per timing epoch. The dialog box 500 may also include a table 503, which includes all the modules in the network 100. For each module listed, the table contains available time slots 504 for a timing epoch 506<sub>1</sub>To 504<sub>4</sub>The graphic representation. Recall that the dynamic control of the position of the manipulation identification parameter is determined by whether each module is in the active or bypass operation state. Therefore, in the graphical user interface, the user can move a cursor 508 and make selections to specify whether a particular module is in active or bypass mode during each time slot. In the example shown, the module 105 is in the time slot 504<sub>1</sub>And 504<sub>3</sub>Is active during the period, but in the time slot 504<sub>2</sub>、504<sub>4</sub>During the period, it is in bypass mode. Conversely, the module 113 is in the time slot 504<sub>2</sub>、504<sub>4</sub>Is active during the period, but in the time slot 504<sub>1</sub>And 504<sub>3</sub>During the period, it is in bypass mode. Referring to Figure 1, this means that the manipulation of the identification parameter is in the time slot 504<sub>1</sub>And 504<sub>3</sub>The period occurs at the location associated with the module 105, but in the time slot 504<sub>2</sub>、504<sub>4</sub>The period instead occurs at module 113.
In the example shown in FIG. 5, the network administrator has made a selection so that the module 114 always operates in the active mode (ie, the module 114 is active during all time slots). Therefore, for the data communication transmitted from the client computer 101 to the client computer 103, the data packets will be manipulated alternately in the modules 105 and 113, but the data will always be manipulated in the module 114 Packet. Finally, in this example, the network administrator has made a choice to use the time slot 504<sub>1</sub>To 504<sub>4</sub>During this period, the modules 106 and 107 are maintained in the bypass mode. Therefore, during any defined time slot, no manipulation of identification parameters will be performed at these modules. Once the module timing has been defined in dialog box 500, the network administrator can select button 510 to save the changes as part of the updated mission plan. The task plan can be saved in various formats. In some embodiments, the mission plan can be saved as a simple table or other type of defined data structure that can be used by each module to control the behavior of the module.
Distribution and loading of mission plan
The distribution and loading of the mission plan as disclosed in this article will now be described in more detail. Referring again to FIG. 1, it can be observed that the modules 105 to 107, 113, and 114 are distributed in one or more locations through the network 100. These modules are integrated in the communication path to intercept communications at these locations, perform necessary manipulations, and forward data to other computing devices in the network. Using the aforementioned configuration, any necessary maintenance of the modules described in this article (for example, maintenance to update a task plan) will have the potential to interrupt network communication when replacing or reprogramming the module. Such interruptions are undesirable in many situations where the reliability and availability of network services are critical. For example, for military, emergency and commercial computer networks, uninterrupted network operations can be crucial.
To ensure uninterrupted network operation, each module preferably has several operating states. These operating states include: (1) Closed state, where the module is powered off and does not process any packets; (2) Initialized state, where the module installs software scripts according to the mission plan; (3) Active state, where according to The current mission plan is to process data; and (4) Bypass state, in which packets can flow through the module as if the module does not exist. The module is configured so that when it is in the active state or the bypass state, the module can receive and load an updated task plan provided by a network administrator. The operation status of the module can be manually controlled by the network administrator with the help of NCSA running on the NAC 104, for example. For example, the user can select the operating state of various modules by using the graphical user interface control panel. Used to control the operation of the network The status command is communicated via the network 100, or may be communicated by any other suitable means. For example, a separate wired or wireless network (not shown) can be used for this purpose.
The mission plan can be directly loaded into the physical location of each module, or it can be communicated to the module from the NCSA. This concept is illustrated in FIG. 6, which shows that the mission plan 604 is communicated from the NCSA 602 to each of the modules 105 to 107, 113, and 114 via the communication medium 606. In the example shown, the NCSA software application is executed on the NAC 104 operated by the network administrator. In some embodiments, the communication medium may include in-band communication using the computer network 100. Alternatively, an out-of-band network (eg, a separate wireless network) can be used as the communication medium 606 to communicate the updated mission plan from the NCSA to each module. As shown in FIG. 7, NCSA may provide a dialog box 700 to facilitate the selection of one of several mission plans 702. Each of these mission plans 702 can be stored on the NAC 104. The network administrator can select from one of the several mission plans 702, and then they can activate a send mission plan button 704. Alternatively, multiple mission plans can be communicated to and stored in each module. In any case, the user can choose to activate one of the defined task plans.
In response to the command to send the mission plan, when the modules are in the active state (where the modules are configured to actively perform the dynamic modification of the identification parameters as described in this article), the selected mission plan is communicated to these Module. This configuration minimizes the time for the network to operate in clear text without manipulating identification parameters. However, the updated mission plan can also be communicated to the modules when the modules are in the bypass mode, and this approach is desirable in some cases.
Once the mission plan is received by a module, the mission plan is automatically stored in a memory location in the module. After that, the module can be caused to enter the bypass state. While still in this state, the module can load the data associated with the new mission plan. This process of entering the bypass state and loading new mission plan data can occur automatically in response to receiving the mission plan, or can occur in response to a command from the NCSA software controlled by the network administrator. The new mission plan preferably includes a change in the way to change the value of the identification parameter. Once loaded With the new mission plan, these modules 105 to 107, 113 and 114 can be synchronized from bypass mode to active mode to ensure that no data communication errors occur. The mission plan can specify the time for the module to return to the active mode, or the network administrator can use NCSA to transmit a command to various modules to guide the modules into the active mode. The aforementioned processing procedure of updating a mission plan advantageously allows changes to the network security procedure to occur without interrupting the communication between the various computing devices attached to the computer network 100.
The dynamic manipulation of various identification parameters at each module 105, 106, 107, 113, and 114 is preferably controlled by application software running on each module 105 to 107, 113, 114. However, the behavior of the application software is advantageously controlled by the mission plan.
Referring now to FIG. 8, a flow chart that outlines the operation of each module 105 to 107, 113, 114 is provided. To avoid confusion, the processing procedure is described with respect to one-way communication. For example, in the case of the module 105, one-way may involve the transmission of data from the client computer 101 to the hub 108. However, in practice, it is preferable for the modules 105 to 107, 113, and 114 to operate bidirectionally. When the module is powered on, the processing procedure starts at step 802 and continues to step 804 (where the module application software is initialized to execute the method described in this article). In step 806, a mission plan is loaded from a memory location in the module. At this point, the module is ready to start processing data and starts processing data in step 808, where the module accesses data packets from one of its input data buffers. In step 810, the module checks to determine whether it is in the bypass mode of operation. If so, in step 812, the data packet accessed in step 808 is retransmitted without any data packet modification. If the module is not in the bypass mode, it must be in the active mode of its operation, and proceed to step 814. In step 814, the module reads the data packet to determine the identification of a source node from which the data packet originated. In step 816, the module checks the packet to determine whether the source node is valid. The specified source node can be compared with a list of valid nodes to determine whether the specified source node is currently valid. If the specified source node is not a valid node, the packet is discarded in step 818. In step 820, the processing program checks to determine whether a trigger event has occurred. trigger The occurrence of the event will affect the choice of false identification value to be used. Therefore, in step 822, the module determines the false identification values to be used based on one or more of trigger information, clock time, and mission plan. Then, the module proceeds to step 826, where the module manipulates the identification parameters of the data packet. Once the manipulation is completed, the data packet is retransmitted from the output port of the module to a neighboring node. In step 830, a determination is made as to whether the module has been ordered to power off. If yes, the processing procedure ends in step 832. In step 808, the process continues and the next data packet is accessed from the input data buffer of the module.
Now referring to FIG. 9, a flowchart outlining the method for managing a dynamic computer network described in this article is provided. The processing procedure starts at step 902 and continues to step 904, where a network model is established (e.g., as shown and described with respect to FIG. 3). In step 906, a determination is made as to whether a new mission plan is to be created. If so, a new mission plan is created in step 908 and the processing procedure continues to step 910, where the new mission plan is selected. Alternatively, if a desired mission plan has been established in step 906, the method can directly proceed to step 910, where an existing mission plan is selected. In step 912, the mission plan is communicated to the modules (for example, modules 105 to 107, 113, 114), where the mission plan is stored in a memory location. When the network administrator is ready to implement the new task model, in step 914, a command that causes the module to enter the standby mode as described herein is sent. When the module is in this standby mode, the mission plan is loaded in step 916. The loading of the mission plan occurs at each module, so that the mission plan can be used to control the operation of an application software running on the module. Specifically, the mission plan is a way to control the application software to perform dynamic manipulation of the identification parameters. In step 918, the task modules are again caused to enter the active operation mode, where each task module executes the manipulation of the identification parameters according to the task plan. Steps 914, 916, and 918 may occur in response to a specific command sent from the network administrator, or may occur automatically at each module in response to receiving the mission plan in step 912. After step 918, the module continues to execute processing according to the loaded mission plan. In step 920, check to determine whether the user has indicated a desire to change the task plan to continue the processing procedure; If so, the processing procedure returns to step 906, where the processing procedure continues as described above. If there is no instruction for the user or the network administrator to change an existing task plan, the processing program determines in step 922 whether the processing program has been instructed to terminate. If so, the processing procedure is terminated in step 924. If the termination instruction is not received, the processing procedure returns to step 920 and continues.
Referring now to FIG. 10, a block diagram showing a computer architecture of an exemplary module 1000 that can be used to perform the manipulation of the identification parameters described herein is provided. The module 1000 includes a processor 1012 (such as a central processing unit (CPU)), a main memory 1020 and a static memory 1018, which communicate with each other via a bus 1022. The computer system 1000 may further include a display unit 1002 (such as a liquid crystal display or LCD) to indicate the status of the module. The module 1000 may also include one or more network interface devices 1016, 1017 that allow the module to simultaneously receive and transmit data on two separate data lines. Two network interface ports facilitate the configuration shown in Figure 1, where each module is configured to simultaneously intercept and retransmit data packets received from two separate computing devices on the network.
The main memory 1020 includes a computer-readable storage medium 1010 on which one or more sets of instructions 1008 (for example, software program codes) are stored, and these instructions 1008 are configured to implement methods, procedures, or functions described herein. One or more. The instructions 1008 may also reside completely or at least partially in the static memory 1018 and/or the processor 1012 during the execution of the instructions by the module. The static memory 1018 and the processor 1012 can also form a machine-readable medium. In various embodiments of the present invention, a network interface device 1016 connected to a network environment uses command 1008 to communicate via the network.
Referring now to FIG. 11, an exemplary network management computer (NAC) 114 configured in accordance with the present invention is shown. NAC can include various types of computing systems and devices, including server computers, client user computers, personal computers (PCs), tablet PCs, laptop computers, desktop computers, control systems or capable of executing designated waiting Any other device of a set of instructions (sequentially or otherwise) of actions taken by the device. In addition, although shown in Figure 11 A single computer, but it should be understood that the phrase "NAC" includes any collection of computing devices that individually or collectively execute a group (or groups) of instructions to execute any one or more of the methodology discussed in this article.
11, NAC 104 includes a processor 1112 (such as a central processing unit (CPU)), a disk drive unit 1106, a main memory 1120, and a static memory 1118, which are connected to each other via a bus 1122 communication. The NAC 104 may further include a display unit 1102, such as a video display (for example, a liquid crystal display or LCD), a flat panel, a solid state display, or a cathode ray tube (CRT). The NAC 104 may include a user input device 1104 (for example, a keyboard), a cursor control device 1114 (for example, a mouse), and a network interface device 1116.
The drive unit 1106 includes a computer-readable storage medium 1110 on which one or more sets of instructions 1108 (eg, software program codes) are stored, and the instructions 1108 are configured to implement the methodology, procedures, or functions described herein One or more. The instructions 1108 may also reside in the main memory 1120, the static memory 1118, and/or the processor 1112, completely or at least partially during their execution. The main memory 1120 and the processor 1112 can also form a machine-readable medium.
Those familiar with this technology should understand that the module architecture shown in FIG. 10 and the NAC architecture in FIG. 11 each represent only one possible example of a computing device that can be used to execute the method described herein. However, the present invention is not limited in this respect and any other suitable computing device architecture can also be used without limitation. Dedicated hardware implementations include, but are not limited to, application-specific integrated circuits, programmable logic arrays, and other hardware devices can also be constructed to implement the methods described herein. The applications of devices and systems that can include various embodiments include a wide variety of electronic and computer systems. Some embodiments may implement the functions of two or more specific interconnected hardware devices (in which relevant control and data signals are communicated between modules and through the modules) or as part of a specific application integrated circuit. Therefore, the exemplary system can be applied to software, firmware, and hardware implementations.
According to various embodiments of the present invention, the method described herein is stored as a software program in a computer-readable storage medium and configured to run on a computer processor. In addition, software implementations may include (but are not limited to) distributed processing, component/object distributed processing, parallel processing, virtual machine processing, etc., which can also be constructed to implement the methods described herein.
Although the computer-readable storage media 1010 and 1110 are shown as a single storage medium in FIGS. 10 and 11, the term "computer-readable storage medium" should be regarded as including a single medium or multiple media storing one or more sets of instructions ( For example, centralized or distributed databases and/or associated high-speed caches and servers). The term "computer-readable storage medium" should also be regarded as including any medium capable of storing, encoding, or carrying a set of instructions for execution by a machine and causing the machine to execute any one or more of the methodologies of the present invention.
Therefore, the term "computer-readable medium" shall be regarded as including (but not limited to) solid-state memory, such as a memory card or housing one or more read-only (non-volatile) memory, random access memory or other Other packages for rewritable (volatile) memory; magneto-optical or optical media, such as magnetic disks or tapes. Therefore, the present disclosure is deemed to include any one or more computer-readable media listed in this article, and includes recognized equivalents and subsequent media (in which the software implementation in this article is stored).
Communicate with computing devices outside the dynamic network
Although the methods for dynamic manipulation of identification parameters described herein can work well within the network 100, these methods do have some problems regarding communication with computers outside the network 100. For example, a computer outside the network 100 will not know the dynamic processing program for manipulating identification parameters in operation. Therefore, if proper actions are not taken, communication with computers outside the network 100 may be interrupted. Therefore, the network 100 advantageously includes at least one bridge 115, which is configured to handle communications entering or leaving the network 100. The bridging ensures that these communications between computing devices within the network 100 and computing devices outside the network 100 can occur without errors.
The bridge 115 is a computing device having a functional block diagram similar to the functional block diagram of a module shown in FIG. 2. The bridge 115 may also have a computer architecture similar to the computer architecture shown in FIG. 10. The operations performed by the bridge 115 are similar to those performed by the modules 105 to 107, 113, 114. The bridge will receive data communications from the network 100 and will manipulate the identification parameters according to a mission plan before retransmitting these data communications to a second network 124. In some embodiments, these manipulations will involve converting false identification parameters back to true identification parameters, where the true identification parameters are determined based on the information contained in the mission plan. In the case that the second network does not dynamically modify the identification parameter information, this configuration is sufficient.
In an alternative embodiment, the second network 124 is a dynamic network that operates in a manner similar to the network 100. Therefore, the second network may have its own mission plan (second mission plan). In this case, the bridge will receive an identification parameter in a data communication from the first network, and transform a first set of such identification parameters with a false value into a true value instead. The mission plan of the second network 124 can specify a completely different dynamic network. For example, the mission plan of the second network can specify different identification parameters to be modified, different trigger timings, and so on. Therefore, the bridge will need to receive messages from the first network, correct the false values in the first group according to the mission plan of the first network 100, and then dynamically modify a second group according to the mission plan of the second network The same (or different) identification parameters. Once the second set of identification parameters have been appropriately converted to false values, the data communication is transmitted to the second network.
It should be understood that the first group is determined according to a first mission plan associated with the first network, and the second group is determined according to a second mission plan associated with the second network. Similarly, the false information contained in the first group is determined according to the first mission plan, and the false information contained in the second group is determined according to the second mission plan. The first set of identification parameters can be the same or different compared to the second set of identification parameters. Furthermore, it should be understood that the first group and the second group may include all or some of the identification parameters included in the data communication. The data communication will usually be a packet data communication containing a plurality of identification parameters. The bridge will also start from the second network 124 receives data communications, and will manipulate the identification parameters in these data communications according to the mission plan of the first network, the second network, or both. For example, the bridge can receive a second data communication from the second data network, and the second data communication can include a second plurality of identification parameters. Depending on whether the second network dynamically modifies the identification parameters, the second identification parameters may or may not specify false information. If the second network does not dynamically modify the identification parameters, the bridge only needs to use the mission plan associated with the first network to dynamically transform a set of second plural identification parameters to specify false information.
If the second network does dynamically modify the identification parameters, the bridge will need to use the mission plan associated with the second network to convert a first set of second plurality of identification parameters (with false values) to true values. This step is preferably performed before the bridge uses the mission plan associated with the first network to transform a second set of the second plurality of identification parameters into false values. The first group and the second group can be the same or different, and will be determined by the mission plan of each network in each case. Likewise, the transformations performed to convert the identification parameters to false values can be the same or different, and will depend on the mission plan associated with each network. After that, the bridge retransmits these data communications to the network 100.
In some embodiments, the false identification parameters of the networks 100 and 124 are determined according to a pseudo-random processing procedure. In this case, the pseudo-random processing program and/or the seed value of the pseudo-random processing program can be determined by the mission plan of the related network. Similarly, the selection of the identification parameters to be manipulated can be determined by a pseudo-random processing program, wherein the processing program and/or the seed value of the processing program are determined separately by the task plan associated with each network. As described above with respect to the module, the bridge will change the selection of the false identification parameter value and/or the identification parameter to be manipulated based on the occurrence of one or more trigger events. Unlike modules, the bridge 115 will need to perform these actions relative to trigger events that occur relative to the first network and the second network.
Except for potentially managing dynamic operations associated with more than one mission plan, the operation of the bridge 115 is similar to the operation of the module. However, it should be understood that the operation of bridge 115 Compared with the operation of modules 105 to 107, 113, 114, the operation system is different. For example, unlike the module, the position where the identification parameter manipulation is performed does not change in the case of the bridge 115. Alternatively, when at least one module in the network 100 is in the active mode, the bridge 115 will always be in the active mode because the bridge forms a connection with one of the computing devices outside the network 100.
Referring now to FIG. 12, a flowchart outlining the operation of the bridge 115 is provided. When the bridge is powered on, the process starts at step 1202 and continues to step 1204, where the bridge application software is initialized to execute the method described herein. In step 1206, load one or more mission plans from a memory location in the bridge. If the bridge is connected to a network that does not participate in the dynamic manipulation of the identification parameters, only a single mission plan is required. However, if two or more networks are bridged (each of which dynamically modifies the identification parameters as described herein), then in step 1206, more than one mission plan will be loaded. A first mission plan can define a dynamic control of a first network, and a second mission plan can define a dynamic control of a second network. At this point, the bridge is ready to start processing data and in step 1208, the bridge accesses data packets from one of the input data buffers. In step 1210, the bridge checks whether it is in the bypass mode of operation. If so, in step 1212, the data packet accessed in step 1208 is retransmitted without any data packet modification. If the bridge is not in the bypass mode, it must be in the active mode of its operation, and proceed to step 1214.
In step 1214, the bridge reads the data packet to determine the identification of the source node and the destination node from which the data packet originated. In step 1216, the bridge checks the data packet to determine whether the source node is valid. This can be done by comparing the specified source node in the data packet with the current list of valid source nodes. If the source node information is invalid, the packet is discarded in step 1218. In step 1220, the processing program checks to determine whether a trigger event has occurred. This is an important step because the occurrence of a trigger event can have a significant impact on the calculation of the appropriate false identification value. If the bridge uses two or more task plans, then this step The step includes determining whether a trigger event has occurred for any task plan. Note that each task plan may involve different trigger events.
The source and destination address information of the received data is important because it needs to allow the bridge to determine how to properly manipulate the identification parameters contained in the data communication. Once this information has been determined, the bridge then proceeds to step 1222, where the bridge determines the choice/value of the false identification parameter. Then, the processing procedure continues to step 1226, where it bridges the manipulation of the identification parameters of the data packet according to one or more mission plans. Once the manipulation is completed, the data packet is retransmitted from the bridged output port to a neighboring node at 1228. In step 1230, a determination is made as to whether the bridging power-off has been commanded. If yes, the processing procedure ends at step 1232; otherwise, the processing procedure returns to 1208. In step 1208, the process continues and the next data packet is accessed from the bridged input data buffer. As explained above, the type of manipulation performed at step 1216 will depend on the source and destination of the data communication, and whether there is one or more networks that are being dynamically manipulated.
Types of identification parameters that can be changed
Referring now to FIG. 13, a list of some identification parameters that can be manipulated by the modules 105 to 107, 113, 114 and/or by the bridge 115 is provided. Each of the parameters listed in FIG. 13 is included in a data communication, and the data communication is included in a network that uses the TCP/IP communication protocol. Most of the information types listed in Figure 13 are well-known to those who are familiar with this technology. However, a brief description of each information type and its use as an identification parameter is provided in this article. A brief discussion of the ways in which each identification parameter can be manipulated is also provided.
IP address. An IP address is a digital identifier assigned to each computing device participating in a computer network, where the network uses the well-known Internet protocol for communication. The IP address can be a 32-bit or 128-bit number. For the purpose of the present invention, the IP address number can be changed to a false value randomly selected (for example, using a pseudo-random number generator). Alternatively, a list can be predetermined from one of the false values (e.g., false IP address value may be randomly selected designated by the mission plan). The source and destination IP addresses are included in the TCP header part of the data packet. So this The manipulation of the value is performed by using the packet manipulation technique to change only the IP header information. When the packet reaches a second module (which can be manipulated), the fake IP address value is converted back to its true value. The second module uses the same pseudo-random processing procedure (or its reverse processing procedure) to derive the true IP address value based on the false value.
MAC address. The MAC address is a unique value assigned to a network interface device by the manufacturer and stored in the onboard ROM. For the purpose of the present invention, the source and/or destination MAC address can be changed to a false value randomly selected (for example, using a pseudo-random number generator). Alternatively, the false MAC value may be randomly selected from a predetermined list of false values (for example, a list designated by the mission plan). The source and destination MAC addresses are included in the IP header part of the data packet. Therefore, these equivalent manipulations are performed by changing only the Ethernet header information of each packet. When the packet reaches a second module (which can be manipulated), the false MAC address value is converted back to its true value. One of the modules receiving the packet will use the same pseudo-random processing procedure (or its inverse processing procedure) to derive the true MAC address value based on the false value.
Network/subnet. In some embodiments, the IP address can be regarded as a single identification parameter. However, an IP address is usually defined as including at least two parts, and these parts include the network prefix part and the host number part. The network prefix part identifies the network to which the data packet is to be transmitted. The host number identifies a specific node in a local area network (LAN). A subnet (sometimes called a subnet) is a logical part of an IP network. When the network is divided into two or more subnets, a part of the host number section of the IP address is used to specify the subnet number. For the purpose of the present invention, each of the network prefix, subnet number, and host number can be regarded as a separate identification parameter. Therefore, each of these identification parameters can be manipulated independently of the others in a pseudo-random manner. In addition, it should be understood that the data packet will contain the source IP address and the destination IP address. Therefore, the network prefix, subnet number, and host number can be manipulated in the source IP address and/or destination IP address, so that a total of six different variable identification parameters can be manipulated in a pseudo-random manner. The module receiving the packet will use the same pseudo-random processing procedure (or the inverse processing procedure of this processing procedure) as the source node to derive the true network/subnet information value based on the false value.
TCP sequence. Two client computers communicating with each other on opposite sides of the TCP session will each maintain a TCP sequence number. The serial number allows each computer to track how much data it has communicated. The TCP sequence number is included in the TCP header part of each packet transmitted during the session. At the beginning of the TCP session, the initial sequence number value is randomly selected. For the purpose of the present invention, the TCP sequence number can be manipulated as an identification parameter according to a pseudo-random processing procedure. For example, the TCP sequence number can be changed to a false value randomly selected (for example, using a pseudo-random number generator). When a packet is received at a different module of the network (which will dynamically change its position), the TCP sequence number can be converted from a false value back to a true value using the inverse processing procedure of the pseudo-random processing procedure.
Port number. The TCP/IP port number is included in the TCP or UDP header part of the data packet. For example, the port used in the TCP/IP communication protocol is well known in the art, and therefore will not be described in detail in this article. Port information is included in the TCP header part of the data packet. Therefore, the manipulation of port information is accomplished by only modifying the TCP header information to change the true port value to the false port value. As with the other identification parameters discussed in this article, the port number information can be manipulated or transformed into false values according to a pseudo-random processing procedure at the first module. Subsequently, the inverse process of the pseudo-random process can be used at the second module to transform the port information from a false value to a true value.
Although the present invention has been illustrated and described with respect to one or more embodiments, those skilled in the art will think of equivalent changes and modifications after reading and understanding this specification and the drawings. In addition, although a specific feature of the present invention may have been disclosed with respect to only one of several embodiments, this feature can be combined with one or more other features of other embodiments as may be desired and advantageous for any given or specific application . Therefore, the breadth and scope of the present invention should not be limited to any of the above-mentioned embodiments. In fact, the scope of the present invention should be defined according to the scope of the following patent applications and their equivalents.
5 members in 3 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 13369433 | United States of America | – | |
| 201213369433 | United States of America | A |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| US2013212676A1 | United States of America | A1 | |
| WO2013119428A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201347488AThis record | Taiwan Province of China | A | |
| US8935780B2 | United States of America | B2 | |
| TWI496445B | Taiwan Province of China | B |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- 201347488
- Application
- 102104970
Titles3
- English
- MISSION MANAGEMENT FOR DYNAMIC COMPUTER NETWORKS
- Chinese
- 動態電腦網路之任務管理
- English
- Task management of dynamic computer network
Classification
- CPC, 5
- H04L63/0414
- H04L61/2539
- H04L63/1441
- H04L63/20
- H04L2101/622
- IPC, 2
- H04L29 06
- G06F21 00