WO0070458A1

Method of communications and communication network intrusion protection methods and intrusion attempt detection system

Abstract

The intrusion protection method and system for a communication network provides address agility wherein the cyber coordinates of a target host (14) are changed both on a determined time schedule and when an intrusion attempt is detected. The system includes a managment unit (18) which generates a random sequence of cyber coordinates and maintains a series of tables containing the current and next set of cyber coordinates. These cyber coordinates are distributed to authorized users (12) under an encryption process to prevent unauthorized access.

WO0070458A1, drawing sheet 1
Sheet 1 of 6

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

25 claims: 3 independent, 22 dependent

  1. 1
    I claim:1. A method for protecting a communications device which is connected to a communications system against an unauthorized intrusion which includes: providing the communications device with at least one identifier, providing the at least one identifier for use in accessing the communications device to entities authorized to access said communications device, sensing the presence or absence of said identifier before granting access to said communications device, providing access to said communications device when the use of said at least one correct identifier is sensed denying access to said communications device and providing said communications device with at least one new identifier when the absence of the correct at least one identifier is sensed during an attempt to access said communications device, and providing said at least one new identifier to entities authorized to access said communications device.
  2. 16
    An intrusion protection method for protecting a host computer connected to a computer communications system which includes one or more authorized computers having access to said computer communications system which are authorized to access said host computer which includes:providing each authorized computer with an authorized computer identifying address, providing said host computer with a host computer destination identifier and a host computer port identifier, providing said host computer destination identifier and said host computer port identifier to said authorized computers, causing each authorized computer to access said host computer with the host computer destination and port identifiers and said authorized computer identifying address, sensing the presence or absence of said host computer destination and port identifiers and said authorized computer identifying address before granting access to said host computer, providing access to said host computer when the use of correct computer destination and port identifiers and a correct authorized computer identifying address is sensed, and denying immediate access to said host computer when the absence of any one or more of the correct host computer destination and port identifiers or the authorized computer identifying address is sensed.
  3. 24
    A method of communication with a remote entity over a communication system which includes providing the remote entity with at least one remote entity cyber coordinate identifier, providing the remote entity cyber coordinate identifier to one or more base entities authorized to communicate with said remote entity, periodically changing the remote entity cyber coordinate identifier to a new remote entity cyber coordinate identifier and providing the new remote entity cyber coordinate identifier to said one or more base entities.