IP Library › Granted Patent US 8,495,738
Granted Patent B2
US 8,495,738 · App. 13/278,861 · Granted Jul 23, 2013

Stealth network node

Inventors: James B. Burnham (San Ramon, CA); Neil R. Lofland (San Jose, CA); Michael Hegarty (Bellevue, NE); Robert W. Hale (Manassas, VA)
Assignee: Lockheed Martin Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,495,738
App. No.
13/278,861
Granted
Jul 23, 2013
Kind
B2
Abstract

A method, a network node, and a set of instructions are disclosed. A network interface 260 may have a precedent network address to represent the network node 104 in the network 100 . A processor 210 may recognize an address hop trigger. The processor 210 may change to a successor network address to represent the network node 104 in the network 100.

Claims (24)

1. A method for protecting a network node from malicious mapping, comprising:

receiving an address hopping instruction from at least one of a hypervisor, an end-node operating system network stack and a network interface card extension;

establishing a precedent network address to represent the network node in a network;

recognizing an address hop trigger;

changing to a successor network address to represent the network node in the network;

receiving an authentication request from a user device;

sending an address hopping instruction to the user device in response to the authentication request; and

interacting with a proxy to present the user device with a seamless connection experience while implementing the address hopping,

wherein the address hopping instruction describes an address hopping sequence and the address hop trigger.

2. The method of claim 1 , wherein the address hop trigger is at least one of a temporal hop trigger and an event hop trigger.

3. The method of claim 1 , further comprising:

assigning a honeypot to the precedent network address after changing to the successor network address.

4. A non-transitory machine-readable data storage medium on which is recorded a set of instructions that, when executed by one or more processors, causes the one or more processors to perform a method comprising:

receiving an address hopping instruction from at least one of a hypervisor, an end-node operating system network stack and a network interface card extension;

establishing a precedent network address to represent the network node in a network;

recognizing an address hop trigger;

changing to a successor network address to represent the network node in the network;

receiving an authentication request from a user device;

sending an address hopping instruction to the user device in response to the authentication request; and

interacting with a proxy to present the user device with a seamless connection experience while implementing the address hopping,

wherein the address hopping instruction describes an address hopping sequence and the address hop trigger.

5. The non-transitory machine-readable data storage medium of claim 4 , wherein the address hop trigger is at least one of a temporal hop trigger and an event hop trigger.

6. The non-transitory machine-readable data storage medium of claim 4 , wherein the method further comprises:

assigning a honeypot to the precedent network address after changing to the successor network address.

Continuity (1)
Related Publication 20130104228A1 · Apr 25, 2013