IBM Technical Disclosure Bulletin
English (United States)
4 pages / 92.5 KB
The Method for preventing unauthorized network access by occupying idle IP addresses
Idea of disclosure
1. Describe your invention, stating problem solved (if appropriate), and indicating the advantages of using the invention.
The Resouce X manages idle IP addresses in a IP sub network. Resource X registers all IP adresses which are not assigned by DHCP servers or network administrator, to its Network interfaces. This prevents to access by unauthorized users, because all IP addresses are occupied. User should register his MAC address of NetWork Interface Card(NIC) on List of acceptable MAC addresses using IP addresses, before user begins to use new IP address. Resource X release one IP address and assign it to user. If user has non-registered MAC address, user cannot use IP address, because there is no idle IP address in a sub network. It prevents to use network resources by unauthorized users.
Administrator does not care idle IP addresses in general. Router can block to access over sub network by its configuration, but router cannot block to access in its sub network. Any user can set idle IP address to his NIC manually, can easily use network resources in its sub network. It is easy to crack network resources. It is needed to countermeasure against unauthorized access.
This invention solves to create a status that all IP addresses are in use, which were idle temporary or everlastingly. It assigns IP address not in use to a special Resource X. No idle IP address exists in a sub network.
1. Fair accounting - unauthorized use is prevented.
2. In Apartments ;
1. Prevents to access by unauthorized users which uses idle IP addresses.
2. Prevents to scan address and port to check absence or not.
3. Can detect an indiscriminate attack in a sub network. Switching device is used for network connection generally, so that special device is needed to monitor communication between 2 users. Using this method, unauthorized access is detected easily, by establishment of reserved address / size of address space.
2. How does the invention solve the problem or achieve an advantage, (a description of "the invention", including figures inline as appropriate)?
Methods: Configuration of invetion
i. Basic configuration Figure 1 is Class C sub network, 192.168.0.0/24, which constitutes a part of intranet.
IP Sub Network（Class C：192.168.0/24)
IP address space
192.168.0.1 - 192.168.0.254 (254)
Fixed Address space
192.168.0.1 - 192.168.0.100 DHCP Address space
192.168.0.101 - 192.168.0.254
DHCP Relay Agent (RA)
List of registered M AC addresses
Work Group Serve...