Temporal Port Mutation Protocol (TPMP)
Abstract
The proliferation of automated port-scanning tools such as Nmap and Masscan has rendered static listening-port configurations a critical and pervasive attack surface for networked services. This paper introduces the Temporal Port Mutation Protocol (TPMP), a novel cryptographic port-hopping framework that eliminates the concept of a fixed network attack surface at the transport layer. TPMP derives a time-bounded listening port by computing HMAC-SHA256 over a shared secret and a TOTP-style time-window counter, placing the resultant port within the IANA ephemeral range (49152-65535). Both the server and an authorised client independently compute the identical port without any network negotiation, as both possess the shared secret and access to a synchronised clock. The protocol incorporates Elliptic Curve Diffie-Hellman (ECDH) key exchange over P-256 followed by HKDF key derivation for initial secret establishment, TLS 1.3 for all session-layer communication, a NTP-inspired clock-drift compensation algorithm, and a cryptographically authenticated session-migration mechanism (SESSION_RESUME) that allows established TCP sessions to survive port rotations without interruption. A full reference implementation in Python is provided, comprising 58 unit tests, 20 integration tests exercising live TLS sockets and a live port-rotation cycle, and a real-time terminal dashboard. Empirical evaluation demonstrates that the protocol renders ephemeral-range port scanning computationally infeasible within a single rotation window, rejects forged session-resume packets with 100% accuracy, and sustains 50 concurrent messages and eight simultaneous client sessions across port rotations without message loss.
References
IANA. (2024). Service Name and Transport Protocol Port Number Registry. Internet Assigned Numbers Authority. Available at: https://www.iana.org/assignments/servi ce-names-port-numbers/
Bellovin, S. M. (1989). Security Problems in the TCP/IP Protocol Suite. ACM SIGCOMM Computer Communication Review, 19(2), 32–48. https://doi.org/10.1145/378444.378449
Lyon, G. F. (2009). Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and
Security Scanning. Insecure.Com LLC. Available at: https://nmap.org/book/
Graham, R. D. (2014). Masscan: TCP port scanner, spews SYN packets asynchronously. GitHub Repository. Available at: https://github.com/robertdavidgraham/m asscan
Durumeric, Z., Wustrow, E., & Halderman, J. A. (2013). ZMap: Fast Internet-Wide Scanning and Its Security Applications. In Proceedings of the 22nd USENIX Security Symposium (pp. 605–620).
Matherly, J. (2015). Complete Guide to Shodan. Shodan Inc. Available at: https://leanpub.com/shodan
Krzywinski, M. (2003). Port Knocking: Network Authentication Across Closed Ports. SysAdmin Magazine, 12, 12–17. Available at: https://www.portknocking.org/
Deraison, R. (2007). Security analysis of port knocking. Journal of Network Security, 4(2), 1–15.
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture. NIST Special Publication 800-207. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
ENISA. (2021). Threat Landscape 2021. European Union Agency for Cybersecurity. Available at: https://www.enisa.europa.eu/publication s/enisa-threat-landscape-2021
Refbacks
- There are currently no refbacks.