Automatic deployment of decoys

The automatic decoy deployment system addresses inefficiencies in static decoy systems by dynamically deploying decoys based on network intrusions, optimizing resource use and enhancing cyber defense deception efficacy.

WO2025180755A1PCT designated stage Publication Date: 2025-09-04BRITISH TELECOM PLC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/052493
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-28
Filing Date
2025-01-31
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

Existing cyber defense deception systems face inefficiencies due to static decoy deployments, which do not adapt to the current network environment, leading to increased computational processing and memory usage without optimizing decoy usage.

Method used

An automatic decoy deployment system that dynamically deploys decoys based on network intrusion detection, using decoy databases and generating new decoys when needed, redirecting traffic to appropriate decoys based on attacker identity, attack type, and target.

Benefits of technology

Optimizes decoy usage, improves efficiency by deploying only necessary decoys, and enhances cyber defense deception effectiveness by adapting to real-time network conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025052493_04092025_PF_FP_ABST
    Figure EP2025052493_04092025_PF_FP_ABST
Patent Text Reader

Abstract

Cyber defensive deception (CDD) encompasses a range of techniques which can be used to mislead and deceive an attacker. A cyber deception method comprises detecting a network intrusion, determining one or more deception decoys to deploy in response to the network intrusion, and deploying the one or more deception decoys in response to the intrusion.
Need to check novelty before this filing date? Find Prior Art

Description

AUTOMATIC DEPLOYMENT OF DECOYS

[0001] The present invention relates to a method of deploying a cyber defence deception strategy.BACKGROUND

[0002] Deception relates to manipulating an attacker’s beliefs to mislead their decision making, i.e. inducing the attacker to act sub-optimally so as to delay their attack and save the assets. Deception technology typically implements traps to monitor the suspicious activities in an attack chain and provide an understanding of the attacker’s behaviour and intentions.

[0003] The examples described herein are not limited to examples which solve problems mentioned in this background section.SUMMARY

[0004] Examples of preferred aspects and embodiments of the invention are as set out in the accompanying independent and dependent claims.

[0005] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0006] According to a first aspect there is a computer-implemented cyber deception method comprising: detecting a network intrusion; determining one or more deception decoys to deploy in response to the network intrusion; and deploying the one or more deception decoys in response to the intrusion.

[0007] In some examples, the method further comprising redirecting network traffic from an attacker to the one or more deception decoys.

[0008] In some examples, wherein determining one or more deception decoys to deploy comprises: searching a decoy database to identify one or more suitable decoys; responsive to identifying one or more suitable decoys, retrieving the one or more suitable decoys; responsive to identifying no suitable decoys, generating one or more new decoys and storing the one or more new decoys in the decoy database.

[0009] In some examples, the one or more deception decoys are determined based on at least one of an attacker identity, an attack type and an attack target.

[0010] In a second aspect, there is a computer system including a processor and memory storing computer program code for performing the steps of:detecting a network intrusion; determining one or more deception decoys to deploy in response to the network intrusion; and deploying the one or more deception decoys in response to the intrusion.

[0011] In some examples, the method further comprising redirecting network traffic from an attacker to the one or more deception decoys.

[0012] In some examples, determining one or more deception decoys to deploy comprises: searching a decoy database to identify one or more suitable decoys; responsive to identifying one or more suitable decoys, retrieving the one or more suitable decoys; responsive to identifying no suitable decoys, generating one or more new decoys and storing the one or more new decoys in the decoy database.

[0013] In some examples, the one or more deception decoys are determined based on at least one of an attacker identity, an attack type and an attack target.

[0014] In a third aspect, there is a computer program element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer to perform the steps of: detecting a network intrusion; determining one or more deception decoys to deploy in response to the network intrusion; and deploying the one or more deception decoys in response to the intrusion.

[0015] In some examples, the method further comprising redirecting network traffic from an attacker to the one or more deception decoys.

[0016] In some examples, determining one or more deception decoys to deploy comprises: searching a decoy database to identify one or more suitable decoys; responsive to identifying one or more suitable decoys, retrieving the one or more suitable decoys; responsive to identifying no suitable decoys, generating one or more new decoys and storing the one or more new decoys in the decoy database.

[0017] In some examples, the one or more deception decoys are determined based on at least one of an attacker identity, an attack type and an attack target.

[0018] It will also be apparent to anyone of ordinary skill in the art, that some of the preferred features indicated above as preferable in the context of one of the aspects of the disclosed technology indicated may replace one or more preferred features of other ones of the preferred aspects of the disclosed technology. Such apparentcombinations are not explicitly listed above under each such possible additional aspect for the sake of conciseness.

[0019] Other examples will become apparent from the following detailed description, which, when taken in conjunction with the drawings, illustrate by way of example the principles of the disclosed technology.BRIEF DESCRIPTION OF THE DRAWINGS

[0001] FIG. 1 is a schematic diagram of a cyber defense deception deployment architecture;

[0002] FIG. 2 is a schematic diagram of an automatic decoy deployment system;

[0003] FIG. 3 is a schematic diagram of how the automatic decoy deployment system fits within the cyber defense deception deployment architecture; and

[0004] FIG. 4 is a flow diagram of an exemplary method of operation of automatic decoy deployment.

[0005] FIG. 5 is a schematic diagram of an exemplary response to an SQL injection attack; and

[0006] FIG. 6 is a schematic diagram of an exemplary response to lateral movement detection.

[0007] The accompanying drawings illustrate various examples. The skilled person will appreciate that the illustrated element boundaries (e.g., boxes, groups of boxes, or other shapes) in the drawings represent one example of the boundaries. It may be that in some examples, one element may be designed as multiple elements or that multiple elements may be designed as one element. Common reference numerals are used throughout the figures, where appropriate, to indicate similar features.DETAILED DESCRIPTION

[0008] The following description is made for the purpose of illustrating the general principles of the present technology and is not meant to limit the inventive concepts claimed herein. As will be apparent to anyone of ordinary skill in the art, one or more or all of the particular features described herein in the context of one embodiment are also present in some other embodiment(s) and / or can be used in combination with other described features in various possible combinations and permutations in some other embodiment(s).

[0009] A key concept of deception is to manipulate an attacker’s beliefs to mislead their decision making, inducing them to act sub-optimally thus delaying attacks and save the assets. Deception technology can form a stand-alone platform that implements effective traps to monitor the suspicious activities in the attack chain and provides deep understanding of the attacker’s behaviour. Cyber defensive deception (CDD) encompasses a range of techniques which can be used to mislead and deceivean attacker. CDD protects the organization's important data by deploying various artefacts of deception technologies such as decoys, breadcrumbs, baits and lure.

[0010] To implement these deception techniques, four deceptive artefacts are typically required: decoys, breadcrumbs, baits and lure. Decoys are IT assets that either use real licensed operating system software or are emulations of real devices. Examples of decoys include: servers, workstations, applications, printers, loT / OT / ICS, network services, mailbox, AD forest. Breadcrumbs are deception assets deployed on to the devices of real environment and used to divert / lead to decoys. Examples of breadcrumbs include: registry entries, files and folders, memory credentials, browser history, mapped drive, credential store. Baits are deception assets used as host tripwires. Examples of baits include: beaconing docs, database rows, ransomware, files and folders, DNS records, processes, directory browsing, tainted tools, fake AV, listeners. Lures are the deception assets to make the traps (decoys, breadcrumbs, and baits) attractive for adversaries. Examples of lures include: vulnerability, misconfigurations, default / weak credentials, weak permission, registration in catalogues like AD, entity names.

[0011] The present invention provides a system for an automatic deployment of a deception artefact, specifically a decoy, after analysing the network traffic. Automatic decoy deployment may form part of a Cyber Defence Deception (CDD) security system.

[0012] An increased number of deceptive artefacts will increase the security but in terms of cyber security more deceptive artefacts deployment will also impact the computational processing and memory usage that will impact overall efficiency of the network. Thus, deceptive artefacts should be deployed as and when required for CDD.

[0013] In some examples, the present invention involves the use of deceptive strategies to automatically deploy the decoys when an intrusion detection system provides information about an attack. An identical decoy of the corresponding real system that is (or could potentially be) under attack will be deployed and traffic will be diverted to the new deployed decoy to capture the attacker behaviour for future analysis. This approach is to automatically place the decoy and divert the traffic of the decoy whereas existing solutions consider only static deployment of decoys irrespective of the current status of the environment.

[0014] An automatic decoy deployment approach has many benefits including: (i) optimising the deception artefact usage, (ii) efficient decoy deployment by automatically deploying decoys when needed, (iii) improving deception effectiveness by deploying only appropriate decoys, (iv)improving overall efficiency of CDD.

[0015] Figure 1 is a block diagram of an exemplary computer architecture 100 comprising four modules 101 -104 that are configured individually.

[0016] An environment analysis module 101 is associated with the environment information 105 provided as input by a user so as to facilitate the design of deception strategy. The environment analysis explores the environment information 105 as input by the user(s) in a variety of ways, including segregating the information in useful blocks, extracting the vulnerabilities / risks could be exploited by an attacker, and / or categorise devices in groups.

[0017] A deception strategy module 102 is responsible for designing the deception strategy based on input from environmental analysis module 101. In some examples, the deception strategy module 102 additionally designs the deception strategy on the basis of the deception constraints 106. There are several possible deception strategies that can be employed, such as resolving the vulnerabilities detected and informed by the environment analysis module 101 or ranking the device groups. Another possible deception strategy, and the subject of the present invention, is calculating the number of deception artefacts needed to enhance the environment security. In some examples, a deception effectiveness metric is utilised by the deception strategy module 102.

[0018] A deception deployment module 103 creates and deploys the deception artefacts, based on the deception strategy.

[0019] A deception analysis module 104 evaluates the deception deployment module 103 so that any required improvements are recorded.

[0020] In some examples, there is a human in the loop 108 that operates to verify the result of each module and perform the changes / updates if required. In some examples, the human in the loop 108 is not a human user, but instead a model programmed to verify the results of each module. The human in the loop / model 108 may verify the result / solution of each module by a variety of methods, including: populating a database by users or organization data and / or previous recording to check the generated reactions by each module, matching the threats to reduce false positives, and / or confirming the deception artefacts and connections.

[0021] FIG. 2 is an exemplary schematic diagram of an automatic decoy deployment system. The automatic decoy deployment system consists of 5 main components: Network analysis, Decoy configuration, Create Decoy, Populate Decoy Database and Deploy Decoy. The Network Analysis component analyses the traffic to capture any suspicious activity to identify at least one targeted host and match attack stages to the activity. The decoy (target) configuration component checks the targeted nodes configuration so as to use that to match with decoy’s database. In the scenario that nodecoys are matched with the identified activity, new decoys are created by the Create decoys component. The Populate Decoy Database component uploads the new created decoy to the database for future use if required. The Deploy Decoys component deploys the specific decoy on the targeted host(s).

[0022] Fig. 3 shows how the decoys automatic deployment components are placed in modules of the CDD architecture. The network analysis component is part of the Environment Analysis, the decoy configuration is part of Deception Strategy and the decoy creation and deployment components form part of the Deception Deployment. The new decoy is populated to the decoy database in a Validation module (which may be a human in the loop).

[0023] Fig. 4 is a flowchart that represents exemplary implementation of the automatic deployment of decoys. The captured network traffic is analysed and, based on the phase where adversary behaviour is detected, appropriate decoy information is considered. If similar decoy information is available in a decoy database, that decoy’s configuration is used to create the decoy and deploy said decoy. Otherwise, a new decoy is generated and the corresponding decoy configuration uploaded to the decoy database.

[0024] There are several methods of transferring traffic from one machine to another (i.e. to a decoy) depending on the machine’s type and available information. Herein is an example of redirection option for Internet traffic from one computer running Linux to another IP address using IPTables. IPTables is a software firewall that ships with most distributions of Linux. Commands used to configure IPTables on a Linux server to redirect all the traffic coming on port 80, (which is a default web server port), to a server with the IP aa.bb.cc.dd are mentioned below as three steps.

[0025] The first step is to set the Linux box to allow this kind of forwarding to take place. Open a terminal window, log in as root user and run the following command:# echo 1 > / proc / sys / net / ipv4 / ip_forward

[0026] The next step is to tell IPTables to redirect the traffic to the new server:# iptables -t nat -A PREROUTING -p tcp -dport 80 -j DNAT -to-destination aa.bb.cc.dd

[0027] The third and final step is to tell IPTables to rewrite the origin of connections to the new server’s port 80 to appear to come from the old server:# iptables -t nat -A POSTROUTING -p tcp -d aa.bb.cc.dd -dport 80 -j MASQUERADE

[0028] To redirect traffic from port 80 to 443 on another server:

[0029] # iptables -t nat -A PREROUTING -p tcp -dport 80 -j DNAT -to-destination aa.bb.cc.dd:443

[0030] IPtables use all the other parameters that is known. To redirect traffic from a specific IP, add -s with IP. For example, to redirect only the traffic that comes from 10.10.0.5:# iptables -t nat -A PREROUTING -p tcp -s 10.10.0.5 --dport 80 -j DNAT -to- destination aa.bb.cc.dd:443

[0031] Or an entire network ( / 24):# iptables -t nat -A PREROUTING -p tcp -s 10.10.0.0 / 24 --dport 80 -j DNAT -to- destination aa.bb.cc.dd

[0032] To specify the network interface, add -i:# iptables -t nat -A PREROUTING -p tcp -i eth1 -dport 80 -j DNAT -to-destination aa.bb.cc.dd

[0033] Network flow tables (IPTables, FlowTables, Routing Tables, etc) can be updated using scripting and scripts can automatically be generated according to various triggering conditions.

[0034] Possible use cases include an SQL Injection attack. In this scenario, an attacker may try to target a specific Database such as MySQL Database for an SQL injection attack. An intrusion Detection System (IDS) will detect that SQL injection attack by analysing the network traffic that might be performed on a specific machine. With this information, automatic decoy deployment can launch a decoy with attacked machine’s configuration and fake MSQL information in the network, as shown in Figure 5.

[0035] Another possible use case is against lateral movement. An attacker may try to collect information from an organization by lateral movement within the network. The intrusion Detection System (IDS) will detect the movement and, with this information, automatic decoy deployment can launch a decoy with a lucrative configuration and fake information in the network, as shown in Figure 6.

[0036] The steps of the methods described herein may be carried out in any suitable order, or simultaneously where appropriate. The arrows between boxes in the figures show one example sequence of method steps but are not intended to exclude other sequences or the performance of multiple steps in parallel. Additionally, individual blocks may be deleted from any of the methods without departing from the spirit and scope of the subject matter described herein. Aspects of any of the examples described above may be combined with aspects of any of the other examples described to form further examples without losing the effect sought. Where elements of the figures are shown connected by arrows, it will be appreciated that these arrows show just one example flow of communications (including data and control messages) between elements. The flow between elements may be in either direction or in bothdirections. Where the description has explicitly disclosed in isolation some individual features, any apparent combination of two or more such features is considered also to be disclosed, to the extent that such features or combinations are apparent and capable of being carried out based on the present specification as a whole in the light of the common general knowledge of a person skilled in the art, irrespective of whether such features or combinations of features solve any problems disclosed herein. In view of the foregoing description it will be evident to a person skilled in the art that various modifications may be made within the scope of the invention.

Claims

CLAIMS1 . A computer-implemented cyber deception method comprising: detecting a network intrusion; determining one or more deception decoys to deploy in response to the network intrusion; and deploying the one or more deception decoys in response to the intrusion; wherein determining one or more deception decoys to deploy comprises searching a decoy database to identify one or more suitable decoys; responsive to identifying one or more suitable decoys, retrieving the one or more suitable decoys; responsive to identifying no suitable decoys, generating one or more new decoys and storing the one or more new decoys in the decoy database.

2. The method of claim 1 , further comprising redirecting network traffic from an attacker to the one or more deception decoys.

3. The method of any preceding claim, wherein decoy configurations are determined based on at least one of an attacker identity, an attack type and an attack target.

4. A computer system including a processor and memory storing computer program code for performing the steps of any preceding claim.

5. A computer program element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer to perform the steps of a method as claimed in any of claims 1 to 4.

Citation Information

Patent Citations

  • Network protection methods and systems, electronic devices, and computer-readable storage media

    CN111970310B

  • Cyber security deception system

    GB2606591A

  • Systems and Methods for Detecting and Tracking Adversary Trajectory

    US20170302691A1