Active Token Intrusion Detection via Traffic Embedding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing token placement techniques in computer network security fail to detect sophisticated network intruders who monitor and modify network traffic without exploring client or server end stations for information, allowing them to perform Man-In-The-Middle attacks undetected.

Innovation Solution

The implementation of 'active tokens' that are misleading information packets sent over the network, which can be monitored to detect intruders by assessing whether they attempt to access or use the fake information, using a system comprising a Token Transmission Server, Token Monitoring Server, and optionally a Token Sink Server to identify and alert on suspicious network activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional honey tokens are placed in server data repositories, then intrusion detection capability is provided, but sophisticated intruders who monitor and modify network traffic without exploring end stations can evade detection

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidevasion by sophisticated intruders
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional honeypot approach by placing fake information (active tokens) within legitimate-looking network traffic instead of placing traditional honeypots or honey tokens in accessible locations. Rather than waiting for intruders to find stationary tokens, the system embeds deceptive tokens inside normal traffic flows that intruders are already monitoring, reversing the detection paradigm from passive waiting to active embedding within the traffic stream.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent uses legitimate network traffic as an intermediary carrier to deliver active tokens to intruders. Instead of directly placing detectable tokens in vulnerable locations, the system embeds tokens within normal traffic flows, using the traffic itself as a medium to transport the deceptive information to where sophisticated intruders are already positioned and monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If honeypots are deployed to detect intrusions, then attacker activity can be monitored, but additional computing resources need to be acquired, configured, deployed, managed, and monitored

Engineering Contradiction:
Improveintrusion detectionVSAvoidresource management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes existing network traffic multi-functional by embedding active tokens within normal traffic flows. The same traffic serves both its original communication purpose and the additional function of delivering deceptive tokens to intruders, eliminating the need for separate honeypot infrastructure and reducing resource management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates copies of legitimate traffic patterns that contain embedded active tokens. Rather than deploying physical honeypot systems, the patent generates token-containing traffic copies that mimic normal network flows, allowing intrusion detection without the overhead of maintaining separate honeypot infrastructure.

Inventive Principle:
Principle #26Copying

3Loss of time

If active tokens are embedded in network traffic, then early detection of intruders is enabled, but the system must monitor and analyze traffic patterns to identify deviations

Engineering Contradiction:
Improvedetection timingVSAvoidtraffic monitoring complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by embedding active tokens into network traffic before intruders can establish their presence. The tokens are pre-placed within traffic flows that will naturally reach monitoring points, allowing detection to occur as soon as intruders interact with the embedded tokens rather than waiting for later signs of compromise.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10805325B2Techniques for detecting enterprise intrusions utilizing active tokens
Publication Date: 2020.10.13 IMPERVA INC
  • US10805325B2 patent drawing
  • US10805325B2 patent drawing
  • US10805325B2 patent drawing

AI summary

A Token Transmission Server transmits active tokens within an enterprise network. The active tokens include either active data tokens or active request tokens, and are fraudulent from the perspective of the enterprise. A Token Monitoring Server monitors network traffic within the enterprise network to detect the presence of network traffic being originated by an enterprise device based upon the active tokens, and generates an alert indicating that the enterprise device is likely compromised.