Active Token Intrusion Detection via Traffic Embedding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing token placement techniques in computer network security fail to detect sophisticated network intruders who monitor and modify network traffic without exploring client or server end stations for information, allowing them to perform Man-In-The-Middle attacks undetected.
Innovation Solution
The implementation of 'active tokens' that are misleading information packets sent over the network, which can be monitored to detect intruders by assessing whether they attempt to access or use the fake information, using a system comprising a Token Transmission Server, Token Monitoring Server, and optionally a Token Sink Server to identify and alert on suspicious network activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional honey tokens are placed in server data repositories, then intrusion detection capability is provided, but sophisticated intruders who monitor and modify network traffic without exploring end stations can evade detection
Solution Approach 1:
The patent inverts the traditional honeypot approach by placing fake information (active tokens) within legitimate-looking network traffic instead of placing traditional honeypots or honey tokens in accessible locations. Rather than waiting for intruders to find stationary tokens, the system embeds deceptive tokens inside normal traffic flows that intruders are already monitoring, reversing the detection paradigm from passive waiting to active embedding within the traffic stream.
Solution Approach 2:
The patent uses legitimate network traffic as an intermediary carrier to deliver active tokens to intruders. Instead of directly placing detectable tokens in vulnerable locations, the system embeds tokens within normal traffic flows, using the traffic itself as a medium to transport the deceptive information to where sophisticated intruders are already positioned and monitoring.
2Reliability
If honeypots are deployed to detect intrusions, then attacker activity can be monitored, but additional computing resources need to be acquired, configured, deployed, managed, and monitored
Solution Approach 1:
The patent makes existing network traffic multi-functional by embedding active tokens within normal traffic flows. The same traffic serves both its original communication purpose and the additional function of delivering deceptive tokens to intruders, eliminating the need for separate honeypot infrastructure and reducing resource management complexity.
Solution Approach 2:
The system creates copies of legitimate traffic patterns that contain embedded active tokens. Rather than deploying physical honeypot systems, the patent generates token-containing traffic copies that mimic normal network flows, allowing intrusion detection without the overhead of maintaining separate honeypot infrastructure.
3Loss of time
If active tokens are embedded in network traffic, then early detection of intruders is enabled, but the system must monitor and analyze traffic patterns to identify deviations
Solution Approach 1:
The patent performs preliminary action by embedding active tokens into network traffic before intruders can establish their presence. The tokens are pre-placed within traffic flows that will naturally reach monitoring points, allowing detection to occur as soon as intruders interact with the embedded tokens rather than waiting for later signs of compromise.
Data Source
AI summary
A Token Transmission Server transmits active tokens within an enterprise network. The active tokens include either active data tokens or active request tokens, and are fraudulent from the perspective of the enterprise. A Token Monitoring Server monitors network traffic within the enterprise network to detect the presence of network traffic being originated by an enterprise device based upon the active tokens, and generates an alert indicating that the enterprise device is likely compromised.


