Adaptive Network Decoys for Evolving Attacker Preferences

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network decoys become stale and ineffective as attackers become sophisticated, and simply alternating between predetermined decoys does not effectively deter advanced attackers.

Innovation Solution

A method of maintaining a pool of dynamic and adaptive network decoys by monitoring interactions with attackers to learn their preferences, dynamically creating new decoys that are increasingly attractive, and evolving the decoy pool using machine learning techniques and evolutionary processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If predetermined decoys are deployed on the network, then network security is enhanced by providing targets for attackers, but the decoys become stale and ineffective as attackers become sophisticated

Engineering Contradiction:
Improvedecoy effectivenessVSAvoiddecoy adaptability to attacker evolution
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic decoy deployment by continuously monitoring attacker interactions and automatically updating decoy configurations in real-time. The system transitions from static predetermined decoys to dynamic adaptive decoys that evolve their characteristics based on observed attacker behavior, ensuring ongoing effectiveness against sophisticated threats

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes key parameters of decoys including their configuration, services offered, and behavioral characteristics based on monitored attacker preferences. By dynamically adjusting these parameters according to learned attacker patterns, the decoys maintain their attractiveness and effectiveness while adapting to evolving attack methodologies

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the decoy pool is updated dynamically based on attacker interactions, then the decoys remain effective against sophisticated attackers, but the system complexity increases

Engineering Contradiction:
Improvedecoy effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback loop where attacker interactions with decoys are continuously monitored and analyzed. This feedback informs automatic updates to the decoy pool, creating a closed-loop system that adapts to attacker behavior. The feedback mechanism enables the system to maintain effectiveness without requiring complex manual intervention by security personnel

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-updating of the decoy pool by automatically monitoring attacker behavior, analyzing preferences, and generating updated decoy configurations without external intervention. This self-service capability reduces operational complexity while maintaining high adaptability to evolving threats

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If machine learning techniques are used to evolve decoys, then the system can learn and adapt to attacker preferences, but the computational resources and time required increase

Engineering Contradiction:
Improveattacker preference learningVSAvoiddecoy evolution time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system pre-generates multiple candidate decoy configurations and pre-computes potential evolutionary paths using machine learning models. By preparing these options in advance, the system can rapidly select and deploy appropriate decoys when attacker interactions are detected, reducing the time penalty associated with real-time adaptation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260012485A1Adaptive dynamic network decoy system
Publication Date: 2026.01.08 THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY OF THE NAVY
  • US20260012485A1 patent drawing
  • US20260012485A1 patent drawing
  • US20260012485A1 patent drawing

AI summary

A method of maintaining a pool of network decoys includes evolving, over a plurality of epochs, the pool of network decoys towards one or more preferences of a network attacker. The method includes modeling preferences of the network attacker based on monitored interactions between the network attacker and the pool of network decoys to generate a preference model of the network attacker. Each epoch includes updating a fitness function based on the preference model and applying the fitness function to each network decoy included in the pool of network decoys to determine a plurality of fitness values, where the fitness values are representative of an attractiveness of a respective network decoy to the network attacker. The pool of network decoys is then updated based on the fitness values.