Automated Honeynet Provisioning for Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security technologies generate massive data to identify attacks, requiring time-consuming and labor-intensive analysis by system administrators, making it expensive and inefficient to monitor computing systems and networks for unauthorized activity.

Innovation Solution

The implementation of an automated honeynet network system that provisions, configures, and operates a scalable environment with honeypots, honeywalls, and honeycombs to capture and analyze unauthorized network traffic, enabling real-time data collection and visualization of potential security threats, and prioritizing alerts for swift action.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security technologies (firewall, intrusion detection systems) are used to monitor computing systems and networks, then security monitoring capability is provided, but massive amounts of data are generated requiring time-consuming and labor-intensive analysis by system administrators

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidtime for data analysis
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces honeypots as intermediary systems that attract and capture unauthorized network traffic before it reaches production systems. These honeypots generate targeted security data with higher relevance, reducing the volume of data requiring administrator analysis while maintaining reliable security monitoring capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts unauthorized traffic monitoring functionality into separate honeypot systems that are deliberately placed in the network. These extracted honeypots capture malicious activity independently, removing the burden of analyzing irrelevant traffic from conventional security systems and reducing administrator workload.

Inventive Principle:
Principle #2Taking out (Extraction)

2Quantity of substance

If conventional security technologies generate massive amounts of data to identify attacks, then comprehensive security data collection is achieved, but the data requires expensive and labor-intensive validation and interpretation by system administrators

Engineering Contradiction:
Improvesecurity data volumeVSAvoidease of data validation
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent applies local quality by making honeypots highly specialized systems designed specifically to attract and capture unauthorized traffic. Rather than having conventional security systems generate all data, the honeypots provide locally optimized data collection with higher quality and relevance, reducing the effort needed for validation and interpretation.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If manual analysis of security data is performed by system administrators, then attack identification and validation can be achieved, but the process becomes time-consuming and expensive

Engineering Contradiction:
Improveattack identification accuracyVSAvoidsecurity analysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The honeypots serve as intermediaries that pre-process and filter network traffic, capturing only unauthorized attempts. This intermediary function improves measurement precision by providing targeted attack data while increasing productivity by reducing the volume of data requiring administrator analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10560434B2Automated honeypot provisioning system
Publication Date: 2020.02.11 LEVEL 3 COMMUNICATIONS LLC
  • US10560434B2 patent drawing
  • US10560434B2 patent drawing
  • US10560434B2 patent drawing

AI summary

Systems and methods for automatically provisioning honeynets are disclosed. The honeynets continuously gather and capture unauthorized network traffic and/or other information being transmitted, processed, accessed, and/or executed within the honeynet network that is indicative of a network threat or attack by unauthorized users.