Bait Information Generation for Trap-Based Network Defenses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current preventive defense mechanisms, such as firewalls and signature-based detection, are insufficient in detecting and preventing malware infiltration, especially as malware evolves to evade detection and can cause significant damage if left undetected.

Innovation Solution

The development of systems and methods for generating bait information to create trap-based defenses, which involve recording historical network information, translating it, and tailoring it to create decoy data that attracts and deceives malware, thereby detecting and deceiving infiltrated malware within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If preventive defense mechanisms (firewalls, packet filters, signature-based detection) are used, then network security is maintained, but malware can still infiltrate and cause damage when detection fails

Engineering Contradiction:
Improvenetwork securityVSAvoidmalware infiltration and damage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by recording historical network information and translating it into bait information before malware infiltration occurs. This bait information is then deployed in the network to proactively attract and detect malware, shifting from reactive prevention to proactive detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the harmful behavior of malware (its tendency to seek vulnerabilities and exploit networks) into a benefit by using bait information that attracts malware to predetermined traps. The malware's invasive nature is transformed into a detection mechanism, where its attempts to exploit the system reveal its presence.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Difficulty of detecting and measuring

If filtering-based prevention mechanisms are used, then some malware is blocked, but sophisticated malware can evade detection through various delivery methods

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidmalware evasion capability
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

Instead of trying to detect malware by analyzing its characteristics (traditional approach), the system inverts the approach by having malware identify itself through its reactions to bait information. The detection paradigm is flipped from passive analysis to active provocation, where the system deliberately presents targets and observes malware responses.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system introduces bait information as an intermediary element between the defense mechanism and malware. This bait acts as a mediator that attracts malware and facilitates detection without requiring direct confrontation or analysis of malware's inherent characteristics, thereby overcoming evasion techniques.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If traditional preventive defenses are deployed, then network protection is provided, but significant damage occurs when prevention fails and malware remains undetected

Engineering Contradiction:
Improvetime to detect malwareVSAvoiddamage from undetected malware
Core Design Contradiction:
Loss of timeVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary detection actions by deploying bait information throughout the network before significant damage can occur. This allows for early detection of malware infiltration, reducing the time window during which malware can operate undetected and minimize damage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback mechanism where bait information deployment triggers observable responses from malware. When malware interacts with the bait, the system receives feedback signals that immediately alert defenders to the presence and location of malware, enabling rapid response and damage containment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9356957B2Systems, methods, and media for generating bait information for trap-based defenses
Publication Date: 2016.05.31 THE TRUSTEES OF COLUMBIA UNIV IN THE CITY OF NEW YORK
  • US9356957B2 patent drawing
  • US9356957B2 patent drawing
  • US9356957B2 patent drawing

AI summary

Systems, methods, and media for generating bait information for trap-based defenses are provided. In some embodiments, methods for generating bait information for trap-based defenses include: recording historical information of a network; translating the historical information; and generating bait information by tailoring the translated historical information.