Custom Deception Entities for Network Endpoint Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems face challenges in deploying effective decoys that appear authentic to attackers, limiting the ability to customize deceptions and making it difficult to defend against targeted attacks, particularly in mimicking real network resources.

Innovation Solution

A system and method for generating and deploying custom deceptions using a formal language, allowing administrators to define and install deception entities with specific parameters on network endpoints, including type, conditions, and deception type, through an API and translator for real-time installation and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security systems deploy standard decoys, then deployment is simple, but the decoys cannot effectively mimic real network resources and fail to detect targeted attacks

Engineering Contradiction:
Improvedecoy authenticityVSAvoiddeception system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates virtual copies of real network resources by capturing their characteristics (files, registry keys, processes) and replicating them as deceptive entities. These copies mimic the appearance and behavior of legitimate resources to trick attackers into interacting with them instead of real targets.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system dynamically changes parameters of decoy entities based on the real network environment. It monitors actual resources and adjusts the characteristics of virtual decoys (such as file paths, registry keys, process names) to match current system states, ensuring ongoing authenticity and effectiveness.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If administrators use pre-defined deception templates, then deployment is easier, but customization to match specific network environments is limited

Engineering Contradiction:
Improvedeception customizationVSAvoiddeployment ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The system automatically discovers real network resources and generates appropriate decoys without requiring manual configuration. It self-configures by monitoring the network environment, identifying legitimate files, registry keys, and processes, and creating matching deceptive versions autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The deception entities are dynamic and can be created, modified, or removed based on real-time network conditions. The system continuously adapts the deception environment to match changes in the real network, ensuring that decoys remain relevant and effective as the network evolves.

Inventive Principle:
Principle #15Dynamics

3Reliability

If comprehensive deception entities are deployed to cover all possible attack vectors, then detection capability improves, but system complexity and resource consumption increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of uniformly deploying comprehensive decoys across the entire network, the system applies deception selectively to specific high-value targets and critical resources. It identifies which files, registry keys, and processes are most important to protect and creates decoys only for those specific locations, optimizing resource usage while maintaining effective detection.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10382483B1User-customized deceptions and their deployment in networks
Publication Date: 2019.08.13 PROOFPOINT ISRAEL HOLDINGS LTD
  • US10382483B1 patent drawing
  • US10382483B1 patent drawing
  • US10382483B1 patent drawing

AI summary

A system for generating and deploying custom deceptions for a network, including an administrator computer for generating custom deception entities (CDEs), each CDE including parameters including inter alia (i) a type of entity, (ii) conditions for deployment of the CDE, and (iii) a deception type, and a management server, comprising an application programming interface for use by the administrator computer to generate CDEs through the medium of a formal language for specifying deceptions, and a translator for translating formal language CDEs to deceptions that are installable in network endpoint computers, wherein the management computer receives a request from a network endpoint computer to retrieve CDEs, selects CDEs that are relevant to the requesting network endpoint computer based on the parameters of the CDE, translates the requested CDEs to installable deceptions, and transmits the installable deceptions to the network endpoint computer for installation thereon.