Optimizing Cyber Deception via Attack Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for using deception technology in electronic communication networks lack a systematic approach for selecting and placing decoys and lures effectively, making it difficult to detect and localize cyber attacks.

Innovation Solution

The method involves determining an attack vector, creating an attack graph, selecting and distributing decoys and lures based on the attack graph's structure, and evaluating the change in attack paths to optimize the placement of decoys and lures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decoys and lures are distributed in the communication network to detect attackers, then attack detection capability is improved, but the systematic approach for selecting and placing decoys and lures is lacking

Engineering Contradiction:
Improveattack detection capabilityVSAvoidselection and placement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates an attack graph before deploying decoys and lures, which models potential attack paths in advance. This preliminary analysis allows the system to identify optimal placement locations for decoys and lures before the actual attack occurs, enabling proactive rather than reactive security measures. The attack graph serves as a pre-computed roadmap that guides the systematic distribution of deception elements throughout the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates simplified representations (attack graphs) that copy and model the complex network structure and attack pathways. Instead of directly analyzing the entire complex network, the system works with a simplified graph model that captures essential attack relationships. This copying approach enables systematic analysis and optimization of decoy placement without dealing with the full complexity of the actual network infrastructure.

Inventive Principle:
Principle #26Copying

2Reliability

If more decoys and lures are deployed to increase detection coverage, then attack path coverage is improved, but the complexity of evaluating different deployment variants increases

Engineering Contradiction:
Improveattack path coverageVSAvoidevaluation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs an optimization algorithm that uses feedback from the attack graph analysis to iteratively improve decoy and lure placement. The system evaluates different deployment variants by analyzing how they affect attack paths in the attack graph, and uses this feedback to refine the placement strategy. This feedback loop enables systematic comparison of different deployment scenarios without requiring manual evaluation of each variant.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent transforms the security deployment problem into an optimization problem by changing the parameters being optimized - specifically, the placement locations and types of decoys and lures. By formulating objective functions that quantify detection effectiveness and coverage, the system can systematically compare different parameter configurations (deployment variants) and select the optimal set of parameters that maximizes attack path coverage while minimizing evaluation complexity.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If decoys are placed closer to attack points, then early detection is improved, but the precision of placement requires higher measurement precision

Engineering Contradiction:
Improvedetection timeVSAvoidplacement precision
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The patent performs preliminary analysis of the attack graph to identify optimal placement locations that are strategically close to potential attack points. By pre-computing the attack graph and analyzing attack pathways in advance, the system can identify specific nodes or edges where placing decoys will maximize early detection probability. This preliminary positioning ensures that decoys are placed optimally close to attack points without requiring trial-and-error adjustments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual or heuristic-based placement methods with a systematic optimization approach. Instead of relying on intuitive or mechanical placement strategies, the system uses computational optimization algorithms that automatically determine precise placement locations based on the attack graph structure. This substitution of mechanical/placement methods with computational optimization enables high precision in decoy positioning while reducing the complexity of achieving such precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4060938B1Method for improving security in an electronic communication network
Publication Date: 2025.05.07 CYBERSENSE GMBH
  • EP4060938B1 patent drawingFigure 1
  • EP4060938B1 patent drawingFigure 2
  • EP4060938B1 patent drawingFigure 3

AI summary

The invention relates to a method for improving security in an electronic communication network, in which lures and decoys are distributed within the communication network. The object of the invention is to provide a systematic approach for selecting and placing lures and decoys, thereby distributing them within the communication network in the most optimal way possible.The invention proposes that an attack vector on the communication network is determined, an attack graph (1) is created based on the attack vector, which maps possible attack paths as an acyclic, directed graph, the type and number of lures and decoys are determined based on the structure of the attack graph, and the lures and decoys are distributed in the communication network using an objective function, wherein the objective function takes into account specifications which determine the earliest and most probable detection of an attacker (4) using the available lures and decoys and enable an evaluation of the distribution.