Deception Management Server for Containerized Cluster Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions are inadequate in protecting containerized clusters from attackers who exploit human errors and lateral movement within these complex environments, often resulting in false alerts and inability to mitigate threats effectively.

Innovation Solution

A system and method that includes a deception management server learning the network environment, creating deceptions such as fake attack vectors and credentials, and planting them via a container orchestrator to trap attackers, while issuing alerts and hindering their progress towards critical assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional network security solutions are used to monitor containerized clusters, then attackers can be detected, but false alerts are generated and threats cannot be mitigated effectively

Engineering Contradiction:
Improveattack detection accuracyVSAvoidthreat mitigation effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by deploying deceptive entities (honeypots, fake credentials,虚假配置 files) into the containerized cluster environment before actual attacks occur. These deceptions are pre-positioned to intercept and detect attacker activities, allowing the system to identify threats before they can compromise real assets, thereby reducing false alerts and improving detection reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces deceptive entities as intermediary elements between attackers and critical assets. These intermediaries (fake service accounts,虚假container instances, decoy configuration files) serve as mediators that attract and capture attacker attention, allowing security monitoring to occur without exposing actual sensitive resources, thus improving both detection accuracy and threat mitigation effectiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If deceptive entities are deployed to trap attackers, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal deception management system that can deploy multiple types of deceptive entities (honeypots, fake credentials,虚假配置 files, decoy container instances) through a single integrated platform. This multi-functional system manages diverse deception types using common protocols and interfaces, reducing operational complexity while maintaining high detection accuracy across various attack vectors

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates simplified copies of legitimate system entities (service accounts, configuration files, container instances) as deceptive elements. These copies replicate the appearance and behavior of real assets but contain no sensitive data, making them easy to deploy and manage while effectively attracting attackers. The copying approach reduces complexity by using standardized templates rather than custom deception designs

Inventive Principle:
Principle #26Copying

3Productivity

If comprehensive monitoring is implemented in containerized environments, then more threats are detected, but false positives increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidalert accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

By pre-deploying deceptive entities throughout the containerized environment, the system establishes known detection points that generate high-confidence alerts when accessed. This preliminary positioning allows comprehensive monitoring coverage without the false positives associated with monitoring legitimate system variations, as deceptive entities are designed to be uniquely identifiable and their access patterns are unambiguously indicative of malicious activity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10382484B2Detecting attackers who target containerized clusters
Publication Date: 2019.08.13 PROOFPOINT ISRAEL HOLDINGS LTD
  • US10382484B2 patent drawing
  • US10382484B2 patent drawing
  • US10382484B2 patent drawing

AI summary

A method for operation of a deception management server, for detecting and hindering attackers who target containerized clusters of a network, including learning the network environment, including finding existing container instances, finding existing services and relationships, extracting naming conventions in the environment, and classifying the most important assets in the environment, creating deceptions based on the learning phase, the deceptions including one or more of (i) secrets, (ii) environment variables pointing to deceptive databases, web servers or active directories, (iii) mounts, (iv) additional container instances comprising one or more of file server, database, web applications and SSH, (v) URLs to external services, and (vi) namespaces to fictional environments, planting the created deceptions via a container orchestrator, via an SSH directly to the containers, or via the container registry, and issuing an alert when an attacker attempts to connect to a deceptive entity.