Deception Management Server for Containerized Cluster Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions are inadequate in protecting containerized clusters from attackers who exploit human errors and lateral movement within these complex environments, often resulting in false alerts and inability to mitigate threats effectively.
Innovation Solution
A system and method that includes a deception management server learning the network environment, creating deceptions such as fake attack vectors and credentials, and planting them via a container orchestrator to trap attackers, while issuing alerts and hindering their progress towards critical assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional network security solutions are used to monitor containerized clusters, then attackers can be detected, but false alerts are generated and threats cannot be mitigated effectively
Solution Approach 1:
The system performs preliminary actions by deploying deceptive entities (honeypots, fake credentials,虚假配置 files) into the containerized cluster environment before actual attacks occur. These deceptions are pre-positioned to intercept and detect attacker activities, allowing the system to identify threats before they can compromise real assets, thereby reducing false alerts and improving detection reliability
Solution Approach 2:
The patent introduces deceptive entities as intermediary elements between attackers and critical assets. These intermediaries (fake service accounts,虚假container instances, decoy configuration files) serve as mediators that attract and capture attacker attention, allowing security monitoring to occur without exposing actual sensitive resources, thus improving both detection accuracy and threat mitigation effectiveness
2Measurement precision
If deceptive entities are deployed to trap attackers, then detection accuracy improves, but system complexity increases
Solution Approach 1:
The patent implements a universal deception management system that can deploy multiple types of deceptive entities (honeypots, fake credentials,虚假配置 files, decoy container instances) through a single integrated platform. This multi-functional system manages diverse deception types using common protocols and interfaces, reducing operational complexity while maintaining high detection accuracy across various attack vectors
Solution Approach 2:
The system creates simplified copies of legitimate system entities (service accounts, configuration files, container instances) as deceptive elements. These copies replicate the appearance and behavior of real assets but contain no sensitive data, making them easy to deploy and manage while effectively attracting attackers. The copying approach reduces complexity by using standardized templates rather than custom deception designs
3Productivity
If comprehensive monitoring is implemented in containerized environments, then more threats are detected, but false positives increase
Solution Approach 1:
By pre-deploying deceptive entities throughout the containerized environment, the system establishes known detection points that generate high-confidence alerts when accessed. This preliminary positioning allows comprehensive monitoring coverage without the false positives associated with monitoring legitimate system variations, as deceptive entities are designed to be uniquely identifiable and their access patterns are unambiguously indicative of malicious activity
Data Source
AI summary
A method for operation of a deception management server, for detecting and hindering attackers who target containerized clusters of a network, including learning the network environment, including finding existing container instances, finding existing services and relationships, extracting naming conventions in the environment, and classifying the most important assets in the environment, creating deceptions based on the learning phase, the deceptions including one or more of (i) secrets, (ii) environment variables pointing to deceptive databases, web servers or active directories, (iii) mounts, (iv) additional container instances comprising one or more of file server, database, web applications and SSH, (v) URLs to external services, and (vi) namespaces to fictional environments, planting the created deceptions via a container orchestrator, via an SSH directly to the containers, or via the container registry, and issuing an alert when an attacker attempts to connect to a deceptive entity.


