Deception Mechanism for Mixed Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Small networks, including those with Internet-of-Things devices, are vulnerable to threats due to inadequate security infrastructure and the use of diverse communication protocols, making them susceptible to intrusions both externally and internally.
Innovation Solution
A deception-based network security system that deploys deceptive mechanisms to attract and divert attacks, using a deception center and sensors to monitor and analyze network activity, and dynamically configure security mechanisms to emulate devices within the network, thereby deflecting threats away from critical assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional security infrastructure is used in mixed networks with diverse protocols, then network coverage is limited, but security effectiveness deteriorates due to inability to detect and respond to intrusions across multiple protocol types
Solution Approach 1:
The security device is designed to operate across multiple network protocols (TCP/IP, UDP, Zigbee, Z-Wave, LoRaWAN, NB-IoT, Wi-Fi, Bluetooth, Thread) simultaneously, making it universally applicable to diverse network types. The device can identify and respond to different protocol types, enabling a single security system to protect mixed networks without requiring protocol-specific security appliances for each network type.
2Reliability
If comprehensive security monitoring is implemented across all network devices, then security effectiveness improves, but device complexity increases due to the need to manage diverse protocols and device types
Solution Approach 1:
The security device autonomously identifies network device types and protocols, automatically configures appropriate security responses, and dynamically adjusts monitoring parameters without requiring manual intervention. The system self-adapts to new device types and protocols as they join the network, eliminating the need for complex manual configuration while maintaining comprehensive security coverage.
Solution Approach 2:
The security device dynamically adjusts its monitoring and response behaviors based on real-time detection of different protocol types and device characteristics. Instead of using fixed, complex configuration rules, the system adapts its security posture dynamically - enabling deep inspection for critical devices while using lighter-weight monitoring for less critical devices, thereby reducing overall system complexity while maintaining effectiveness.
3Difficulty of detecting and measuring
If deep inspection of network traffic is performed on all protocols, then intrusion detection capability improves, but processing time increases due to the need to analyze diverse protocol formats
Solution Approach 1:
The security device applies different inspection depths and analysis methods tailored to each specific protocol and device type. Critical devices or protocols with higher security risks receive deep inspection, while less critical components receive lighter monitoring. This localized quality approach ensures high intrusion detection capability where needed while minimizing processing time elsewhere, avoiding uniform deep inspection of all traffic.
Data Source
AI summary
Provided are methods, including computer-implemented methods or methods implemented by a network device, devices including network devices, and computer-program products for providing dynamic security mechanisms for mixed networks. A mixed network can include an IoT type device and a non-IoT device. Using a configuration of the network, a deception device type can be determined. A second network that includes a deception mechanism corresponding to the deception device type can be determined. A network tunnel from the mixed network to the second network can be configured. The network tunnel enables the deception mechanism to be a node on the mixed network, such that the deception mechanism can be accessed from the mixed network. The deception mechanism can be used to monitor the mixed network for network abnormalities. An action can be taken when the deception mechanism detects an abnormality.


