Deception Profiler Optimizes Network Security Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network deception mechanisms are costly and inefficient due to the difficulty in determining the optimal location, number, configuration, and deployment schedule for deception mechanisms, leading to either ineffective attacker diversion or excessive resource expenditure.

Innovation Solution

A method for intelligently deploying deception mechanisms using a deception profiler that assesses asset densities, historical attack statistics, and machine information to determine the appropriate number, configuration, and schedule for deception mechanisms within a network, allowing for targeted and dynamic deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deception mechanisms are deployed to divert attackers from real assets, then network security effectiveness is improved, but deployment and maintenance costs increase

Engineering Contradiction:
Improvenetwork security effectivenessVSAvoiddeployment and maintenance cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system dynamically adjusts the number and placement of deception mechanisms based on real-time asset density calculations and historical attack patterns. The deception profiler continuously learns from new attacks and modifies deployment strategies, transforming static deception mechanisms into adaptive security assets that optimize their presence based on network conditions and threat levels.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes key parameters including asset density thresholds, deception mechanism counts, and deployment locations based on computed importance scores. By adjusting these parameters dynamically rather than using fixed configurations, the system achieves better security coverage while reducing unnecessary deployment costs in low-risk areas.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If more deception mechanisms are deployed to improve attacker diversion, then security coverage is improved, but resource expenditure increases

Engineering Contradiction:
Improveattacker diversion effectivenessVSAvoidnumber of deception mechanisms
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system applies different densities of deception mechanisms to different network segments based on local asset density and importance scores. High-value areas with critical assets receive higher concentrations of deception mechanisms, while low-value areas receive fewer or no mechanisms, optimizing the overall distribution rather than using a uniform approach across the entire network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system determines the optimal number of deception mechanisms by analyzing historical attack data and asset criticality, deploying enough mechanisms to effectively divert attackers from critical assets without over-deploying in areas where additional mechanisms would provide diminishing returns. This partial action approach avoids the waste of excessive deployment while maintaining adequate coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If deception mechanisms are deployed in all network locations to maximize protection, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the network into different zones based on asset density and criticality, applying different deception mechanism deployment strategies to each segment. This segmentation approach simplifies the overall deployment by breaking down the complex problem of network-wide protection into manageable regional decisions, each optimized based on local characteristics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The deception profiler performs preliminary analysis of network assets, historical attacks, and threat patterns before deployment decisions are made. By pre-computing asset densities, importance scores, and optimal deployment configurations, the system simplifies the actual deployment process and reduces on-the-fly complexity during implementation.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If deception mechanisms are continuously monitored and adjusted to maintain effectiveness, then security effectiveness is improved, but monitoring and maintenance costs increase

Engineering Contradiction:
Improvedeception mechanism effectivenessVSAvoidmonitoring and maintenance cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system implements continuous feedback loops where the deception profiler monitors new attacks, learns from attack patterns, and automatically adjusts deception mechanism deployment accordingly. This automated feedback mechanism maintains effectiveness without requiring proportional increases in human monitoring and maintenance resources, as the system self-optimizes based on incoming data.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The deception profiler performs self-learning and self-adjustment by analyzing attack data and automatically modifying deployment strategies. This self-service capability reduces the need for external monitoring and manual maintenance, lowering operational costs while maintaining or improving effectiveness over time.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9853999B2Context-aware knowledge system and methods for deploying deception mechanisms
Publication Date: 2017.12.26 ACALVIO TECH
  • US9853999B2 patent drawing
  • US9853999B2 patent drawing
  • US9853999B2 patent drawing

AI summary

Methods, systems, and computer-readable mediums are described herein to provide context-aware knowledge systems and methods for deploying deception mechanisms. In some examples, a deception profiler can be used to intelligently deploy the deception mechanisms for a network. For example, a method can include identifying a network for which to deploy one or more deception mechanisms. In such an example, a deception mechanism can emulate one or more characteristics of a machine on the network. The method can further include determining one or more asset densities and a summary statistic. An asset density can be associated with a number of assets connected to the network. The summary statistic can be associated with a number of historical attacks on the network. Using at least one or more of the one or more asset densities, the summary statistic, other information associated with the network, or a combination thereof, the method can further include determining a number of deception mechanisms to deploy, and deploying the number of deception mechanisms.