Deception Services in Segmented Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network segmentation policies struggle to detect and mitigate malicious activities effectively, as malicious actors can exploit vulnerabilities before being detected.
Innovation Solution
A system and method that employs a policy management server to distribute segmentation and deception rules to enforcement modules, allowing communications while implementing deception services to detect and remediate malicious behavior by mimicking real services, thereby increasing the likelihood of detecting malicious actors before a successful attack.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If segmentation rules are enforced to control network communications, then network security is improved, but malicious actors can still exploit vulnerabilities before detection
Solution Approach 1:
The patent deploys deception services in advance across the network segment before any attack occurs. These deception services create fake service instances that are positioned to intercept potential attack traffic, enabling detection to happen earlier in the attack lifecycle rather than waiting for actual exploitation attempts.
Solution Approach 2:
The deception service acts as an intermediary between the segmentation firewall and the actual services. It intercepts traffic that would otherwise reach real services, allowing the system to detect and analyze malicious behavior patterns before they can compromise actual resources.
2Measurement precision
If deception services are deployed to detect malicious behavior, then detection capability is improved, but system complexity increases
Solution Approach 1:
The deception detection system is divided into independent deception service instances distributed across different network segments. Each deception service operates autonomously within its segment, monitoring for malicious behavior locally. This segmentation allows the complex detection functionality to be distributed and managed in manageable units rather than a monolithic system.
Solution Approach 2:
The deception service is designed to provide multiple functions: it mimics real services to attract attackers, monitors traffic for malicious behavior, and reports findings to the segmentation firewall. This multi-functionality reduces overall system complexity by consolidating detection, deception, and reporting capabilities into a single service component.
3Measurement precision
If deception services mimic real services, then attacker detection is improved, but it becomes difficult to distinguish between real and deceptive services
Solution Approach 1:
The patent converts the attacker's inability to distinguish real from fake services into a benefit. By making deception services indistinguishable from real ones, the system ensures that any connection attempt is likely to be malicious, and thus all such attempts are monitored and analyzed for attack patterns, turning the ambiguity into a detection advantage.
Solution Approach 2:
Different quality characteristics are applied to different service instances based on their function. Deception services use identical characteristics to real services at the network protocol level to maintain indistinguishability, but differ in their monitoring and reporting behavior. This local differentiation allows the system to maintain detection accuracy while preserving operational security.
Data Source
AI summary
A policy management server manages a segmentation policy for segmenting a network and a deception policy for implementing deception services. The policy management server distributes segmentation rules and deception rules to distributed enforcement modules that configure respective traffic filters to enforce the policies. The deception rule may be enforced directly by the traffic filter acting as a deception service, or the traffic filter may act as a proxy to an external deception service. The deception service can behave similarly to a real service to obtain information about the malicious actor that is reported to the policy management server to enable the policy management server to take a remedial action. Furthermore, the policy management server may automatically generate the deception policy based on the segmentation policy such that connection requests that are not allowed by the segmentation policy are automatically sent to a deception service.


