Deception Services in Segmented Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network segmentation policies struggle to detect and mitigate malicious activities effectively, as malicious actors can exploit vulnerabilities before being detected.

Innovation Solution

A system and method that employs a policy management server to distribute segmentation and deception rules to enforcement modules, allowing communications while implementing deception services to detect and remediate malicious behavior by mimicking real services, thereby increasing the likelihood of detecting malicious actors before a successful attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If segmentation rules are enforced to control network communications, then network security is improved, but malicious actors can still exploit vulnerabilities before detection

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent deploys deception services in advance across the network segment before any attack occurs. These deception services create fake service instances that are positioned to intercept potential attack traffic, enabling detection to happen earlier in the attack lifecycle rather than waiting for actual exploitation attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The deception service acts as an intermediary between the segmentation firewall and the actual services. It intercepts traffic that would otherwise reach real services, allowing the system to detect and analyze malicious behavior patterns before they can compromise actual resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If deception services are deployed to detect malicious behavior, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The deception detection system is divided into independent deception service instances distributed across different network segments. Each deception service operates autonomously within its segment, monitoring for malicious behavior locally. This segmentation allows the complex detection functionality to be distributed and managed in manageable units rather than a monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The deception service is designed to provide multiple functions: it mimics real services to attract attackers, monitors traffic for malicious behavior, and reports findings to the segmentation firewall. This multi-functionality reduces overall system complexity by consolidating detection, deception, and reporting capabilities into a single service component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If deception services mimic real services, then attacker detection is improved, but it becomes difficult to distinguish between real and deceptive services

Engineering Contradiction:
Improveattacker detection accuracyVSAvoidservice authentication difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent converts the attacker's inability to distinguish real from fake services into a benefit. By making deception services indistinguishable from real ones, the system ensures that any connection attempt is likely to be malicious, and thus all such attempts are monitored and analyzed for attack patterns, turning the ambiguity into a detection advantage.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

Different quality characteristics are applied to different service instances based on their function. Deception services use identical characteristics to real services at the network protocol level to maintain indistinguishability, but differ in their monitoring and reporting behavior. This local differentiation allows the system to maintain detection accuracy while preserving operational security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11356483B2Protecting network-based services using deception in a segmented network environment
Publication Date: 2022.06.07 ILLUMIO INC
  • US11356483B2 patent drawing
  • US11356483B2 patent drawing
  • US11356483B2 patent drawing

AI summary

A policy management server manages a segmentation policy for segmenting a network and a deception policy for implementing deception services. The policy management server distributes segmentation rules and deception rules to distributed enforcement modules that configure respective traffic filters to enforce the policies. The deception rule may be enforced directly by the traffic filter acting as a deception service, or the traffic filter may act as a proxy to an external deception service. The deception service can behave similarly to a real service to obtain information about the malicious actor that is reported to the policy management server to enable the policy management server to take a remedial action. Furthermore, the policy management server may automatically generate the deception policy based on the segmentation policy such that connection requests that are not allowed by the segmentation policy are automatically sent to a deception service.