Deception Server Deployment in Multi-Tiered Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting and counteracting malicious attacks on multi-tiered resources within a system is challenging due to the difficulty in determining the optimal deployment of deception servers without understanding the system's topology, which can change over time, leading to ineffective defense mechanisms.

Innovation Solution

A deception server automation engine that accesses and analyzes topology information from a configuration management database to dynamically select and deploy deception servers at appropriate layers of a multi-tiered resource, monitoring interactions and generating alerts to detect and respond to attacks in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If deception servers are deployed without understanding system topology, then deployment is simpler and faster, but detection effectiveness deteriorates

Engineering Contradiction:
Improvedeployment speedVSAvoiddetection effectiveness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by automatically discovering and analyzing the system topology before deploying deception servers. The topology discovery engine maps the network structure, identifies multi-tiered resources, and determines optimal deployment locations in advance, ensuring both simplicity and effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring interactions with deception servers and using this information to detect attacks. The deception server deployment engine receives feedback about attack patterns and uses it to dynamically adjust deployment strategies, improving detection effectiveness while maintaining operational simplicity.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If deception servers are statically deployed, then deployment is easier to manage, but adaptability to topology changes deteriorates

Engineering Contradiction:
Improvemanagement simplicityVSAvoidresponse to topology changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system transitions from static to dynamic deployment by implementing continuous topology discovery and automatic redeployment capabilities. When topology changes are detected through monitoring, the deception server deployment engine automatically adjusts server locations and configurations, maintaining both ease of operation and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs self-service mechanisms where the topology discovery engine autonomously monitors network changes and triggers redeployment of deception servers without human intervention. This maintains management simplicity while ensuring the system adapts to topology changes automatically.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If manual topology analysis is performed, then deployment accuracy is higher, but time consumption increases

Engineering Contradiction:
Improvedeployment accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces manual mechanical analysis with automated computational methods. The topology discovery engine uses software-based network mapping, graph theory algorithms, and automated resource identification to achieve high deployment accuracy without manual intervention, eliminating time consumption while maintaining precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces an intermediary topology discovery engine that acts as a mediator between the deception server deployment engine and the complex network infrastructure. This intermediary automatically gathers topology information, processes it through analysis algorithms, and provides accurate deployment recommendations, achieving high precision without manual analysis time.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11374971B2Deception server deployment
Publication Date: 2022.06.28 MICRO FOCUS LLC
  • US11374971B2 patent drawing
  • US11374971B2 patent drawing
  • US11374971B2 patent drawing

AI summary

A system accesses information regarding a topology of an arrangement of resources, where one of the resources is a multi-tiered resource having a plurality of layers. Based on the information regarding the topology of the arrangement of resources, the system selects one or more layers of the multi-tiered resource for deployment of a deception server that has a reduced security mechanism to act as a decoy to attract attackers of the system. The system deploys the deception server at the selected one or more layers of the multi-tiered resource.