Deceptive Network Emulation for Wireless Attack Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional decoy systems lack the capability to fully characterize attackers and attacks, particularly in wireless network security, where existing protection protocols like WEP, WPA, and WPA2 are easily breached by sophisticated hacking tools, and there is a need for more accurate identification and prevention of cyber threats.

Innovation Solution

A system and method utilizing deceptive network emulation with a Wireless Risk Audit Tool (WRAT) and Data Capture and Forensic Reporting (DFR) to lure attackers into a simulated network, perform deep packet inspection, and generate attack signatures for comprehensive defense and response strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional decoy systems are used to identify attackers, then attacker identification capability is improved, but the ability to fully characterize attack modalities and generate comprehensive defense strategies is insufficient

Engineering Contradiction:
Improveattacker identification accuracyVSAvoidattack characterization capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a deceptive network that copies the structure, services, and appearance of the real network. This replica network includes fake access points, emulated services, and simulated vulnerabilities that mirror the actual network environment, allowing attackers to interact with a realistic target while enabling comprehensive analysis of their techniques without compromising the real system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary characterization of the network environment by deploying the deceptive network before actual attacks occur. This advance preparation includes pre-configuring trap services, establishing baseline behavior patterns, and setting up monitoring mechanisms that enable immediate and accurate analysis when attackers engage with the system.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If wireless encryption protocols like WEP, WPA, and WPA2 are implemented to protect wireless networks, then basic security protection is improved, but these protocols are easily breached by sophisticated hacking tools

Engineering Contradiction:
Improvewireless security protectionVSAvoidvulnerability to sophisticated attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The deceptive network acts as an intermediary between attackers and the real network. It intercepts and analyzes attack traffic before it can reach the actual protected systems, allowing security personnel to study attack methods involving sophisticated tools while blocking the attacks from compromising the real encrypted network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system converts harmful attack attempts into beneficial security intelligence by capturing, analyzing, and characterizing attack patterns. Attacks that would normally compromise the network are instead transformed into valuable data for developing defense strategies, signature databases, and improved security measures against similar threats.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Measurement precision

If a deceptive network emulates the actual network with realistic components, then attacker identification and tracking accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveattacker tracking accuracyVSAvoiddeceptive network structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The deceptive network is segmented into modular components including separate fake access points, emulated services, trap systems, and analysis modules. Each component performs a specific function and can be independently configured, deployed, and maintained, reducing overall system complexity while maintaining high fidelity in attacker tracking capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3433749B1Identifying and trapping wireless based attacks on networks using deceptive network emulation
Publication Date: 2020.11.04 802 SECURE INC
  • EP3433749B1 patent drawingFigure 1
  • EP3433749B1 patent drawingFigure 2
  • EP3433749B1 patent drawingFigure 3~4

AI summary

A system and method are provided that enable identifying and trapping cyber security attacks via wireless connectivity on enterprise and corporate networks. A deceptive network emulation of a specific customer network is used to invite and draw in possible attackers. The attacker is also enticed to initiate attack on the emulated deceptive network. Packet header inspection and deep packet evaluation of the attack are used for generating possible signatures of the attacker and the attack. The information from deep packet inspection combined with the understanding of attack modality derived from enablement of attack on the deceptive network are used to generate detailed defensive methodologies, response capabilities and attack signatures, so that various types of cyber attacks including zero-day attacks from the attacker can be identified, prevented or addressed and responded to.