Decoy Network Environment for Intrusion Counter-Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems fail to gather actionable information from malicious users as they are typically blocked once identified, preventing the collection of their access patterns and signatures, which are essential for quick identification in future attacks.

Innovation Solution

Implementing a decoy network environment where identified malicious users can continue to access network services, allowing data collection on their access requests and responses to generate malicious user analytics, thereby refining their signatures for faster recognition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malicious users are blocked after identification, then network security is improved, but actionable information about attack patterns and signatures cannot be gathered

Engineering Contradiction:
Improvenetwork securityVSAvoidattack patterns and signatures
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The network environment is segmented into a real network portion and a decoy network environment portion. Malicious users are redirected to the decoy portion where their attack patterns can be observed without affecting the real network, thus maintaining security while gathering intelligence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A decoy network environment acts as an intermediary between the malicious user and the real network. This intermediary allows the system to study attack behaviors indirectly without exposing the actual network resources, resolving the contradiction between blocking users and gathering information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If malicious users are blocked immediately, then network resources are protected, but the opportunity to collect data for future identification is lost

Engineering Contradiction:
Improvenetwork resource protectionVSAvoidtime for signature collection
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The decoy network environment is prepared in advance with monitoring capabilities. When malicious users are redirected there, their behaviors are automatically tracked and analyzed, allowing signature collection to occur preliminarily before they can evolve their attack methods or return to the real network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous monitoring and data collection activities within the decoy environment. This continuous observation ensures that attack patterns and signatures are gathered over time without interruption, eliminating the time loss that would occur with immediate blocking.

Inventive Principle:
Principle #20Continuity of useful action

3Loss of information

If a decoy network environment is implemented, then actionable intelligence can be gathered, but system complexity increases

Engineering Contradiction:
Improvecounter-intelligence gatheringVSAvoidnetwork environment structure
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The decoy network environment is created as a simplified copy or representation of the real network environment. It replicates essential structures and services needed to attract and observe malicious users, but omits critical real network resources, thus reducing complexity while maintaining intelligence-gathering capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The decoy environment uses lightweight, easily deployable components that can be quickly set up and discarded. These disposable-like elements reduce the long-term complexity burden, as the decoy infrastructure doesn't need to be as robust or permanent as the real network environment.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11750653B2Network intrusion counter-intelligence
Publication Date: 2023.09.05 CISCO TECHNOLOGY INC
  • US11750653B2 patent drawing
  • US11750653B2 patent drawing
  • US11750653B2 patent drawing

AI summary

Systems, methods, and computer-readable media for gathering network intrusion counter-intelligence. A system can maintain a decoy network environment at one or more machines. The system can identify a malicious user accessing network services through the network environment. Further, the system can receive network service access requests from the user at one or more machines in the network environment and subsequently direct the network service access requests from the malicious user to the decoy network environment based on an identification of the malicious user. The network services access requests can be satisfied with network service access responses generated in the decoy network environment. Subsequently, the system can maintain malicious user analytics based on the network service access requests of the malicious user that are directed to the decoy network environment.