Decoy Network System for Zero-Day Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems are ineffective against zero-day attacks due to their static nature and inability to detect new or undefined threats, and honeynet configurations are often bypassed by sophisticated attackers.

Innovation Solution

A modular decoy network system with a front-end fully functional operating system that captures and analyzes attack data, generating real-time attack signatures for intrusion detection and prevention systems, allowing for dynamic updates to protect networks from emerging threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional IDS/IPS with static signatures are used, then known threats can be detected, but zero-day attacks cannot be detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static signature-based detection into dynamic behavior-based detection. The system continuously monitors and learns normal network behavior patterns, then dynamically adapts to detect deviations that indicate zero-day attacks. This allows the system to evolve its detection capabilities without relying on pre-defined signatures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-learning by automatically analyzing network traffic patterns and generating behavioral baselines without human intervention. It autonomously updates its detection models based on observed normal behavior, enabling continuous adaptation to new threat landscapes while maintaining reliable detection of both known and unknown attacks.

Inventive Principle:
Principle #25Self-service

2Loss of information

If honeynet arrangements are used to trap attackers, then attack data can be collected, but sophisticated attackers can detect and avoid honeynets

Engineering Contradiction:
Improveattack data collectionVSAvoidattacker detection capability
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts the detection functionality from visible honeypot infrastructure and embeds it within normal network devices. Instead of relying on separate honeynet systems that attackers can identify, the behavioral analysis capabilities are integrated into production network devices, making detection invisible to attackers while continuing to collect valuable attack data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces behavioral analysis as an intermediary layer between network traffic and security responses. Rather than relying on attackers interacting with visible honeypots, the behavioral mediator continuously analyzes all traffic patterns, enabling detection of sophisticated attacks without requiring attackers to be trapped in identifiable honeynet environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If behavioral signatures are used in IPS, then higher level protection is provided, but the signatures remain static and limited against zero-day attacks

Engineering Contradiction:
Improveprotection levelVSAvoidresponse to new attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static behavioral signatures into dynamic behavioral baselines that continuously adapt. Instead of using fixed rules for detecting anomalies, the system learns normal behavior patterns over time and dynamically adjusts its detection thresholds, enabling it to provide high-level protection while remaining adaptable to zero-day attacks that exhibit novel behavioral patterns.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9866584B2System and method for analyzing unauthorized intrusion into a computer network
Publication Date: 2018.01.09 GOSECURE INC
  • US9866584B2 patent drawing
  • US9866584B2 patent drawing
  • US9866584B2 patent drawing

AI summary

The method analyzes unauthorized intrusion into a computer network. Access is allowed to a virtualized operating system running on a hypervisor operating system hosted on a network device. A network attack is intercepted on the virtualized operating system using an introspection module with a virtual-machine-based rootkit module and its associated userland processes running on the hypervisor operating system. The network attack includes attack-identifying information. Forensic data is generated on the network attack from the attack-identifying information.