Decoy Network Device for Scan Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identifying unexpected network scans is challenging due to the vast number of packets in flight, making it difficult to distinguish between routine and systematic network traffic, and existing methods require significant processing resources or may introduce delays.
Innovation Solution
Implementing a deception-based security system where a network device is configured as a decoy to monitor network activity, using unassigned network addresses to detect scan patterns and generate response packets, thereby facilitating the identification of scans and configuration of security settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network scanning detection methods are used, then network security monitoring can be performed, but significant processing resources are required and detection delays occur
Solution Approach 1:
The patent creates a virtual copy of a legitimate network device (the decoy) that replicates its network address, services, and operational characteristics. This copy is deployed alongside the real device to attract and capture scan traffic. By copying the device's network footprint, the system can detect scans without processing every packet through complex analysis, thus improving detection reliability while reducing processing requirements.
Solution Approach 2:
The decoy device serves as an intermediary between the network scanner and the legitimate device. Instead of the security system directly analyzing all network traffic, the decoy intercepts scan packets and transfers this information to the security system. This intermediary approach allows the security system to focus only on packets directed at the decoy, significantly reducing processing resources needed while maintaining detection accuracy.
2Measurement precision
If comprehensive network traffic monitoring is implemented, then scan detection accuracy improves, but processing time increases
Solution Approach 1:
The decoy device is configured with specific local characteristics that match the legitimate device's network address, services, and operational profile. By localizing these qualities to the decoy, the system creates a targeted detection mechanism that only processes packets relevant to the decoy's specific configuration. This localized approach maintains high measurement precision for scan detection while reducing overall processing time by ignoring unrelated traffic.
3Adaptability or versatility
If network scanning tools are made accessible to administrators, then legitimate network assessment and maintenance improve, but the same tools can be used by network threats
Solution Approach 1:
The system converts the harmful effect of network scanning into a beneficial detection mechanism. The decoy device is intentionally designed to be attractive to scanners, using legitimate network protocols and services to lure scan traffic. By converting the scanner's systematic probing into a useful detection signal, the system enables administrators to detect malicious scans without restricting legitimate administrative scanning activities.
Solution Approach 2:
Instead of trying to block or prevent network scanning, the system inverts the approach by creating a decoy that actively invites scanning. The decoy's network presence is designed to be indistinguishable from legitimate devices to scanners, reversing the traditional security paradigm of hiding or blocking. This inversion allows the system to detect scans by observing the decoy's interactions with scanners, maintaining adaptability for legitimate administration while countering malicious activity.
Data Source
AI summary
Provided are systems, methods, and computer-program products for using deceptions to detect network scans. In various implementations, a network device, configured as a decoy network device can be configured to determine a particular network address. The network device can determine that the particular network address is unassigned. The network device can configure itself with the particular network address, wherein the network device uses the particular network address to monitor network activity for a network scan. The network device can receive a packet addressed to the particular network address. The network device can determine that received packet is associated with a scan of the network, including associating the received packet with other packets in the monitored network activity. The network device can configure one or more security settings for the network when the received packet is determined to be associated with a scan of the network.


