Decoy Network Device for Scan Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying unexpected network scans is challenging due to the vast number of packets in flight, making it difficult to distinguish between routine and systematic network traffic, and existing methods require significant processing resources or may introduce delays.

Innovation Solution

Implementing a deception-based security system where a network device is configured as a decoy to monitor network activity, using unassigned network addresses to detect scan patterns and generate response packets, thereby facilitating the identification of scans and configuration of security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network scanning detection methods are used, then network security monitoring can be performed, but significant processing resources are required and detection delays occur

Engineering Contradiction:
Improvenetwork scan detection capabilityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates a virtual copy of a legitimate network device (the decoy) that replicates its network address, services, and operational characteristics. This copy is deployed alongside the real device to attract and capture scan traffic. By copying the device's network footprint, the system can detect scans without processing every packet through complex analysis, thus improving detection reliability while reducing processing requirements.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The decoy device serves as an intermediary between the network scanner and the legitimate device. Instead of the security system directly analyzing all network traffic, the decoy intercepts scan packets and transfers this information to the security system. This intermediary approach allows the security system to focus only on packets directed at the decoy, significantly reducing processing resources needed while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive network traffic monitoring is implemented, then scan detection accuracy improves, but processing time increases

Engineering Contradiction:
Improvescan packet identification accuracyVSAvoiddetection delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The decoy device is configured with specific local characteristics that match the legitimate device's network address, services, and operational profile. By localizing these qualities to the decoy, the system creates a targeted detection mechanism that only processes packets relevant to the decoy's specific configuration. This localized approach maintains high measurement precision for scan detection while reducing overall processing time by ignoring unrelated traffic.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If network scanning tools are made accessible to administrators, then legitimate network assessment and maintenance improve, but the same tools can be used by network threats

Engineering Contradiction:
Improvenetwork administration capabilityVSAvoidmalicious network scanning
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system converts the harmful effect of network scanning into a beneficial detection mechanism. The decoy device is intentionally designed to be attractive to scanners, using legitimate network protocols and services to lure scan traffic. By converting the scanner's systematic probing into a useful detection signal, the system enables administrators to detect malicious scans without restricting legitimate administrative scanning activities.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

Instead of trying to block or prevent network scanning, the system inverts the approach by creating a decoy that actively invites scanning. The decoy's network presence is designed to be indistinguishable from legitimate devices to scanners, reversing the traditional security paradigm of hiding or blocking. This inversion allows the system to detect scans by observing the decoy's interactions with scanners, maintaining adaptability for legitimate administration while countering malicious activity.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS9985988B2Deception to detect network scans
Publication Date: 2018.05.29 ACALVIO TECH
  • US9985988B2 patent drawing
  • US9985988B2 patent drawing
  • US9985988B2 patent drawing

AI summary

Provided are systems, methods, and computer-program products for using deceptions to detect network scans. In various implementations, a network device, configured as a decoy network device can be configured to determine a particular network address. The network device can determine that the particular network address is unassigned. The network device can configure itself with the particular network address, wherein the network device uses the particular network address to monitor network activity for a network scan. The network device can receive a packet addressed to the particular network address. The network device can determine that received packet is associated with a scan of the network, including associating the received packet with other packets in the monitored network activity. The network device can configure one or more security settings for the network when the received packet is determined to be associated with a scan of the network.