Decoy Network System for Zero-Day Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security mechanisms operate in isolation and are ineffective against zero-day attacks, failing to quickly identify and mitigate breaches, especially when new threats emerge, leading to potential loss of sensitive information.

Innovation Solution

A system and method that aggregates security threat indicators from multiple sources for combined analysis, using a threat analyzer to intercept and analyze stolen information, and employing decoy devices to attract and intercept malicious traffic, thereby identifying and mitigating breaches more effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security mechanisms operate in isolation, then device complexity is reduced, but reliability of security detection deteriorates

Engineering Contradiction:
Improvesecurity detection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple independent security mechanisms (firewall, antivirus, IDS, IPS) into a unified security system that shares threat intelligence and coordinates responses. This merging allows the system to achieve higher detection reliability through collaborative analysis while managing complexity through centralized coordination.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security system is designed to perform multiple functions simultaneously - threat detection, analysis, blocking, and response coordination - across different security layers. This multi-functionality improves reliability by ensuring comprehensive coverage while reducing the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If security mechanisms operate independently, then ease of operation is improved, but speed of breach identification deteriorates

Engineering Contradiction:
Improvebreach identification speedVSAvoidsystem operation simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system implements continuous feedback loops where threat intelligence from one security mechanism is immediately shared with others, enabling rapid breach identification. The centralized coordinator receives real-time data from all components and distributes actionable intelligence, creating a fast-response ecosystem that maintains operational simplicity through automated feedback cycles.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If traditional security mechanisms are used, then adaptability to known threats is maintained, but effectiveness against zero-day attacks deteriorates

Engineering Contradiction:
Improvethreat response adaptabilityVSAvoidzero-day attack protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary analysis of threat patterns and behaviors before actual attacks occur. By establishing baseline security profiles and pre-configuring response protocols for emerging threat types, the system can rapidly adapt to zero-day attacks without waiting for traditional signature-based updates, thereby improving both adaptability and reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10230761B1Method and system for detecting network compromise
Publication Date: 2019.03.12 DIGICERT INC
  • US10230761B1 patent drawing
  • US10230761B1 patent drawing
  • US10230761B1 patent drawing

AI summary

A method and system are described for detecting unauthorized access to one or more of a plurality of networked victim computers in a victim cloud. The networked victim computers connect to one or more DNS servers. The system includes one or more decoy bot computers, which are operated as victim computers in the victim cloud. The system also includes one or more decoy control computers, which are operated as control computers that communicate with victim computers in the victim cloud. Threats are identified by analyzing data traffic communicated with the decoy bot computers and decoy control computers for information suspected of having being sent from a victim's computer without proper authorization, and by monitoring whether behavior of a DNS server deviates from expected behaviors.