Decoy Segments for Detecting Malicious Network Interactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures, such as antivirus software and firewalls, are inadequate in preventing malicious attacks where attackers possess private information about a computer network, as they do not cover all possible attack methods, particularly those involving social engineering and insider threats.
Innovation Solution
A method and system that generate decoy segments, including sensitive information like email addresses and passwords, are broadcasted in public databases to attract malicious interactions, which are then monitored to identify indicators of compromise (IOCs), and communication with malicious sources is blocked to prevent attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cybersecurity measures (antivirus software and firewalls) are used, then basic protection against known threats is provided, but they cannot prevent attacks where attackers possess private information about the computer network
Solution Approach 1:
The system performs preliminary actions by generating and broadcasting decoy segments (fake email addresses, passwords, vulnerabilities) before actual attacks occur. These decoys are placed in public databases ahead of time, so when attackers attempt to use them, the system has already prepared to detect and block the attack, transforming passive defense into active preemptive security.
Solution Approach 2:
The patent introduces decoy segments as intermediary elements between the security system and attackers. These decoys (fake credentials, dummy vulnerabilities) act as mediators that attract and reveal attacker behavior without exposing real system information, allowing the system to study attack patterns and respond appropriately.
2Measurement precision
If decoy segments are generated and broadcasted in public databases, then malicious interactions can be detected even when attackers use private information, but this requires monitoring and analysis capabilities to identify IOCs from the interactions
Solution Approach 1:
The system implements feedback loops where monitored interactions are analyzed to generate IOCs, which then feed back into updating the decoy segments and blocking rules. This continuous feedback cycle allows the system to learn from detected attacks and improve its detection accuracy over time without requiring proportional increases in system complexity.
Solution Approach 2:
The system performs self-service by automatically generating IOCs from monitored interactions and using these IOCs to update its own blocking capabilities. The security system monitors its own environment, identifies threats, and autonomously responds by blocking malicious sources, reducing the need for external intervention and simplifying operation.
3Reliability
If communication with malicious sources is blocked based on identified IOCs, then attacks can be prevented, but this requires continuous updating of IOC databases to remain effective against evolving threats
Solution Approach 1:
The system ensures continuous useful action by continuously monitoring interactions, generating IOCs, and updating blocking rules without interruption. The security process runs continuously rather than in periodic batches, ensuring that the system remains up-to-date with emerging threats and maintains constant protection capability without downtime or manual intervention.
Data Source
AI summary
System and method of detecting malicious interactions in a computer network, the method including generating, by a processor, at least one decoy segment, broadcasting, by the processor, the generated at least one decoy segment in a public database, monitoring, by the processor, communication within the computer network to identify interactions associated with the generated at least one decoy segment, determining, by the processor, at least one indicator of compromise (IOC) for the identified interactions, and blocking communication between the computer network and any computer associated with the determined at least one IOC.


