Decoy Segments for Detecting Malicious Network Interactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures, such as antivirus software and firewalls, are inadequate in preventing malicious attacks where attackers possess private information about a computer network, as they do not cover all possible attack methods, particularly those involving social engineering and insider threats.

Innovation Solution

A method and system that generate decoy segments, including sensitive information like email addresses and passwords, are broadcasted in public databases to attract malicious interactions, which are then monitored to identify indicators of compromise (IOCs), and communication with malicious sources is blocked to prevent attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity measures (antivirus software and firewalls) are used, then basic protection against known threats is provided, but they cannot prevent attacks where attackers possess private information about the computer network

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidcoverage of attack methods
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by generating and broadcasting decoy segments (fake email addresses, passwords, vulnerabilities) before actual attacks occur. These decoys are placed in public databases ahead of time, so when attackers attempt to use them, the system has already prepared to detect and block the attack, transforming passive defense into active preemptive security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces decoy segments as intermediary elements between the security system and attackers. These decoys (fake credentials, dummy vulnerabilities) act as mediators that attract and reveal attacker behavior without exposing real system information, allowing the system to study attack patterns and respond appropriately.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If decoy segments are generated and broadcasted in public databases, then malicious interactions can be detected even when attackers use private information, but this requires monitoring and analysis capabilities to identify IOCs from the interactions

Engineering Contradiction:
Improvedetection accuracy of malicious interactionsVSAvoidsystem complexity for monitoring and IOC identification
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements feedback loops where monitored interactions are analyzed to generate IOCs, which then feed back into updating the decoy segments and blocking rules. This continuous feedback cycle allows the system to learn from detected attacks and improve its detection accuracy over time without requiring proportional increases in system complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service by automatically generating IOCs from monitored interactions and using these IOCs to update its own blocking capabilities. The security system monitors its own environment, identifies threats, and autonomously responds by blocking malicious sources, reducing the need for external intervention and simplifying operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If communication with malicious sources is blocked based on identified IOCs, then attacks can be prevented, but this requires continuous updating of IOC databases to remain effective against evolving threats

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidtime for updating security measures
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system ensures continuous useful action by continuously monitoring interactions, generating IOCs, and updating blocking rules without interruption. The security process runs continuously rather than in periodic batches, ensuring that the system remains up-to-date with emerging threats and maintains constant protection capability without downtime or manual intervention.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11785044B2System and method for detection of malicious interactions in a computer network
Publication Date: 2023.10.10 INTSIGHTS CYBER INTELLIGENCE LTD
  • US11785044B2 patent drawing
  • US11785044B2 patent drawing
  • US11785044B2 patent drawing

AI summary

System and method of detecting malicious interactions in a computer network, the method including generating, by a processor, at least one decoy segment, broadcasting, by the processor, the generated at least one decoy segment in a public database, monitoring, by the processor, communication within the computer network to identify interactions associated with the generated at least one decoy segment, determining, by the processor, at least one indicator of compromise (IOC) for the identified interactions, and blocking communication between the computer network and any computer associated with the determined at least one IOC.