Decoy Server Port Forwarding for Undetectable Intrusion Recording

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and recording hacker activities on computer servers are ineffective due to hackers' ability to delete log information and detect recording means, making it difficult to develop effective countermeasures against their actions.

Innovation Solution

A decoy server is used, configured to record hacker actions without their knowledge, utilizing port forwarding techniques to intercept communications between the decoy and recording servers, with the decoy server being remote and insecure to attract hacker attention, and embedding fake files to deceive the hacker, while recording their actions and login information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If recording means are implemented on a real server to trace hacker activities, then hacker actions can be recorded, but hackers can detect the presence of recording means and delete log information

Engineering Contradiction:
Improvehacker activity logVSAvoidrecording means detection
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

A decoy server is introduced as an intermediary between the hacker and the recording system. The decoy server mimics a real server's appearance and behavior, causing hackers to interact with it instead of the actual server. This intermediary absorbs the hacker's attention and actions, while the real server remains protected and unaware of the recording process, thus preventing hackers from detecting the recording means on the real server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The decoy server creates a copy or replica of the real server's interface, services, and characteristics. By replicating the server's appearance and behavior, the decoy attracts hackers to interact with it, believing it to be the real target. This copying strategy allows the recording system to capture hacker activities on the decoy without hackers realizing they are being recorded on the actual server.

Inventive Principle:
Principle #26Copying

2Loss of information

If a decoy server is used to attract hackers, then hacker actions can be recorded without detection, but the decoy server must be remote and insecure which increases security risks

Engineering Contradiction:
Improvehacker activity recordingVSAvoidsecurity risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The vulnerable recording functionality is extracted from the real server and placed on a separate decoy server. The decoy server is deliberately configured with insecure settings and remote access capabilities to attract hackers, while the real server maintains its security integrity. This extraction isolates the security risk to the decoy environment, protecting the real server from direct exposure to hacker threats.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The decoy server's intentional insecurity and remote accessibility, which could be considered harmful vulnerabilities, are converted into a beneficial feature. These same characteristics that make the server attractive to hackers also enable it to effectively lure and record hacker activities. The harmful insecurity becomes the mechanism for capturing valuable intelligence about hacker techniques and tools.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Measurement precision

If professional recording solutions are used to monitor user activities, then user actions can be traced, but hackers can quickly detect these recording means

Engineering Contradiction:
Improveuser activity trackingVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The decoy server acts as an intermediary that absorbs hacker detection efforts. Since the decoy is designed to look and behave like a real server, hackers interact with it naturally without suspicion. The recording system operates on the decoy without hackers realizing they are being monitored, effectively neutralizing their detection capabilities while maintaining precise tracking of their activities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3644146B1Computer intrusion recording device
Publication Date: 2021.03.10 SERENICITY
  • EP3644146B1 patent drawingFigure 1
  • EP3644146B1 patent drawingFigure 2

AI summary

The invention relates to a computer intrusion recording device (10) comprising an application server (14) serving as a decoy in which a remote control service (16) is activated; said application server being associated with at least one Internet address (11) intended to be referenced on a domain name system (12); said remote control service being accessible on a listening port (30) of the application server so as to allow the establishment of a connection between said application server and a remote computer; said application server comprising a virtual port (31) associated with the remote control service on said domain name system and accessible from the Internet address of the application server;said recording device comprising a recording server (40) configured to capture communications transmitted on the virtual port, record these communications, and retransmit these communications on the listening port of the application server.