Decoy Server Port Forwarding for Undetectable Intrusion Recording
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting and recording hacker activities on computer servers are ineffective due to hackers' ability to delete log information and detect recording means, making it difficult to develop effective countermeasures against their actions.
Innovation Solution
A decoy server is used, configured to record hacker actions without their knowledge, utilizing port forwarding techniques to intercept communications between the decoy and recording servers, with the decoy server being remote and insecure to attract hacker attention, and embedding fake files to deceive the hacker, while recording their actions and login information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If recording means are implemented on a real server to trace hacker activities, then hacker actions can be recorded, but hackers can detect the presence of recording means and delete log information
Solution Approach 1:
A decoy server is introduced as an intermediary between the hacker and the recording system. The decoy server mimics a real server's appearance and behavior, causing hackers to interact with it instead of the actual server. This intermediary absorbs the hacker's attention and actions, while the real server remains protected and unaware of the recording process, thus preventing hackers from detecting the recording means on the real server.
Solution Approach 2:
The decoy server creates a copy or replica of the real server's interface, services, and characteristics. By replicating the server's appearance and behavior, the decoy attracts hackers to interact with it, believing it to be the real target. This copying strategy allows the recording system to capture hacker activities on the decoy without hackers realizing they are being recorded on the actual server.
2Loss of information
If a decoy server is used to attract hackers, then hacker actions can be recorded without detection, but the decoy server must be remote and insecure which increases security risks
Solution Approach 1:
The vulnerable recording functionality is extracted from the real server and placed on a separate decoy server. The decoy server is deliberately configured with insecure settings and remote access capabilities to attract hackers, while the real server maintains its security integrity. This extraction isolates the security risk to the decoy environment, protecting the real server from direct exposure to hacker threats.
Solution Approach 2:
The decoy server's intentional insecurity and remote accessibility, which could be considered harmful vulnerabilities, are converted into a beneficial feature. These same characteristics that make the server attractive to hackers also enable it to effectively lure and record hacker activities. The harmful insecurity becomes the mechanism for capturing valuable intelligence about hacker techniques and tools.
3Measurement precision
If professional recording solutions are used to monitor user activities, then user actions can be traced, but hackers can quickly detect these recording means
Solution Approach 1:
The decoy server acts as an intermediary that absorbs hacker detection efforts. Since the decoy is designed to look and behave like a real server, hackers interact with it naturally without suspicion. The recording system operates on the decoy without hackers realizing they are being monitored, effectively neutralizing their detection capabilities while maintaining precise tracking of their activities.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a computer intrusion recording device (10) comprising an application server (14) serving as a decoy in which a remote control service (16) is activated; said application server being associated with at least one Internet address (11) intended to be referenced on a domain name system (12); said remote control service being accessible on a listening port (30) of the application server so as to allow the establishment of a connection between said application server and a remote computer; said application server comprising a virtual port (31) associated with the remote control service on said domain name system and accessible from the Internet address of the application server;said recording device comprising a recording server (40) configured to capture communications transmitted on the virtual port, record these communications, and retransmit these communications on the listening port of the application server.