Distributed Deception D-S DPU for Multi-Layer Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional deception systems in data centers are centralized, expensive, and limited to the software layer (Layer 7) of the OSI model, failing to detect attacks on other layers like Layer 2 and Layer 3, and require human analysis, which is inefficient and costly.

Innovation Solution

A distributed deception system using a Deception-Supported Data Processing Unit (D-S DPU) integrated into multiple servers, operating across multiple layers of the OSI model, including Layer 2 and Layer 3, to detect and deceive attackers, reducing reliance on human intervention and enhancing security by emulating responses to gather threat information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized deception system is used, then deception capabilities are provided, but cost and complexity increase significantly

Engineering Contradiction:
Improvedeception capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized deception system into distributed deception modules integrated into individual servers and network devices. Each device independently performs deception functions at appropriate OSI layers, eliminating the need for a single complex centralized system while maintaining comprehensive deception coverage across the network infrastructure.

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If conventional deception systems are used, then Layer 7 attacks are detected, but attacks on Layer 2 and Layer 3 remain undetected

Engineering Contradiction:
Improveattack detection capabilityVSAvoidmulti-layer detection capability
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The patent implements deception modules that can operate across multiple OSI layers (Layer 2, Layer 3, and Layer 7) within the same network infrastructure. This multi-functional approach allows a single deception system to detect various types of attacks including ARP spoofing, IP spoofing, and application-layer attacks, eliminating the need for separate detection systems for each layer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If centralized deception systems are deployed, then threat data is collected, but human analysis is required which is inefficient and costly

Engineering Contradiction:
Improvethreat information collectionVSAvoidthreat analysis efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The distributed deception modules automatically analyze collected threat data using embedded analytics capabilities. The system self-manages threat detection, classification, and response without requiring external human intervention for analysis, thereby improving productivity while maintaining comprehensive threat information collection across all network layers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240015183A1Deception-based firewall enhancement
Publication Date: 2024.01.11 NVIDIA CORP
  • US20240015183A1 patent drawing
  • US20240015183A1 patent drawing
  • US20240015183A1 patent drawing

AI summary

Apparatuses, systems, and techniques to deceive a sender of a communication and optionally use that deception to gather data associated with the sender and/or the communication.