Distributed Threat Detection via Decoy Redirection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deploying threat monitoring servers across multiple network segments is costly and inefficient, especially in virtualized data centers where network configurations are dynamic, as it requires numerous servers to detect and manage threats without disrupting production systems.
Innovation Solution
Implementing a distributed threat detection system with lightweight threat sensors deployed across various network segments that forward unsolicited requests to a centralized threat detection system, which emulates services to analyze potential threats without affecting production servers, and uses deception points to redirect malicious traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple threat monitoring servers are deployed across all network segments, then threat detection coverage is improved, but deployment cost and complexity increase significantly
Solution Approach 1:
The patent creates a virtual copy of the production server as a threat monitoring server. This virtual copy receives copies of network traffic destined for the production server, allowing threat analysis without requiring physical deployment of monitoring servers in every network segment. The virtual copy replicates server functionality while enabling centralized threat detection.
Solution Approach 2:
The patent introduces a network switch as an intermediary device that intercepts network traffic before it reaches production servers. The switch forwards copies of this traffic to the virtual threat monitoring server, enabling centralized monitoring without modifying the production server infrastructure or requiring distributed monitoring nodes.
2Reliability
If threat monitoring servers are deployed in all network segments, then threat detection capability is improved, but cost increases due to additional hardware and deployment efforts
Solution Approach 1:
Instead of deploying physical monitoring servers in every network segment, the patent creates a single virtual copy of the production server that can monitor traffic from multiple segments. This virtualization approach eliminates the need for expensive hardware deployment across distributed locations while maintaining comprehensive monitoring capability.
Solution Approach 2:
The virtual threat monitoring server is designed to handle traffic from multiple network segments simultaneously, making it a universal monitoring solution. A single server instance performs the threat detection function for multiple segments, eliminating the need for separate dedicated monitoring servers in each segment and significantly reducing overall deployment cost.
3Reliability
If traditional threat monitoring approaches are used, then threat detection is achieved, but production systems are disrupted by monitoring overhead
Solution Approach 1:
The patent segments the monitoring function from the production server by using a separate virtual threat monitoring server. The network switch creates separate copies of traffic for monitoring purposes, allowing threat detection to occur in isolation without interfering with the original production server operations. This segmentation ensures monitoring overhead does not impact production system performance.
Data Source
AI summary
Methods and systems for deception using distributed threat detection are provided. Exemplary methods by an enforcement point, the enforcement point communicatively coupled to a first data network and a second data network, the enforcement point not providing services in the second data network, include: receiving, from a first workload in the second data network, a data packet addressed to a second workload in the second data network, the data packet requesting a service from the second workload; determining the data packet is for unauthorized access of the second workload, the determining using at least some of a 5-tuple of the data packet; identifying a deception point using the service, the deception point being in the first data network and including a decoy for the service; and redirecting the data packet to the deception point in the first data network.


