Distributed Threat Detection via Decoy Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying threat monitoring servers across multiple network segments is costly and inefficient, especially in virtualized data centers where network configurations are dynamic, as it requires numerous servers to detect and manage threats without disrupting production systems.

Innovation Solution

Implementing a distributed threat detection system with lightweight threat sensors deployed across various network segments that forward unsolicited requests to a centralized threat detection system, which emulates services to analyze potential threats without affecting production servers, and uses deception points to redirect malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple threat monitoring servers are deployed across all network segments, then threat detection coverage is improved, but deployment cost and complexity increase significantly

Engineering Contradiction:
Improvethreat detection coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the production server as a threat monitoring server. This virtual copy receives copies of network traffic destined for the production server, allowing threat analysis without requiring physical deployment of monitoring servers in every network segment. The virtual copy replicates server functionality while enabling centralized threat detection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a network switch as an intermediary device that intercepts network traffic before it reaches production servers. The switch forwards copies of this traffic to the virtual threat monitoring server, enabling centralized monitoring without modifying the production server infrastructure or requiring distributed monitoring nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If threat monitoring servers are deployed in all network segments, then threat detection capability is improved, but cost increases due to additional hardware and deployment efforts

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Instead of deploying physical monitoring servers in every network segment, the patent creates a single virtual copy of the production server that can monitor traffic from multiple segments. This virtualization approach eliminates the need for expensive hardware deployment across distributed locations while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual threat monitoring server is designed to handle traffic from multiple network segments simultaneously, making it a universal monitoring solution. A single server instance performs the threat detection function for multiple segments, eliminating the need for separate dedicated monitoring servers in each segment and significantly reducing overall deployment cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional threat monitoring approaches are used, then threat detection is achieved, but production systems are disrupted by monitoring overhead

Engineering Contradiction:
Improvethreat detectionVSAvoidproduction system disruption
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the monitoring function from the production server by using a separate virtual threat monitoring server. The network switch creates separate copies of traffic for monitoring purposes, allowing threat detection to occur in isolation without interfering with the original production server operations. This segmentation ensures monitoring overhead does not impact production system performance.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10091238B2Deception using distributed threat detection
Publication Date: 2018.10.02 GRYPHO5 LLC
  • US10091238B2 patent drawing
  • US10091238B2 patent drawing
  • US10091238B2 patent drawing

AI summary

Methods and systems for deception using distributed threat detection are provided. Exemplary methods by an enforcement point, the enforcement point communicatively coupled to a first data network and a second data network, the enforcement point not providing services in the second data network, include: receiving, from a first workload in the second data network, a data packet addressed to a second workload in the second data network, the data packet requesting a service from the second workload; determining the data packet is for unauthorized access of the second workload, the determining using at least some of a 5-tuple of the data packet; identifying a deception point using the service, the deception point being in the first data network and including a decoy for the service; and redirecting the data packet to the deception point in the first data network.