Dummy Network Traffic for Attack Detection in Sandboxes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security systems, particularly in sandbox operating systems, face challenges in detecting potential attacks on applications without monitoring network traffic, as firewalls are limited in their ability to protect against attackers exploiting message content.
Innovation Solution
A computing device executes a detection application that transmits dummy messages simulating network traffic to identify potential attacks by comparing reply messages with expected responses, allowing for the detection of malicious activities without monitoring actual application traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall is used to control network traffic based on rule sets, then network security is improved, but the ability to detect attacks exploiting message content is lost
Solution Approach 1:
The patent creates dummy messages that copy the structure and format of real application messages without containing actual sensitive data. These synthetic messages are transmitted through the network to provoke attacks, allowing the system to detect malicious activities while preserving application privacy and avoiding the need to monitor real message contents.
Solution Approach 2:
The patent introduces an intermediary detection application that sits between the firewall and the network traffic. This intermediary analyzes incoming and outgoing messages for attack patterns while allowing the firewall to continue its basic filtering function, thus adding detection capability without compromising the firewall's rule-based operation.
2Difficulty of detecting and measuring
If network traffic monitoring is implemented to detect attacks, then attack detection capability is improved, but application privacy and sandbox isolation are compromised
Solution Approach 1:
Instead of monitoring real application messages, the system generates synthetic dummy messages that replicate the structural characteristics of real traffic. These copies are used to bait attackers into revealing their presence through malformed responses, while the actual application messages remain private and unmonitored.
Solution Approach 2:
The patent segments the detection function from the application function by running a separate detection application that independently generates and analyzes dummy traffic. This segmentation allows attack detection to occur without requiring access to or analysis of real application messages, preserving sandbox isolation and application privacy.
3Difficulty of detecting and measuring
If dummy messages are transmitted to induce attacks, then attack detection is improved, but network bandwidth is consumed
Solution Approach 1:
The detection application transmits dummy messages periodically rather than continuously, and can adjust the frequency based on network conditions and detected threat levels. This periodic approach maintains detection capability while minimizing unnecessary bandwidth consumption during low-risk periods.
Solution Approach 2:
The system transmits only enough dummy traffic to effectively probe for attacks - not so much as to waste bandwidth, but sufficient to provoke attacker responses. The volume of dummy messages is optimized to achieve detection goals with minimal network resource consumption.
Data Source
AI summary
A method, apparatus and product for potential attack detection based on dummy network traffic. One embodiment includes a method comprising analyzing an activity, wherein the activity is performed in response to a message, wherein the message is transmitted by a first application that is executed by a computing device, wherein the computing device is connected to a computerized network, wherein the first application is configured to transmit the message in order to induce a potential attacker to perform a malicious activity, wherein said analyzing comprises comparing the activity to a predetermined expected activity in response to the message; and determining, based on the analysis of the activity, that a second application is under a potential attack; whereby an operation of the first application is capable of exposing potential attacks on the second application without monitoring network traffic of the second application.


