Dummy Network Traffic for Attack Detection in Sandboxes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security systems, particularly in sandbox operating systems, face challenges in detecting potential attacks on applications without monitoring network traffic, as firewalls are limited in their ability to protect against attackers exploiting message content.

Innovation Solution

A computing device executes a detection application that transmits dummy messages simulating network traffic to identify potential attacks by comparing reply messages with expected responses, allowing for the detection of malicious activities without monitoring actual application traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall is used to control network traffic based on rule sets, then network security is improved, but the ability to detect attacks exploiting message content is lost

Engineering Contradiction:
Improvenetwork securityVSAvoidattack detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates dummy messages that copy the structure and format of real application messages without containing actual sensitive data. These synthetic messages are transmitted through the network to provoke attacks, allowing the system to detect malicious activities while preserving application privacy and avoiding the need to monitor real message contents.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary detection application that sits between the firewall and the network traffic. This intermediary analyzes incoming and outgoing messages for attack patterns while allowing the firewall to continue its basic filtering function, thus adding detection capability without compromising the firewall's rule-based operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If network traffic monitoring is implemented to detect attacks, then attack detection capability is improved, but application privacy and sandbox isolation are compromised

Engineering Contradiction:
Improveattack detection capabilityVSAvoidapplication privacy
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

Instead of monitoring real application messages, the system generates synthetic dummy messages that replicate the structural characteristics of real traffic. These copies are used to bait attackers into revealing their presence through malformed responses, while the actual application messages remain private and unmonitored.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the detection function from the application function by running a separate detection application that independently generates and analyzes dummy traffic. This segmentation allows attack detection to occur without requiring access to or analysis of real application messages, preserving sandbox isolation and application privacy.

Inventive Principle:
Principle #1Segmentation

3Difficulty of detecting and measuring

If dummy messages are transmitted to induce attacks, then attack detection is improved, but network bandwidth is consumed

Engineering Contradiction:
Improveattack detection capabilityVSAvoidnetwork bandwidth
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of energy

Solution Approach 1:

The detection application transmits dummy messages periodically rather than continuously, and can adjust the frequency based on network conditions and detected threat levels. This periodic approach maintains detection capability while minimizing unnecessary bandwidth consumption during low-risk periods.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system transmits only enough dummy traffic to effectively probe for attacks - not so much as to waste bandwidth, but sufficient to provoke attacker responses. The volume of dummy messages is optimized to achieve detection goals with minimal network resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9288223B2Potential attack detection based on dummy network traffic
Publication Date: 2016.03.15 CA TECH INC
  • US9288223B2 patent drawing
  • US9288223B2 patent drawing
  • US9288223B2 patent drawing

AI summary

A method, apparatus and product for potential attack detection based on dummy network traffic. One embodiment includes a method comprising analyzing an activity, wherein the activity is performed in response to a message, wherein the message is transmitted by a first application that is executed by a computing device, wherein the computing device is connected to a computerized network, wherein the first application is configured to transmit the message in order to induce a potential attacker to perform a malicious activity, wherein said analyzing comprises comparing the activity to a predetermined expected activity in response to the message; and determining, based on the analysis of the activity, that a second application is under a potential attack; whereby an operation of the first application is capable of exposing potential attacks on the second application without monitoring network traffic of the second application.