Dummy Response Generation for Network Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face challenges in distinguishing between true and false information, leading to potential reputation damage and increased costs when dealing with cyberattacks, as attackers can easily access and exploit false honeytokens, and unauthorized intrusion prevention systems struggle to effectively prevent malware infections and data leakage.
Innovation Solution
A security system that generates and transmits dummy resource responses based on characteristic information, using a timer-controlled request end flag to deceive attackers, thereby increasing their costs and minimizing damage while maintaining network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If a virtual decoy server with a decoy area is deployed to guide unauthorized access, then the ability to detect intruders is improved, but the reliability of information authenticity deteriorates because attackers cannot distinguish between true and false information
Solution Approach 1:
The patent creates a virtual decoy server that copies the directory structure and appearance of a real server, storing dummy responses that mimic legitimate data. This copying approach allows the system to deceive attackers into believing the decoy area contains real information, thereby detecting intruders while maintaining the appearance of authenticity without actually compromising real data integrity
Solution Approach 2:
The patent introduces a response generation unit as an intermediary between the decoy area and attackers. This intermediary dynamically generates dummy responses that are transmitted to attackers, serving as a mediator that prevents direct access to real information while maintaining the illusion of legitimate data availability, thus preserving information authenticity
2Reliability
If repeated deletion or protection actions are taken every time an unauthorized intrusion is detected, then network security is improved, but the protection cost increases
Solution Approach 1:
The patent deploys a virtual decoy server and decoy area in advance as preliminary defensive measures. By pre-positioning dummy resources and response generation capabilities, the system can detect and respond to intrusions without needing to repeatedly execute costly deletion or protection actions on real systems, thereby maintaining security while reducing ongoing protection costs
Solution Approach 2:
The patent converts the harmful aspect of unauthorized access into a beneficial detection opportunity. By allowing attackers to access the decoy area instead of real systems, the system transforms potential damage into useful intrusion detection data, reducing the need for repeated protective interventions and associated costs
3Difficulty of detecting and measuring
If a honeytoken with false information is deployed, then the ability to trace unauthorized use is improved, but the reputation damage risk increases when attackers cannot distinguish false from true information
Solution Approach 1:
The patent uses a response generation unit as an intermediary that creates and transmits dummy responses containing false information. This intermediary layer allows the system to trace unauthorized use through attacker interactions with the decoy area while controlling the dissemination of false information, thereby maintaining tracing capability while mitigating reputation damage by preventing confusion between real and fake data
Solution Approach 2:
The patent creates copied versions of legitimate information structures in the decoy area, but these copies are managed through a controlled response generation mechanism. This allows tracing of unauthorized access through the copied structures while ensuring that false information is clearly delimited and does not compromise the organization's reputation
Data Source
AI summary
Provided is a security system or the like with which security can be improved. A security system according to one embodiment of the present invention is provided with: a packet reception means that receives a request from an intruding device that is attempting intrusion; a dummy resource characteristic information storage means that stores characteristic information for a plurality of virtual dummy resources; a dummy response generation means that generates a dummy response on the basis of the characteristic information in response to the request directed to the dummy resource; a dummy response transmission control means that controls a request end flag, which indicates the presence/absence of untransmitted dummy resources, on the basis of a timer value; and a dummy response transmission means that, on the basis of the request end flag, transmits the dummy response to the intruding device that transmits the request.


