Dummy Response Generation for Network Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in distinguishing between true and false information, leading to potential reputation damage and increased costs when dealing with cyberattacks, as attackers can easily access and exploit false honeytokens, and unauthorized intrusion prevention systems struggle to effectively prevent malware infections and data leakage.

Innovation Solution

A security system that generates and transmits dummy resource responses based on characteristic information, using a timer-controlled request end flag to deceive attackers, thereby increasing their costs and minimizing damage while maintaining network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If a virtual decoy server with a decoy area is deployed to guide unauthorized access, then the ability to detect intruders is improved, but the reliability of information authenticity deteriorates because attackers cannot distinguish between true and false information

Engineering Contradiction:
Improveintruder detection capabilityVSAvoidinformation authenticity
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent creates a virtual decoy server that copies the directory structure and appearance of a real server, storing dummy responses that mimic legitimate data. This copying approach allows the system to deceive attackers into believing the decoy area contains real information, thereby detecting intruders while maintaining the appearance of authenticity without actually compromising real data integrity

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a response generation unit as an intermediary between the decoy area and attackers. This intermediary dynamically generates dummy responses that are transmitted to attackers, serving as a mediator that prevents direct access to real information while maintaining the illusion of legitimate data availability, thus preserving information authenticity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If repeated deletion or protection actions are taken every time an unauthorized intrusion is detected, then network security is improved, but the protection cost increases

Engineering Contradiction:
Improvenetwork securityVSAvoidprotection cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent deploys a virtual decoy server and decoy area in advance as preliminary defensive measures. By pre-positioning dummy resources and response generation capabilities, the system can detect and respond to intrusions without needing to repeatedly execute costly deletion or protection actions on real systems, thereby maintaining security while reducing ongoing protection costs

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the harmful aspect of unauthorized access into a beneficial detection opportunity. By allowing attackers to access the decoy area instead of real systems, the system transforms potential damage into useful intrusion detection data, reducing the need for repeated protective interventions and associated costs

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Difficulty of detecting and measuring

If a honeytoken with false information is deployed, then the ability to trace unauthorized use is improved, but the reputation damage risk increases when attackers cannot distinguish false from true information

Engineering Contradiction:
Improveunauthorized use tracing capabilityVSAvoidreputation damage risk
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent uses a response generation unit as an intermediary that creates and transmits dummy responses containing false information. This intermediary layer allows the system to trace unauthorized use through attacker interactions with the decoy area while controlling the dissemination of false information, thereby maintaining tracing capability while mitigating reputation damage by preventing confusion between real and fake data

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates copied versions of legitimate information structures in the decoy area, but these copies are managed through a controlled response generation mechanism. This allows tracing of unauthorized access through the copied structures while ensuring that false information is clearly delimited and does not compromise the organization's reputation

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10868830B2Network security system, method, recording medium and program for preventing unauthorized attack using dummy response
Publication Date: 2020.12.15 NEC CORP
  • US10868830B2 patent drawing
  • US10868830B2 patent drawing
  • US10868830B2 patent drawing

AI summary

Provided is a security system or the like with which security can be improved. A security system according to one embodiment of the present invention is provided with: a packet reception means that receives a request from an intruding device that is attempting intrusion; a dummy resource characteristic information storage means that stores characteristic information for a plurality of virtual dummy resources; a dummy response generation means that generates a dummy response on the basis of the characteristic information in response to the request directed to the dummy resource; a dummy response transmission control means that controls a request end flag, which indicates the presence/absence of untransmitted dummy resources, on the basis of a timer value; and a dummy response transmission means that, on the basis of the request end flag, transmits the dummy response to the intruding device that transmits the request.