Dynamic Honeypots in SD-WAN for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Wide Area Network (WAN) deployments face challenges such as insufficient bandwidth, high costs, application downtime, poor SaaS performance, complex operations, and difficulty in securing networks due to increased complexity from mobile and IoT device traffic, and cloud adoption.

Innovation Solution

The implementation of a Software-Defined Wide-Area Network (SD-WAN) platform that dynamically generates honeypots to improve end-to-end network security by tracking hosts across Local Area Networks (LANs) and routing traffic through honeypot network devices, using Locator/Identifier Separation Protocol (LISP) for efficient traffic management and segmentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional WAN deployments use MPLS transports or Internet links with centralized data center backhaul, then network security can be maintained through traditional perimeter defense, but network complexity increases and scalability is limited

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple Virtual Private Networks (VPNs) that can be independently managed and secured. Each VPN represents a logical segmentation of the network infrastructure, allowing security policies to be applied at the VPN level rather than requiring complex perimeter defense across the entire network. This segmentation enables simplified security management while maintaining robust protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces Virtual Network Functions (VNFs) as intermediary elements that provide security services within the SD-WAN architecture. These VNFs act as mediators between network traffic and security policies, enabling centralized security management without requiring complex distributed security configurations. The VNFs can be dynamically deployed and managed through the centralized controller.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SD-WAN dynamically generates honeypots to secure unauthorized access attempts, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service honeypot generation where the SD-WAN system automatically creates, deploys, and manages honeypots without requiring manual intervention. The centralized controller detects potential security threats and dynamically provisions honeypots as needed, then automatically manages their lifecycle including deployment, monitoring, and decommissioning. This automation reduces system complexity despite the advanced security functionality.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The honeypots are dynamically generated and adapted based on real-time network conditions and threat detection. The system can adjust honeypot characteristics, locations, and behaviors dynamically rather than using static security configurations. This dynamic approach enhances security effectiveness while the centralized management keeps operational complexity manageable.

Inventive Principle:
Principle #15Dynamics

3Reliability

If traffic is routed through honeypot network devices for security monitoring, then unauthorized access attempts are secured, but bandwidth utilization decreases

Engineering Contradiction:
Improveunauthorized access securityVSAvoidbandwidth utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by routing only suspicious or unauthorized traffic through honeypot network devices for security monitoring, while allowing legitimate traffic to flow through normal network paths. The centralized controller analyzes traffic patterns and selectively directs only the portion of traffic that requires security inspection through the honeypot infrastructure, minimizing impact on overall bandwidth utilization while maintaining security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11671450B2Dynamic honeypots
Publication Date: 2023.06.06 CISCO TECHNOLOGY INC
  • US11671450B2 patent drawing
  • US11671450B2 patent drawing
  • US11671450B2 patent drawing

AI summary

A mapping system, under administrative control of a Wide Area Network (WAN) controller, can track each host, authorized to access a plurality of Local Area Networks (LANs), in one or more mapping databases including a first network address representing an identifier and a second network addressing representing a locator for each host. The mapping system can receive a request for resolution of a first identifier of a host not presently connected to the network. The mapping system can determine the mapping databases exclude a mapping for the first identifier. The mapping system can update the mapping databases with a first mapping including the first identifier and a first locator corresponding to a honeypot network device. The mapping system can transmit, to one or more LANs of the plurality of LANs, routing information to route traffic destined for the first identifier to the honeypot network device.