Dynamic Network Deception System for Threat Engagement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network deception mechanisms are limited in engaging and gathering intelligence on network threats due to their processor-intensive nature and inability to dynamically adapt to varying threat behaviors, often requiring significant resources and struggling to distinguish real assets from decoys.

Innovation Solution

Implementing a network deception system that dynamically escalates engagement with threats using super-low, low-interaction, and high-interaction deception mechanisms, which can be configured in response to network packets and traffic patterns, allowing for the emulation of authentic systems and data to keep attackers engaged and away from real assets while gathering intelligence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If interactive deception mechanisms are used to engage network threats, then the ability to gather intelligence and emulate authentic systems improves, but the processing resource consumption increases

Engineering Contradiction:
Improveintelligence gathering capabilityVSAvoidprocessing resource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The deception system is segmented into multiple interaction levels (super-low interaction, low interaction, high interaction deceptions). Each level handles specific threat types and consumes different processing resources. The system segments the deception mechanism into address deception, low-interaction deception, and high-interaction deception components that can be independently activated based on threat assessment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The deception system dynamically adjusts its interaction level based on real-time threat behavior analysis. The network device monitors traffic patterns and automatically escalates from super-low interaction to low-interaction or high-interaction deceptions when threats exhibit suspicious behavior. This dynamic adaptation allows the system to conserve resources during normal operation while deploying intensive deception mechanisms only when needed.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple deception mechanisms are deployed to distinguish real assets from decoys, then the reliability of threat engagement improves, but the device complexity increases

Engineering Contradiction:
Improvethreat engagement accuracyVSAvoiddeception mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The deception system segments functionality across multiple independent mechanisms (address deception mechanism, low-interaction deception mechanism, high-interaction deception mechanism). Each mechanism handles specific aspects of deception and can operate independently, reducing the complexity burden on any single component while maintaining overall system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network device acts as an intermediary controller that manages the complexity by coordinating between different deception mechanisms. It receives network traffic, analyzes behavior, and routes traffic to appropriate deception mechanisms based on threat assessment, thereby simplifying the overall system architecture while maintaining high reliability through layered deception strategies.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Use of energy by moving object

If super-low deception mechanisms are used to conserve processing resources, then the processing resource consumption decreases, but the ability to engage and track network threats is limited

Engineering Contradiction:
Improveprocessing resource consumptionVSAvoidthreat engagement adaptability
Core Design Contradiction:
Use of energy by moving objectVSAdaptability or versatility

Solution Approach 1:

The system dynamically transitions between different deception interaction levels based on real-time threat behavior analysis. Super-low interaction deceptions are used for initial engagement and resource conservation, while the system escalates to low-interaction or high-interaction deceptions when threats exhibit adaptive or sophisticated behavior patterns, thereby maintaining versatility without continuous high resource consumption.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The deception system employs periodic monitoring and assessment of network traffic behavior to determine when to escalate deception mechanisms. During normal periods, super-low interaction deceptions are maintained with minimal processing overhead. When periodic analysis detects suspicious patterns, the system periodically activates more intensive deception mechanisms, creating an efficient rhythm of resource consumption aligned with actual threat dynamics.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10348763B2Responsive deception mechanisms
Publication Date: 2019.07.09 ACALVIO TECH
  • US10348763B2 patent drawing
  • US10348763B2 patent drawing
  • US10348763B2 patent drawing

AI summary

Provided are methods, network devices, and computer-program products for dynamically configuring a deception mechanism in response to network traffic from a possible network threat. In various implementations, a network deception system can receive a packet from a network. The network deception system can determine an intent associated with the packet by examining the contents of the packet. The network deception system can further configure a deception mechanism to respond to the intent, for example with the appropriate network communications, software or hardware configuration, and/or data.