Endemic Host Decoy Agents for Network Malicious Activity Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional decoy systems in computer networks face challenges in making decoy servers appear authentic to attackers and scaling them to cover large networks effectively, requiring significant resources and manual effort.
Innovation Solution
The use of endemic hosts to host decoy agents, which match real hosts in attributes and reduce the need for dedicated resources, allowing decoy systems to exist in all network segments and thwart attacker fingerprinting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional decoy servers are deployed to detect attackers, then attacker detection capability is improved, but resource consumption and manual effort increase significantly
Solution Approach 1:
The patent creates virtual copies of decoy agents that can be deployed across multiple hosts. Instead of requiring physical decoy servers, virtual instances are copied and distributed throughout the network infrastructure, allowing comprehensive coverage with minimal resource investment. Each virtual decoy agent replicates the functionality needed for attacker detection.
Solution Approach 2:
The decoy agent is designed to perform multiple functions simultaneously: it can detect attackers, collect forensic data, communicate with trap servers, and adapt to different network environments. This multi-functionality eliminates the need for separate specialized systems, reducing overall resource consumption while maintaining detection capability.
2Reliability
If decoy servers are made to appear authentic to attackers, then detection effectiveness is improved, but device complexity and manual configuration effort increase
Solution Approach 1:
The decoy agent automatically configures itself upon deployment. It self-registers with the deception management server, receives necessary credentials and configuration parameters, and adapts to the host environment without manual intervention. This self-service capability eliminates complex manual configuration while maintaining authentic appearance through automated environment detection and adaptation.
Solution Approach 2:
The deception management server pre-generates credentials, configuration templates, and deployment packages before the decoy agents are instantiated. This preliminary preparation ensures that when decoy agents are deployed, they are already configured to appear authentic in their target environments, reducing on-site complexity and manual effort.
3Area of stationary object
If decoy servers are scaled to cover large networks, then network coverage is improved, but resource requirements and deployment complexity increase
Solution Approach 1:
The patent divides the decoy system into modular components: a deception management server that coordinates operations, multiple trap servers that handle specific detection functions, and numerous lightweight decoy agents deployed across network segments. This segmentation allows the system to scale to large networks by adding only individual agent instances rather than entire server systems, reducing overall resource requirements.
Solution Approach 2:
Instead of scaling decoy coverage by adding more physical servers in the traditional dimension, the patent transitions to a virtual dimension where decoy agents can be instantiated as software instances on existing infrastructure. This dimensional shift allows unlimited network coverage without proportional increases in physical resource requirements.
4Reliability
If decoy systems are deployed in all network segments, then attacker detection coverage is improved, but system complexity and management overhead increase
Solution Approach 1:
The decoy agents continuously report their status, detected activities, and environmental information back to the deception management server. This feedback mechanism allows centralized monitoring and coordination of all decoy instances across network segments, reducing management overhead by providing automated visibility and control rather than requiring manual tracking of each individual decoy.
Solution Approach 2:
The deception management server acts as an intermediary between the numerous decentralized decoy agents and the external monitoring systems or administrators. It aggregates data from all agents, coordinates their operations, and presents unified management interfaces, thereby reducing the complexity of managing widespread decoy deployments by introducing a central coordinating layer.
Data Source
AI summary
A system for detecting malicious activity in networks, including a deception manager having administrative credentials for a network, planting deceptions within network hosts, and distributing a decoy agent to each endemic decoy host (EDH), each deception including information regarding decoy communication ports of an EDH, each EDH having a group of ports, referred to as decoy ports, for connection by an attacker from a network host that the attacker has breached, wherein each decoy agent is programmed to alert the deception management server, and to proxy communication with the attacker to a trap server, in response to the decoy agent identifying the attacker attempting a connection to the decoy agent's EDH via one of the decoy ports, and a forensic collector that collects, from the breached network host, forensics of the attacker's activity, when the decoy agent acts as a proxy between the attacker and the trap server.


