Endemic Host Decoy Agents for Network Malicious Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional decoy systems in computer networks face challenges in making decoy servers appear authentic to attackers and scaling them to cover large networks effectively, requiring significant resources and manual effort.

Innovation Solution

The use of endemic hosts to host decoy agents, which match real hosts in attributes and reduce the need for dedicated resources, allowing decoy systems to exist in all network segments and thwart attacker fingerprinting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional decoy servers are deployed to detect attackers, then attacker detection capability is improved, but resource consumption and manual effort increase significantly

Engineering Contradiction:
Improveattacker detection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent creates virtual copies of decoy agents that can be deployed across multiple hosts. Instead of requiring physical decoy servers, virtual instances are copied and distributed throughout the network infrastructure, allowing comprehensive coverage with minimal resource investment. Each virtual decoy agent replicates the functionality needed for attacker detection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The decoy agent is designed to perform multiple functions simultaneously: it can detect attackers, collect forensic data, communicate with trap servers, and adapt to different network environments. This multi-functionality eliminates the need for separate specialized systems, reducing overall resource consumption while maintaining detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If decoy servers are made to appear authentic to attackers, then detection effectiveness is improved, but device complexity and manual configuration effort increase

Engineering Contradiction:
Improvedetection effectivenessVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The decoy agent automatically configures itself upon deployment. It self-registers with the deception management server, receives necessary credentials and configuration parameters, and adapts to the host environment without manual intervention. This self-service capability eliminates complex manual configuration while maintaining authentic appearance through automated environment detection and adaptation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The deception management server pre-generates credentials, configuration templates, and deployment packages before the decoy agents are instantiated. This preliminary preparation ensures that when decoy agents are deployed, they are already configured to appear authentic in their target environments, reducing on-site complexity and manual effort.

Inventive Principle:
Principle #10Preliminary action

3Area of stationary object

If decoy servers are scaled to cover large networks, then network coverage is improved, but resource requirements and deployment complexity increase

Engineering Contradiction:
Improvenetwork coverageVSAvoidresource requirements
Core Design Contradiction:
Area of stationary objectVSQuantity of substance

Solution Approach 1:

The patent divides the decoy system into modular components: a deception management server that coordinates operations, multiple trap servers that handle specific detection functions, and numerous lightweight decoy agents deployed across network segments. This segmentation allows the system to scale to large networks by adding only individual agent instances rather than entire server systems, reducing overall resource requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of scaling decoy coverage by adding more physical servers in the traditional dimension, the patent transitions to a virtual dimension where decoy agents can be instantiated as software instances on existing infrastructure. This dimensional shift allows unlimited network coverage without proportional increases in physical resource requirements.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If decoy systems are deployed in all network segments, then attacker detection coverage is improved, but system complexity and management overhead increase

Engineering Contradiction:
Improvedetection coverageVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The decoy agents continuously report their status, detected activities, and environmental information back to the deception management server. This feedback mechanism allows centralized monitoring and coordination of all decoy instances across network segments, reducing management overhead by providing automated visibility and control rather than requiring manual tracking of each individual decoy.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The deception management server acts as an intermediary between the numerous decentralized decoy agents and the external monitoring systems or administrators. It aggregates data from all agents, coordinates their operations, and presents unified management interfaces, thereby reducing the complexity of managing widespread decoy deployments by introducing a central coordinating layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10404747B1Detecting malicious activity by using endemic network hosts as decoys
Publication Date: 2019.09.03 PROOFPOINT ISRAEL HOLDINGS LTD
  • US10404747B1 patent drawing
  • US10404747B1 patent drawing
  • US10404747B1 patent drawing

AI summary

A system for detecting malicious activity in networks, including a deception manager having administrative credentials for a network, planting deceptions within network hosts, and distributing a decoy agent to each endemic decoy host (EDH), each deception including information regarding decoy communication ports of an EDH, each EDH having a group of ports, referred to as decoy ports, for connection by an attacker from a network host that the attacker has breached, wherein each decoy agent is programmed to alert the deception management server, and to proxy communication with the attacker to a trap server, in response to the decoy agent identifying the attacker attempting a connection to the decoy agent's EDH via one of the decoy ports, and a forensic collector that collects, from the breached network host, forensics of the attacker's activity, when the decoy agent acts as a proxy between the attacker and the trap server.