Fake Infrastructure for Stealthy Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting and preventing malicious attacks on computer networks often alert attackers that their attempts have been detected, allowing them to adjust their strategies. Additionally, these methods typically focus on evaluating attacks before they occur, which is insufficient for dynamic and evolving attacks.
Innovation Solution
The method involves creating a fake infrastructure that mimics the actual target infrastructure, allowing malicious attacks to be executed on the fake system while protecting the actual infrastructure. This fake infrastructure is dynamically created at runtime and communicates with external devices, allowing the system to gather information about intruders without revealing that it has detected the attack.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional intrusion detection methods are used to detect and alert attackers, then attack detection capability is improved, but attackers can adjust their strategies and evade future detection
Solution Approach 1:
The patent creates a virtual copy (virtual infrastructure) of the real infrastructure that mimics its behavior and characteristics. This copy is used to deceive attackers into believing they are attacking the real system, while actually allowing safe observation and analysis of attack patterns without alerting the attackers to their detection.
Solution Approach 2:
The virtual infrastructure acts as an intermediary between the attacker and the real infrastructure. It intercepts and handles attack traffic, preventing direct interaction with the real system while enabling indirect observation and analysis of attack behaviors through the virtual environment.
2Reliability
If attacks are evaluated before accessing the system, then security filtering is improved, but dynamic and evolving attacks cannot be effectively detected
Solution Approach 1:
The system dynamically creates and configures virtual infrastructures at runtime based on incoming traffic patterns and threat intelligence. This dynamic approach allows the system to adapt to new and evolving attack methods by adjusting the virtual environment's behavior and characteristics in real-time, rather than relying on static pre-defined security rules.
Solution Approach 2:
The system performs preliminary evaluation of attack patterns by directing suspicious traffic to the virtual infrastructure first, before allowing access to the real system. This preliminary action enables security filtering while simultaneously gathering data about evolving attacks for future detection improvement.
3Reliability
If a fake infrastructure is created to protect the real system, then system protection is improved, but infrastructure complexity increases
Solution Approach 1:
The virtual infrastructure serves multiple functions simultaneously: it acts as a decoy to protect the real system, a sandbox for observing attack behaviors, a data collection platform for building attack signatures, and a training environment for security systems. This multi-functionality reduces the need for separate systems for each purpose.
Solution Approach 2:
Instead of creating completely separate and complex protection systems, the patent uses virtualization to create a lightweight copy of the real infrastructure that can be rapidly deployed and managed. This copying approach simplifies the overall architecture compared to building entirely separate protection infrastructures.
4Reliability
If attackers receive immediate feedback that their attempts were unsuccessful, then attack prevention is improved, but attackers are motivated to continue attempting intrusions
Solution Approach 1:
The system converts the harmful effect of attacker persistence into a beneficial outcome by using the virtual infrastructure to absorb and analyze repeated attack attempts. The attackers' continued efforts provide more data for building robust attack signatures and improving detection capabilities, while the real system remains protected.
Solution Approach 2:
The virtual infrastructure mediates between the attacker and the real system, absorbing the brunt of attack attempts and preventing direct interaction with the real infrastructure. This intermediary layer allows the system to prevent attacks while avoiding giving attackers immediate feedback about their failure against the real system.
Data Source
AI summary
The present invention is directed towards a method, a network component and a system arrangement that allow the detection of intrusion attempts such that the attacker, or in case of joint attacks the attackers, is not aware that the malicious access is detected by the targeted system. Instead, the targeted system keeps offering services and is able to gather more information about the intruders. The present invention allows the establishment of global attack signature databases which can be provided to several target systems which enables the global prevention of fraudulent data access and system intrusions. For doing so the present invention suggests to provide a fake infrastructure dynamically at runtime which communicates with the external computing devices thereby protecting the requested infrastructure in a sandbox. The present invention is furthermore directed towards a computer program product and a computer-readable medium having stored thereon the computer program.


