Fake Infrastructure for Stealthy Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting and preventing malicious attacks on computer networks often alert attackers that their attempts have been detected, allowing them to adjust their strategies. Additionally, these methods typically focus on evaluating attacks before they occur, which is insufficient for dynamic and evolving attacks.

Innovation Solution

The method involves creating a fake infrastructure that mimics the actual target infrastructure, allowing malicious attacks to be executed on the fake system while protecting the actual infrastructure. This fake infrastructure is dynamically created at runtime and communicates with external devices, allowing the system to gather information about intruders without revealing that it has detected the attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional intrusion detection methods are used to detect and alert attackers, then attack detection capability is improved, but attackers can adjust their strategies and evade future detection

Engineering Contradiction:
Improveattack detection capabilityVSAvoidattacker strategy adaptation
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtual copy (virtual infrastructure) of the real infrastructure that mimics its behavior and characteristics. This copy is used to deceive attackers into believing they are attacking the real system, while actually allowing safe observation and analysis of attack patterns without alerting the attackers to their detection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual infrastructure acts as an intermediary between the attacker and the real infrastructure. It intercepts and handles attack traffic, preventing direct interaction with the real system while enabling indirect observation and analysis of attack behaviors through the virtual environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If attacks are evaluated before accessing the system, then security filtering is improved, but dynamic and evolving attacks cannot be effectively detected

Engineering Contradiction:
Improvesecurity filteringVSAvoiddetection of evolving attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically creates and configures virtual infrastructures at runtime based on incoming traffic patterns and threat intelligence. This dynamic approach allows the system to adapt to new and evolving attack methods by adjusting the virtual environment's behavior and characteristics in real-time, rather than relying on static pre-defined security rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary evaluation of attack patterns by directing suspicious traffic to the virtual infrastructure first, before allowing access to the real system. This preliminary action enables security filtering while simultaneously gathering data about evolving attacks for future detection improvement.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a fake infrastructure is created to protect the real system, then system protection is improved, but infrastructure complexity increases

Engineering Contradiction:
Improvesystem protectionVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual infrastructure serves multiple functions simultaneously: it acts as a decoy to protect the real system, a sandbox for observing attack behaviors, a data collection platform for building attack signatures, and a training environment for security systems. This multi-functionality reduces the need for separate systems for each purpose.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of creating completely separate and complex protection systems, the patent uses virtualization to create a lightweight copy of the real infrastructure that can be rapidly deployed and managed. This copying approach simplifies the overall architecture compared to building entirely separate protection infrastructures.

Inventive Principle:
Principle #26Copying

4Reliability

If attackers receive immediate feedback that their attempts were unsuccessful, then attack prevention is improved, but attackers are motivated to continue attempting intrusions

Engineering Contradiction:
Improveattack preventionVSAvoidattack persistence
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system converts the harmful effect of attacker persistence into a beneficial outcome by using the virtual infrastructure to absorb and analyze repeated attack attempts. The attackers' continued efforts provide more data for building robust attack signatures and improving detection capabilities, while the real system remains protected.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The virtual infrastructure mediates between the attacker and the real system, absorbing the brunt of attack attempts and preventing direct interaction with the real infrastructure. This intermediary layer allows the system to prevent attacks while avoiding giving attackers immediate feedback about their failure against the real system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250158999A1Method and network component for protecting networked infrastructures
Publication Date: 2025.05.15 ZOE LIFE TECH HLDG AG
  • US20250158999A1 patent drawing
  • US20250158999A1 patent drawing
  • US20250158999A1 patent drawing

AI summary

The present invention is directed towards a method, a network component and a system arrangement that allow the detection of intrusion attempts such that the attacker, or in case of joint attacks the attackers, is not aware that the malicious access is detected by the targeted system. Instead, the targeted system keeps offering services and is able to gather more information about the intruders. The present invention allows the establishment of global attack signature databases which can be provided to several target systems which enables the global prevention of fraudulent data access and system intrusions. For doing so the present invention suggests to provide a fake infrastructure dynamically at runtime which communicates with the external computing devices thereby protecting the requested infrastructure in a sandbox. The present invention is furthermore directed towards a computer program product and a computer-readable medium having stored thereon the computer program.