Forwarding Device Honeypot Deception via Traffic Diversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional feature-based security defense methods are inadequate in identifying unknown malware and addressing advanced persistent threats and social engineering attacks within internal networks, leading to high deployment and maintenance costs for honeypot-based deception systems due to the need for software installation on multiple hosts.

Innovation Solution

A cyber threat deception method that uses a forwarding device to simulate multiple honeypots by utilizing unused addresses or port numbers, acting as a traffic diversion node, thereby reducing the need for software installation on hosts and decreasing deployment and maintenance costs by creating a deception target set based on ARP requests, IP packets, and specific packet conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software programs for implementing proxy function are installed on multiple hosts to achieve honeypot deception, then the deception coverage and effectiveness are improved, but the deployment complexity and maintenance costs increase

Engineering Contradiction:
Improvedeception effectivenessVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the proxy function with the existing forwarding device (switch/router), eliminating the need for separate proxy software installation on multiple hosts. The forwarding device performs traffic diversion to honeypots using its existing packet processing capabilities, thus achieving deception effectiveness while reducing deployment complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The forwarding device is designed to perform multiple functions: normal network forwarding and honeypot traffic diversion. By making the forwarding device universal, the system avoids adding specialized proxy software to each host, thereby reducing maintenance complexity while maintaining deception coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If proxy software is installed on each host to divert traffic to honeypots, then the deception coverage is improved, but the maintenance costs and operational burden increase

Engineering Contradiction:
Improvedeception coverageVSAvoidmaintenance ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines the deception function with the forwarding device's existing traffic processing capabilities. This eliminates the need for separate proxy software maintenance on each host, significantly reducing operational burden while maintaining comprehensive deception coverage through the forwarding device's packet inspection and diversion mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple honeypots are simulated using unused addresses and ports, then the deception effectiveness against unknown malware is improved, but the system complexity increases

Engineering Contradiction:
Improvedeception effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The forwarding device autonomously performs traffic diversion by inspecting packet destinations and automatically directing traffic to honeypots. This self-service mechanism eliminates the need for complex centralized control systems or manual configuration on each host, reducing system complexity while maintaining high deception effectiveness through automated packet processing.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3923551B1Method and system for entrapping network threat, and forwarding device
Publication Date: 2024.10.09 HUAWEI TECH CO LTD
  • EP3923551B1 patent drawingFigure 1
  • EP3923551B1 patent drawingFigure 2
  • EP3923551B1 patent drawingFigure 3A-1

AI summary

This application discloses a cyber threat deception method and system, and a forwarding device. The forwarding device obtains a deception target set, where the deception target set includes a deception target, and the deception target includes an unused internet protocol IP address or an unopened port number on a used IP address. The forwarding device receives an IP packet from a host, and determines whether a destination party that the IP packet requests to access belongs to the deception target set. If the destination party that the IP packet requests to access belongs to the deception target set, the forwarding device sends the IP packet to a honeypot management server. The forwarding device receives a response packet, returned by the honeypot management server, of the corresponding IP packet. The forwarding device sends the response packet to the host. In this way, the host can subsequently communicate with a destination party that is requested to access and that is simulated, and the forwarding device deceives the host into considering that there is a destination party that is requested to access on a network. Deployment costs of an existing deception system are reduced according to this method.