Forwarding Device Honeypot Deception via Traffic Diversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional feature-based security defense methods are inadequate in identifying unknown malware and addressing advanced persistent threats and social engineering attacks within internal networks, leading to high deployment and maintenance costs for honeypot-based deception systems due to the need for software installation on multiple hosts.
Innovation Solution
A cyber threat deception method that uses a forwarding device to simulate multiple honeypots by utilizing unused addresses or port numbers, acting as a traffic diversion node, thereby reducing the need for software installation on hosts and decreasing deployment and maintenance costs by creating a deception target set based on ARP requests, IP packets, and specific packet conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software programs for implementing proxy function are installed on multiple hosts to achieve honeypot deception, then the deception coverage and effectiveness are improved, but the deployment complexity and maintenance costs increase
Solution Approach 1:
The patent merges the proxy function with the existing forwarding device (switch/router), eliminating the need for separate proxy software installation on multiple hosts. The forwarding device performs traffic diversion to honeypots using its existing packet processing capabilities, thus achieving deception effectiveness while reducing deployment complexity.
Solution Approach 2:
The forwarding device is designed to perform multiple functions: normal network forwarding and honeypot traffic diversion. By making the forwarding device universal, the system avoids adding specialized proxy software to each host, thereby reducing maintenance complexity while maintaining deception coverage.
2Reliability
If proxy software is installed on each host to divert traffic to honeypots, then the deception coverage is improved, but the maintenance costs and operational burden increase
Solution Approach 1:
The patent combines the deception function with the forwarding device's existing traffic processing capabilities. This eliminates the need for separate proxy software maintenance on each host, significantly reducing operational burden while maintaining comprehensive deception coverage through the forwarding device's packet inspection and diversion mechanisms.
3Reliability
If multiple honeypots are simulated using unused addresses and ports, then the deception effectiveness against unknown malware is improved, but the system complexity increases
Solution Approach 1:
The forwarding device autonomously performs traffic diversion by inspecting packet destinations and automatically directing traffic to honeypots. This self-service mechanism eliminates the need for complex centralized control systems or manual configuration on each host, reducing system complexity while maintaining high deception effectiveness through automated packet processing.
Data Source
Figure 1
Figure 2
Figure 3A-1
AI summary
This application discloses a cyber threat deception method and system, and a forwarding device. The forwarding device obtains a deception target set, where the deception target set includes a deception target, and the deception target includes an unused internet protocol IP address or an unopened port number on a used IP address. The forwarding device receives an IP packet from a host, and determines whether a destination party that the IP packet requests to access belongs to the deception target set. If the destination party that the IP packet requests to access belongs to the deception target set, the forwarding device sends the IP packet to a honeypot management server. The forwarding device receives a response packet, returned by the honeypot management server, of the corresponding IP packet. The forwarding device sends the response packet to the host. In this way, the host can subsequently communicate with a destination party that is requested to access and that is simulated, and the forwarding device deceives the host into considering that there is a destination party that is requested to access on a network. Deployment costs of an existing deception system are reduced according to this method.