Distributed Honey Pot Pattern Detection for Intrusion Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion detection systems (IDS) face challenges in detecting novel attacks and keeping up with the multitude of attack variations, as they rely on predefined patterns that need frequent updates and may not catch the latest threats until new signatures are released.

Innovation Solution

A distributed honey pot system collects and analyzes network traffic information to detect patterns indicative of malicious behavior, generating response data to automatically or manually respond to potential threats, thereby reducing the reliance on predefined attack patterns and improving detection of novel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If predefined attack patterns are used in IDS, then detection of known attacks is improved, but detection of novel attacks deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection of novel attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by deploying honey pots before attacks occur and continuously collecting traffic information in advance. This allows the system to build a database of attack patterns proactively, enabling detection of both known and novel attacks without waiting for signature updates

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously analyzing traffic information from distributed honey pots and using detected patterns to improve future detections. The pattern detection results feed back into the system to enhance its ability to identify both known and novel attacks dynamically

Inventive Principle:
Principle #23Feedback

2Reliability

If predefined patterns are frequently updated, then detection of latest threats is improved, but system complexity and maintenance difficulty worsen

Engineering Contradiction:
Improvedetection effectivenessVSAvoidpattern update complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically detecting patterns from collected traffic information without requiring manual intervention. The automated pattern detection and response data generation eliminate the need for frequent manual signature updates, reducing system complexity while maintaining detection effectiveness

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces the mechanical process of manual pattern creation, testing, and deployment with an automated information processing system. Traffic information is automatically analyzed and patterns are generated through computation rather than human effort, significantly reducing maintenance complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If distributed honey pot system is deployed, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvepattern detection accuracyVSAvoiddistributed system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges information from multiple distributed honey pots into a unified analysis framework. By combining traffic information from various locations and applying centralized pattern detection, the system achieves high detection accuracy while managing complexity through integration rather than distributed independent analysis

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8661102B1System, method and computer program product for detecting patterns among information from a distributed honey pot system
Publication Date: 2014.02.25 MCAFEE LLC
  • US8661102B1 patent drawing
  • US8661102B1 patent drawing
  • US8661102B1 patent drawing

AI summary

A honey pot system, method and computer program product are provided. In use, information is collected which relates to network traffic targeting a plurality of computers associated with a distributed honey pot system. Next, a pattern is detected among the information collected from the distributed honey pot system. To this end, response data is generated, if the pattern is detected.