Honeypot Network Services for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring systems face challenges in accurately detecting network intrusion attempts, often resulting in false positives that can disrupt legitimate network activity and fail to promptly identify compromised devices.

Innovation Solution

Implementing a system that detects network service discovery activity by monitoring requests to unassigned ports and addresses, and presents honeypot network services to suspected devices to verify compromise, allowing for targeted protection measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional port scan detection is used to identify compromised devices, then network security monitoring capability is improved, but false positives increase causing disruption to legitimate network activity

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces honeypot network services as an intermediary between the port scanner and the actual network services. When a port scanner attempts to connect to a honeypot service, the connection is monitored and analyzed. This intermediary layer allows the system to distinguish between legitimate scanning activity and malicious attempts by compromised devices, reducing false positives while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by deploying honeypot network services before actual attacks occur. These honeypot services are positioned to intercept and monitor port scanning attempts in advance. By having these deceptive services ready beforehand, the system can detect and analyze scanning behavior before it reaches real network services, enabling early identification of compromised devices without disrupting legitimate traffic.

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If port scanning detection sensitivity is increased to detect more compromised devices, then detection capability is improved, but legitimate network activity is disrupted more frequently

Engineering Contradiction:
Improvedetection sensitivityVSAvoidnetwork operation continuity
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of operation

Solution Approach 1:

The patent applies local quality by making detection sensitivity local rather than global. Different levels of monitoring and response are applied to different network entities based on their behavior patterns. Legitimate devices that scan ports are allowed to proceed with normal operations, while devices showing signs of compromise are subjected to more intensive monitoring through honeypot interactions. This localized approach maintains high detection sensitivity without causing widespread disruption to legitimate network activity.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If honeypot network services are made available to all devices, then detection coverage is improved, but network performance degradation increases

Engineering Contradiction:
Improvedetection coverageVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the network into different zones with honeypot services deployed strategically rather than universally. Honeypot network services are placed in specific segments or zones where compromised devices are most likely to attempt connections, rather than deploying them across all network devices. This segmentation maintains comprehensive detection coverage for compromised devices while minimizing the performance impact on the overall network by limiting honeypot deployment to specific high-risk areas.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10708304B2Honeypot network services
Publication Date: 2020.07.07 SOPHOS LTD
  • US10708304B2 patent drawing
  • US10708304B2 patent drawing
  • US10708304B2 patent drawing

AI summary

In general, in one aspect, a system for providing honeypot network services may monitor network activity, and detect network activity indicative of network service discovery by a first device, for example, port scanning. The system may present a temporarily available network service to the first device in response to detecting the activity indicative of port scanning, for example, by redirecting traffic at an unassigned network address to a honeypot network service. The system may monitor communication between the first device and the presented honeypot network service to determine whether the monitored communication is indicative of a threat, and determine that the first device is compromised based on the monitored communication between the first device and the presented honeypot network service. The system may initiate measures to protect the network from the compromised first device.