Honeypot Device Accessible via VLAN Trunking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems require multiple honeypot devices to effectively identify unwanted activity in large networks, which is resource-intensive and costly due to the need for virtualization and additional hardware.

Innovation Solution

A system and method utilizing a honeypot device accessible via virtual local area network (VLAN) trunking, allowing a single honeypot device to be accessible across multiple sub-networks, thereby identifying unwanted activity efficiently and scalably without the need for extensive resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple honeypot devices are deployed to effectively identify unwanted activity in large networks, then the coverage and effectiveness of security monitoring is improved, but the cost and resource consumption increase due to virtualization requirements and additional hardware

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidnumber of honeypot devices
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent makes a single honeypot device universally accessible across multiple VLANs through trunking configuration, allowing one device to perform the security monitoring function that would traditionally require multiple devices. The honeypot device is configured with multiple VLAN interfaces and made accessible via 802.1Q trunking, enabling it to receive and analyze traffic from multiple virtual networks simultaneously, thus achieving multi-functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces VLAN trunking as an intermediary mechanism that connects the single honeypot device to multiple sub-networks. The trunking configuration acts as a mediator that allows the honeypot to access traffic from various VLANs without requiring physical presence or dedicated interfaces in each network segment, thereby reducing the number of devices needed while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If virtualization software is used to reduce the number of honeypot devices, then hardware costs are reduced, but the system requires costly resources such as licenses for virtual servers and guest operating systems

Engineering Contradiction:
Improvenumber of honeypot devicesVSAvoidsoftware license costs
Core Design Contradiction:
Quantity of substanceVSLoss of energy

Solution Approach 1:

The patent utilizes existing network infrastructure (VLAN trunking capabilities already present in network switches) to achieve the goal of reducing honeypot devices. Instead of introducing new virtualization software that would require licensing, the solution leverages the self-service capabilities of standard network equipment to make a single honeypot device accessible across multiple VLANs, avoiding additional software license costs.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If a single honeypot device is made accessible across multiple sub-networks via VLAN trunking, then the number of required devices is reduced, but the network configuration complexity increases

Engineering Contradiction:
Improvenumber of honeypot devicesVSAvoidVLAN trunking configuration
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent solves the complexity issue by moving the configuration from the device level to the network infrastructure level. Instead of configuring each honeypot device to handle multiple networks, the solution uses VLAN trunking at the network switch level to present multiple virtual networks to the single honeypot device. This dimensional shift in configuration approach simplifies device management while achieving multi-network accessibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8528092B2System, method, and computer program product for identifying unwanted activity utilizing a honeypot device accessible via VLAN trunking
Publication Date: 2013.09.03 MCAFEE LLC
  • US8528092B2 patent drawing
  • US8528092B2 patent drawing
  • US8528092B2 patent drawing

AI summary

A system, method, and computer program product are provided for identifying unwanted activity utilizing a honeypot accessible via virtual local area network (VLAN) trunking. In use, a honeypot device is allowed to be accessed via VLAN trunking. Furthermore, unwanted data is identified, utilizing the honeypot device.