Inception Engine for Network Attack Detection and Deception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies face challenges in detecting the beginning of attacks without full network segmentation, leading to issues like false positives and noise on networks, and there is a gap between firewall technology and deception infrastructure.

Innovation Solution

The implementation of an inception engine on network security appliances that monitors sessions between external devices and servers, blocks suspicious traffic, provides deceptive responses to attackers, and redirects them to more capable security devices when a threshold of suspicious activity is confirmed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deception-based platforms are used to detect attacks, then attack detection capability is improved, but false positives increase and network noise increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an inception engine as an intermediary component that sits between the network traffic and the deception platform. This engine pre-processes and qualifies suspicious traffic before forwarding it to the deception infrastructure, thereby reducing false positives and unnecessary noise while maintaining accurate attack detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by having the inception engine analyze and qualify traffic characteristics before the traffic reaches the deception platform. This preliminary qualification step identifies genuine attack patterns and filters out benign traffic, ensuring that the deception platform only engages with confirmed suspicious traffic.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If full network segmentation is implemented to improve security, then attack detection and containment are improved, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidnetwork segmentation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the inception engine a universal component that can be deployed on existing network security appliances without requiring full network segmentation. This multi-functional engine provides attack detection, traffic qualification, and deception coordination across the entire network, eliminating the need for complex segmented architectures while maintaining security effectiveness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If deception platforms are deployed to slow down attacks, then attack mitigation is improved, but resource consumption and system complexity increase

Engineering Contradiction:
Improveattack mitigation capabilityVSAvoiddeception infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The inception engine provides self-service functionality by autonomously analyzing traffic patterns, qualifying suspicious activity, and managing the deception platform engagement without requiring complex external coordination. This self-managing approach reduces the overall system complexity while maintaining effective attack mitigation through coordinated deception responses.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11223635B2Inception of suspicious network traffic for enhanced network security
Publication Date: 2022.01.11 FORTINET INC
  • US11223635B2 patent drawing
  • US11223635B2 patent drawing
  • US11223635B2 patent drawing

AI summary

Systems and methods are described for inception of suspicious network traffic to allow detection of the beginning of common attacks by network security devices, such as NGFWs, UTM appliances and IPS appliances. According to one embodiment, inception engine running on network security appliance protecting a private network monitors a session between an external computing device and a server device associated with the private network. In response to receipt of suspicious traffic from external computing device indicative of an attack sequence, the inception engine blocks the suspicious traffic from reaching the server device and incepts the attack sequence by providing one or more responses to the external computing device, which are selected based on the attack sequence. Further, when the attack is confirmed, the inception engine diverts the traffic to a more capable deception device.