Inception Engine for Network Attack Detection and Deception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies face challenges in detecting the beginning of attacks without full network segmentation, leading to issues like false positives and noise on networks, and there is a gap between firewall technology and deception infrastructure.
Innovation Solution
The implementation of an inception engine on network security appliances that monitors sessions between external devices and servers, blocks suspicious traffic, provides deceptive responses to attackers, and redirects them to more capable security devices when a threshold of suspicious activity is confirmed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deception-based platforms are used to detect attacks, then attack detection capability is improved, but false positives increase and network noise increases
Solution Approach 1:
The patent introduces an inception engine as an intermediary component that sits between the network traffic and the deception platform. This engine pre-processes and qualifies suspicious traffic before forwarding it to the deception infrastructure, thereby reducing false positives and unnecessary noise while maintaining accurate attack detection capability.
Solution Approach 2:
The system performs preliminary action by having the inception engine analyze and qualify traffic characteristics before the traffic reaches the deception platform. This preliminary qualification step identifies genuine attack patterns and filters out benign traffic, ensuring that the deception platform only engages with confirmed suspicious traffic.
2Reliability
If full network segmentation is implemented to improve security, then attack detection and containment are improved, but system complexity and deployment difficulty increase
Solution Approach 1:
The patent makes the inception engine a universal component that can be deployed on existing network security appliances without requiring full network segmentation. This multi-functional engine provides attack detection, traffic qualification, and deception coordination across the entire network, eliminating the need for complex segmented architectures while maintaining security effectiveness.
3Reliability
If deception platforms are deployed to slow down attacks, then attack mitigation is improved, but resource consumption and system complexity increase
Solution Approach 1:
The inception engine provides self-service functionality by autonomously analyzing traffic patterns, qualifying suspicious activity, and managing the deception platform engagement without requiring complex external coordination. This self-managing approach reduces the overall system complexity while maintaining effective attack mitigation through coordinated deception responses.
Data Source
AI summary
Systems and methods are described for inception of suspicious network traffic to allow detection of the beginning of common attacks by network security devices, such as NGFWs, UTM appliances and IPS appliances. According to one embodiment, inception engine running on network security appliance protecting a private network monitors a session between an external computing device and a server device associated with the private network. In response to receipt of suspicious traffic from external computing device indicative of an attack sequence, the inception engine blocks the suspicious traffic from reaching the server device and incepts the attack sequence by providing one or more responses to the external computing device, which are selected based on the attack sequence. Further, when the attack is confirmed, the inception engine diverts the traffic to a more capable deception device.


