Masquerading Shared Resources to Detect Malicious Network Activity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network security techniques fail to effectively detect and monitor malicious attempts to access non-existent shared resources, which can lead to undetected attacks and lack of valuable information for analysis.

Innovation Solution

A system and method that involves a server with a network interface and processor configured to detect requests for non-existent shared resources, respond with a masqueraded grant of access, and process interactions to identify malicious activity, potentially creating or redirecting the resource to analyze the attacker's behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the server denies access to non-existent shared resources, then security is improved, but the ability to detect and analyze malicious activity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidmalicious activity information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent converts the harmful aspect of attacker requests (which would normally be blocked) into a beneficial opportunity for security analysis. By creating fake shared resources in response to access requests, the system allows malicious activity to manifest fully, generating valuable intelligence about attack patterns, tools, and techniques while maintaining actual security through monitoring and analysis

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Measurement precision

If the server creates fake shared resources to lure attackers, then the ability to detect malicious activity is improved, but device complexity is worsened

Engineering Contradiction:
Improvemalicious activity detectionVSAvoidserver complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component (the fake shared resource creation mechanism) that mediates between the server and potential attackers. This intermediary layer handles the complexity of resource creation, access control, and monitoring, allowing the core server to maintain its primary functions while the intermediary handles the sophisticated detection and analysis tasks

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If the server processes all access requests to non-existent resources, then information about attacker behavior is improved, but loss of time is worsened

Engineering Contradiction:
Improveattacker behavior informationVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies partial action by selectively creating fake shared resources based on specific criteria rather than processing all access requests uniformly. The system identifies suspicious patterns and targets only those requests that exhibit characteristics of malicious activity, thereby gathering valuable information while minimizing the time and resources spent on benign access attempts

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10609075B2Masquerading and monitoring of shared resources in computer networks
Publication Date: 2020.03.31 AKAMAI TECHNOLOGIES INC
  • US10609075B2 patent drawing

AI summary

An apparatus for computer-network security includes a network interface and a processor. The network interface is configured for communicating over a communication network. The processor is configured to detect a request from a first computer to access a non-existent shared resource of a second computer, to send to the first computer, responsively to the request, a response that imitates a genuine grant of access to the non-existent shared resource, so as to initiate an interaction between the first computer and the shared resource, and to process the interaction so as to identify a malicious activity attempted by the first computer.