Masquerading Shared Resources to Detect Malicious Network Activity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer network security techniques fail to effectively detect and monitor malicious attempts to access non-existent shared resources, which can lead to undetected attacks and lack of valuable information for analysis.
Innovation Solution
A system and method that involves a server with a network interface and processor configured to detect requests for non-existent shared resources, respond with a masqueraded grant of access, and process interactions to identify malicious activity, potentially creating or redirecting the resource to analyze the attacker's behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the server denies access to non-existent shared resources, then security is improved, but the ability to detect and analyze malicious activity is worsened
Solution Approach 1:
The patent converts the harmful aspect of attacker requests (which would normally be blocked) into a beneficial opportunity for security analysis. By creating fake shared resources in response to access requests, the system allows malicious activity to manifest fully, generating valuable intelligence about attack patterns, tools, and techniques while maintaining actual security through monitoring and analysis
2Measurement precision
If the server creates fake shared resources to lure attackers, then the ability to detect malicious activity is improved, but device complexity is worsened
Solution Approach 1:
The patent introduces an intermediary component (the fake shared resource creation mechanism) that mediates between the server and potential attackers. This intermediary layer handles the complexity of resource creation, access control, and monitoring, allowing the core server to maintain its primary functions while the intermediary handles the sophisticated detection and analysis tasks
3Loss of information
If the server processes all access requests to non-existent resources, then information about attacker behavior is improved, but loss of time is worsened
Solution Approach 1:
The patent applies partial action by selectively creating fake shared resources based on specific criteria rather than processing all access requests uniformly. The system identifies suspicious patterns and targets only those requests that exhibit characteristics of malicious activity, thereby gathering valuable information while minimizing the time and resources spent on benign access attempts
Data Source
AI summary
An apparatus for computer-network security includes a network interface and a processor. The network interface is configured for communicating over a communication network. The processor is configured to detect a request from a first computer to access a non-existent shared resource of a second computer, to send to the first computer, responsively to the request, a response that imitates a genuine grant of access to the non-existent shared resource, so as to initiate an interaction between the first computer and the shared resource, and to process the interaction so as to identify a malicious activity attempted by the first computer.
