Network Device Net Liar Module for Intrusion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network intrusions often begin with attackers gathering information about target devices, exploiting weaknesses to gain unauthorized access, which existing technologies fail to prevent effectively at an early stage.

Innovation Solution

Implementing a network device with a 'net liar' module that transmits disinformation to hide real information, determining untrusted entities based on trust credentials and communication validity, and correlating attacks to unauthorized entities using disinformation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real information of the network device is transmitted to entities, then communication transparency and trust are improved, but network security and vulnerability to attacks deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidinformation transparency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by transmitting disinformation to entities before real attacks occur. The net liar module proactively misleading attackers about the network device's real information (such as open ports, services, and configuration details) in advance, forcing attackers to base their actions on false premises and preventing them from exploiting actual vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component called the 'net liar module' that acts as a mediator between the network device and external entities. This module intercepts information requests from untrusted entities and provides fabricated information instead of real information, thereby protecting the network device while maintaining communication flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If disinformation is transmitted to hide real information, then network security is improved, but communication complexity and system overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the network device functionality into distinct modules: the net liar module for generating disinformation, the trust determination module for assessing entity credibility, and the information collection module for tracking attacks. This segmentation allows each module to perform its specific function independently, managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The net liar module serves as an intermediary layer that handles all information exchange with untrusted entities, preventing direct access to the core network device. This intermediary approach isolates the complexity of disinformation generation from the main system while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If trust determination based on credentials is implemented, then network security is improved, but processing time and computational overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The trust determination module implements partial verification by checking only essential credentials and communication patterns rather than performing exhaustive validation. For suspicious entities, the system performs sufficient trust assessment to identify attackers without over-verifying, thereby reducing processing time while maintaining security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8819777B2Method and apparatus for preventing and analyzing network intrusion
Publication Date: 2014.08.26 LOCKHEED MARTIN CORP
  • US8819777B2 patent drawing
  • US8819777B2 patent drawing
  • US8819777B2 patent drawing

AI summary

Aspects of the disclosure provide a method for preventing and analyzing network intrusion. The method includes receiving by a network device an initial communication from an entity, determining the entity is not trusted based on the initial communication, and transmitting signals to the entity that are indicative of first disinformation of the network device to hide real information of the network device.