Network Decoy Emulation for Real-Time Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems, such as antivirus software and firewalls, are limited in their ability to detect malware in real-time and are not effective against new or unknown threats, as they rely on predefined signatures and port blocking, respectively.

Innovation Solution

A method and system that automatically discovers resources on a network, emulates these resources, and uses malware trap sensors to detect and analyze malware interactions, uploading data for analysis and taking actions based on the results, while also monitoring network traffic and assigning severity scores to detected payloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If antivirus software performs periodic scans, then malware detection is achieved, but real-time detection capability is lost

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The system preemptively deploys decoy resources (fake files, emulated services) throughout the network before malware arrives. These pre-positioned traps are designed to attract and capture malware attempts, enabling detection the moment malware interacts with any resource rather than waiting for scheduled scans.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Decoy resources serve as intermediaries between the security system and actual valuable assets. Malware interacts with these harmless fake resources instead of real ones, allowing the system to study malware behavior in controlled environments and detect threats before they reach critical systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If antivirus software uses predefined malware signatures, then known malware detection is achieved, but detection of new unknown malware is prevented

Engineering Contradiction:
Improvedetection reliabilityVSAvoidcapability to detect new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system allows malware to freely interact with decoy resources, converting potentially harmful malware activity into beneficial detection opportunities. By analyzing how malware behaves when attempting to access or modify decoy files and services, the system learns patterns of malicious behavior that indicate new threat types without requiring prior knowledge of specific malware signatures.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system automatically analyzes malware behavior patterns observed during interactions with decoy resources and uses this information to detect and respond to new threat types. The decentralized architecture allows each node to independently learn from local malware encounters and contribute to overall system intelligence.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If firewalls block predefined ports, then access control is achieved, but prevention of malware using open ports is lost

Engineering Contradiction:
Improveaccess control simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the network into multiple zones with decoy resources distributed throughout. Rather than relying on perimeter-based port blocking, each segment monitors its own traffic patterns and malware interactions independently, allowing granular detection of malicious activities regardless of which ports are open.

Inventive Principle:
Principle #1Segmentation

4Reliability

If emulated resources are deployed throughout the network, then malware detection coverage is improved, but system complexity increases

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates simplified copies of valuable network resources as decoys - fake files mimicking real documents, emulated services replicating common applications. These copies contain minimal functionality needed to attract malware interactions while remaining computationally lightweight and easy to deploy across numerous network nodes.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9516054B2System and method for cyber threats detection
Publication Date: 2016.12.06 COMMVAULT SYSTEMS INC
  • US9516054B2 patent drawing
  • US9516054B2 patent drawing
  • US9516054B2 patent drawing

AI summary

A system and method for detecting a cyber-threat according to embodiments of the present invention comprise automatically discovering resources on a network, by a resource detection unit, emulating, by a faked asset creation unit, at least one resource discovered on the network, associating a malware trap sensor with the emulated resource and detecting by the malware trap sensor, a malware related to the emulated resource. The system and method may further comprise uploading data related to the detected malware to a server, analyzing, by the server, uploaded data to produce an analysis result and perform one or more actions based on the analysis result.