Network Labyrinth Redirecting Blocked Traffic to Deter Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems, such as firewalls, are limited in effectively deterring malicious attackers as they often provide valuable information to attackers, allowing them to adapt and eventually gain access, consuming fewer resources and becoming more costly for the attacker to continue the attack.
Innovation Solution
The introduction of a packet inspector and redirector system that interfaces with firewalls and redirects blocked traffic to a labyrinth, forcing attackers to expend resources on a simulated network environment, thereby deterring them without accessing real network resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls block malicious traffic, then network security is improved, but attackers gain information about blocked traffic patterns allowing them to adapt their attacks
Solution Approach 1:
The patent introduces a decoy network environment as an intermediary between the firewall and the attacker's target. Blocked traffic is redirected to this intermediary environment that mimics real network resources, allowing attackers to exhaust their resources against simulated targets rather than gaining information about actual network vulnerabilities.
Solution Approach 2:
The patent creates copies of real network resources in a simulated decoy environment. These copies include virtual servers, databases, and application interfaces that replicate the appearance and behavior of actual network assets, causing attackers to waste resources attacking these replicas instead of the real systems.
2Loss of energy
If attackers are allowed to probe network resources, then they can identify vulnerabilities, but this consumes their resources and deters further attacks
Solution Approach 1:
The patent converts the harmful effect of attacker probing into a beneficial outcome by redirecting probe traffic to decoy resources. The attackers' resource consumption against the decoy environment achieves the security goal of exhausting their capabilities without exposing real network vulnerabilities, thus transforming a harmful interaction into a protective mechanism.
3Reliability
If blocked traffic is simply dropped by firewalls, then network resources are protected, but attackers receive no feedback and may continue with modified attack vectors
Solution Approach 1:
The decoy network environment serves as a mediator that provides controlled feedback to attackers. Instead of simply dropping traffic, the system redirects it to simulated resources that respond in predetermined ways, giving attackers feedback that consumes their resources without revealing information about real network configurations or enabling them to adapt successful attack vectors.
Data Source
AI summary
A system is disclosed for protecting a network against malicious attacks or attempts for unauthorized access. A network is connected to an external network by a number of firewalls. Inspectors detect packets blocked by the firewalls and some or all of the packets are detected to a labyrinth configured to emulated an operational network and response to the packets in order to engage an attacker. Blocked packets may be detected by comparing packets entering and exiting a firewall. Packets for which a corresponding packets are not received within a transit delay may be identified as blocked. Entering and exiting packets may be compared by comparing only header information. A central module may receive information from the inspectors and generate statistical information and generate instructions for the inspectors, such as blacklists of addresses known to be used by attackers.


