Network Tunneling for Dynamic Deception Mechanism Projection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network deception systems face challenges in efficiently defending networks from threats, particularly when deception mechanisms need to be dynamically configured and managed, especially in scenarios where physical or logical space is limited, and when networks are partially or fully hosted in the cloud, making it difficult to install and centrally administer deception mechanisms.

Innovation Solution

The implementation of a network deception system that uses network tunnels to project deception mechanisms from a remote site into a site network, allowing a network device to be configured as a projection point, connecting to a deception center and selecting deception mechanisms from a deception farm, which can emulate or be physical devices, and appear as legitimate network devices within the site network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deception mechanisms are physically installed in the site network, then they can directly participate in network defense, but physical space and installation complexity are required

Engineering Contradiction:
Improvenetwork defense capabilityVSAvoidinstallation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of deception mechanisms that can be projected into the site network through tunneling, eliminating the need for physical installation while maintaining defensive functionality. The deception mechanisms are instantiated as virtual network nodes that appear legitimate to other network devices.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transitions from physical deployment to virtual deployment by utilizing network tunneling technology. Deception mechanisms are projected into the site network through a remote site, effectively moving the deployment dimension from physical space to virtual network space.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If deception mechanisms are centrally administered, then management is simplified, but cloud-hosted networks make physical access and central administration difficult

Engineering Contradiction:
Improveadministration easeVSAvoidcloud network complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a remote site as an intermediary between the central administration system and cloud-hosted networks. This remote site establishes network tunnels to project deception mechanisms into the cloud network, enabling centralized management without direct physical access to the cloud environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple deception mechanisms are deployed to improve coverage, then network security is enhanced, but device management and configuration become more complex

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal deception mechanism framework where a single virtualized system can project multiple different deception mechanisms into the site network as needed. This multi-functional approach allows flexible deployment of various deception types without managing separate physical systems for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11212315B2Tunneling for network deceptions
Publication Date: 2021.12.28 ACALVIO TECH
  • US11212315B2 patent drawing
  • US11212315B2 patent drawing
  • US11212315B2 patent drawing

AI summary

Provided are systems, methods, and computer-program products for providing network deceptions using a network tunnel. In various implementations, a network device on a first network can be configured as a projection point. A projection point can be configured as one endpoint of a network tunnel. The other end of the network tunnel can terminate at a deception farm. The deception farm can host a second network, where the second network includes network devices configured as deception mechanisms. By assigning a deception mechanism a network address from the first network, the network address and the network tunnel enable the deception mechanism to appear as a node in the first network.