Optimistic Response Security Mechanism for Port Scan Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer systems face vulnerabilities due to attackers gathering information by scanning ports and user names, allowing them to focus attacks on specific targets, leading to efficient but disruptive and potentially damaging attacks.
Innovation Solution
Implementing a system that detects suspicious behavior, alters the host computer's behavior to provide false positive responses to attackers, and uses imposter services to delay and foil attacks by presenting overwhelming false targets and delaying responses, thereby reducing the efficiency of the attack.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If the host computer system provides accurate responses to port scan requests, then the attacker can efficiently identify and target specific services and users, but the system becomes vulnerable to focused attacks
Solution Approach 1:
The patent inverts the normal response behavior by providing false positive information to attackers. Instead of accurately identifying closed ports and non-existent users, the system deliberately responds as if these targets exist, thereby misleading attackers and protecting the actual system state from exploitation
Solution Approach 2:
The patent converts the harmful port scanning activity into a beneficial security measure. By detecting and responding to scan requests with false information, the system turns the attacker's information-gathering attempt into an opportunity to identify and thwart the attack, thereby protecting the system while maintaining normal operation
2Speed
If the host computer system responds quickly to all connection requests, then legitimate users experience good performance, but attackers can rapidly enumerate services and plan attacks
Solution Approach 1:
The patent implements preliminary detection of scan requests before full processing occurs. By identifying suspicious patterns early in the connection handshake, the system can prepare defensive responses in advance, allowing legitimate traffic to proceed quickly while slowing down detected attack sequences through deliberate response timing
Solution Approach 2:
The patent introduces periodic delays in response timing to detected scan requests. Rather than responding immediately to every connection attempt, the system implements variable delays that disrupt the attacker's ability to rapidly enumerate services, while maintaining normal response times for legitimate users through pattern recognition
3Ease of operation
If the host computer system provides detailed service information, then users can access appropriate services, but attackers can identify vulnerabilities and target specific services
Solution Approach 1:
The patent applies different response qualities to different connection scenarios. For legitimate users, the system provides accurate service information and normal operation. For detected attackers, the system provides false information about service availability and user existence, thereby protecting vulnerability information while maintaining normal service accessibility
Data Source
AI summary
Techniques for improving computer system security by detecting and responding to attacks on computer systems are described herein. A computer system monitors communications requests from external systems and, as a result of detecting one or more attacks on the computer system, the computer system responds to the attacks by modifying the behavior of the computer system. The behavior of the computer system is modified so that responses to communications requests to ports on the computer system are altered, presenting the attacker with an altered representation of the computer system and thereby delaying or frustrating the attack and the attacker.


