Scattered Honeypot Servers for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-provider systems face significant security challenges due to exposure to hostile attacks, as they lack control over tenants' security measures and are responsible for security breaches that affect the entire system, despite having no access to tenants' applications or servers.

Innovation Solution

Deploying honeypot servers with multiple IP addresses scattered across tenant IP address ranges to detect, analyze, and mitigate attacks without accessing tenant resources, using these servers to extract attack parameters and apply blocking or reporting rules to secure the cloud-provider system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If honeypot servers are deployed with multiple IP addresses scattered across tenant IP address ranges, then the cloud-provider system can detect and analyze attacks without accessing tenant resources, but the system complexity and resource allocation overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Honeypot servers are deployed as intermediary systems that monitor and analyze network traffic without requiring access to tenant resources. These honeypots act as mediators between the cloud provider's security needs and tenant operations, capturing attack patterns while maintaining tenant isolation and system independence

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud-provider system is segmented into tenant resources and honeypot resources, allowing independent operation and management. The honeypot infrastructure is separated from tenant workloads, enabling security monitoring without compromising tenant performance or access rights

Inventive Principle:
Principle #1Segmentation

2Productivity

If honeypot servers process network traffic to extract attack parameters and apply blocking rules, then real-time attack mitigation is achieved, but processing overhead and network performance impact increase

Engineering Contradiction:
Improveattack mitigation speedVSAvoidprocessing overhead
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The honeypot servers focus processing efforts only on suspicious traffic patterns identified through attack parameter extraction, rather than analyzing all network traffic. By applying blocking rules selectively to confirmed attack patterns, the system achieves effective threat mitigation while minimizing unnecessary processing overhead on legitimate traffic

Inventive Principle:
Principle #16Partial or excessive action

3Area of stationary object

If multiple IP addresses are assigned to honeypot servers scattered across tenant IP ranges, then attack detection coverage is improved, but IP address management and traffic routing complexity increase

Engineering Contradiction:
Improveattack detection coverageVSAvoidIP address management complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

Honeypot servers are configured with multiple IP addresses scattered across different tenant IP ranges, allowing a single honeypot infrastructure to perform universal attack detection across the entire cloud network. This multi-functional deployment enables comprehensive coverage without requiring separate monitoring systems for each tenant or network segment

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10587651B2Protection of cloud-provider system using scattered honeypots
Publication Date: 2020.03.10 AKAMAI TECHNOLOGIES INC
  • US10587651B2 patent drawing
  • US10587651B2 patent drawing

AI summary

An apparatus for securing a cloud-provider system includes one or more network interfaces and one or more processors. The network interfaces are configured for connecting to a network. The processors are configured to allocate resources of the cloud-provider system for use by tenants of the cloud-provider system, to allocate to the tenants one or more Internet Protocol (IP) address ranges, to assign multiple IP addresses, scattered across the IP address ranges, for use by one or more honeypot servers, and to secure the cloud-provider system against hostile attacks, by processing network traffic associated with the assigned IP addresses using at least the honeypot servers.