Network Deception via SDN Decoy Resources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network and cyber defense techniques are often robust in one area but lacking in others, making them inadequate for effectively preventing cyber-attacks and protecting sensitive data, as they fail to deceive attackers and divert their attention from real assets.
Innovation Solution
The implementation of software-defined networking (SDN) to generate virtual decoy resources and services within a host network, which are indistinguishable from real resources, using a Decoy Resource Generation and Management module to attract and mislead cyber attackers, thereby disrupting their operations and protecting the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network defense techniques are used, then network security is maintained, but they fail to deceive attackers and divert their attention from real assets
Solution Approach 1:
The patent creates virtual decoy resources that are copies or simulations of real network assets. These decoys replicate the appearance and behavior of legitimate resources, causing attackers to interact with them instead of real assets. The virtual instances are generated using software-defined networking to present convincing fake assets without modifying real ones.
Solution Approach 2:
The SDN controller acts as an intermediary between attackers and network assets. It monitors traffic and dynamically routes attacks toward decoy resources while protecting real assets. The controller mediates all interactions, redirecting malicious traffic to virtual decoys while maintaining normal operations of legitimate services.
2Reliability
If virtual decoy resources are generated using SDN, then real assets are protected from modification, but network traffic monitoring and routing complexity increases
Solution Approach 1:
The SDN controller performs multiple functions: it generates virtual decoy resources, monitors network traffic, analyzes attack patterns, and dynamically routes traffic. This multi-functional approach consolidates complexity into a single centralized controller rather than distributing it across multiple network devices, simplifying overall system management.
Solution Approach 2:
The system automatically generates decoy resources, monitors traffic patterns, and routes attacks without human intervention. The SDN controller self-manages the entire deception process, dynamically creating and managing virtual instances based on real-time network conditions and attack detection, reducing operational complexity.
3Adaptability or versatility
If decoy resources are made highly realistic, then attacker deception is improved, but detection difficulty increases requiring more sophisticated monitoring
Solution Approach 1:
The patent implements varying levels of decoy fidelity tailored to different network assets and threat scenarios. Not all decoys are created with equal complexity; instead, the system adjusts the realism and resource allocation of each decoy based on its intended purpose, the value of protected assets, and detected attack patterns, optimizing the balance between deception effectiveness and system complexity.
Data Source
AI summary
An example apparatus configured to perform network deception may include processing circuitry configured to generate virtual instances of decoy resources residing within a defined host network for presentation to cyber attackers, control at least one software defined network switch to monitor network traffic directed to real and decoy resources of the defined host network, and route network traffic based on detected interactions with the decoy resources. The decoy resources may have differing levels of decoy fidelity, where decoy fidelity indicates a difficulty for a cyber attacker to determine that the resource is a decoy. Additionally, generating the virtual instances of decoy resources may be performed without modification to real assets or real services residing in the defined host network. Furthermore, decoy services may be made to appear on real network assets using software defined networking without modification to the real assets or real services residing in the defined host network.


