Security System Blocking Flanking Attacks via Dynamic Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security systems face difficulties in detecting and neutralizing targeted attacks, particularly spear phishing, due to their reliance on known malware signatures, and are often distracted by decoy denial-of-service attacks, increasing the likelihood of successful targeted attacks on computing systems.
Innovation Solution
Implementing a system that detects denial-of-service attacks and infers secondary targeted attacks by enhancing authentication requirements through software-defined networks, adding a second authentication factor to protect sensitive computing resources, thereby preventing decoy attacks from succeeding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security systems use malware signatures to detect attacks, then known malware can be identified, but zero-day exploits and targeted attacks cannot be detected
Solution Approach 1:
The system proactively increases authentication requirements for sensitive resources when a denial-of-service attack is detected, before the attacker can execute the secondary targeted attack. This preliminary security enhancement prevents the flanking attack strategy from succeeding by raising the barrier to access before the actual exploit attempt occurs.
Solution Approach 2:
An authentication system is interposed between the network and sensitive computing resources when threats are detected. This intermediary layer verifies user credentials and can block access even if the attacker successfully compromises initial access points through spear-phishing or other targeted attacks.
2Ease of operation
If systems administrators focus on responding to denial-of-service attacks, then the decoy attack is addressed, but the secondary targeted attack succeeds due to administrator distraction
Solution Approach 1:
The security system automatically detects denial-of-service attacks and autonomously increases authentication requirements for sensitive resources without requiring administrator intervention. This self-service capability ensures continuous protection even when administrators are distracted by responding to the decoy attack.
Solution Approach 2:
The system continuously monitors network traffic patterns to detect denial-of-service attacks and automatically adjusts authentication requirements in response. This feedback loop enables dynamic security adaptation that operates independently of administrator attention or awareness of the ongoing attack.
3Reliability
If authentication requirements are increased for all resources during an attack, then security is enhanced, but legitimate user access is disrupted
Solution Approach 1:
Increased authentication requirements are applied selectively only to sensitive computing resources that are potential targets of flanking attacks, rather than uniformly to all resources. This localized approach maintains security for critical assets while minimizing disruption to legitimate user access of non-sensitive resources.
Solution Approach 2:
The authentication requirements are dynamically adjusted based on detected attack patterns and threat levels. During active denial-of-service attacks, enhanced authentication is temporarily applied to sensitive resources, and then relaxed when the threat subsides, allowing the system to adapt security measures to current conditions rather than maintaining static high-security settings.
Data Source
AI summary
A computer-implemented method for blocking flanking attacks on computing systems may include (1) detecting a denial-of-service attack targeting a computing network, (2) inferring, based at least in part on detecting the denial-of-service attack, a secondary attack targeting at least one computing resource within the computing network, (3) determining that the computing resource is subject to additional protection based on inferring the secondary attack targeting the computing resource, and (4) protecting the computing resource against the secondary attack by adding an authentication requirement for accessing the computing resource. Various other methods, systems, and computer-readable media are also disclosed.


