Automated Session Analysis for Decoy Server Honeypots
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for analyzing actions of computer hackers connected to decoy servers are manual and time-consuming, leading to delays in characterizing misdeeds and informing relevant authorities, especially during increased cyber threats.
Innovation Solution
Implementing an automated system that captures images of a user's session asynchronously upon predefined commands, transcribes them into text using OCR tools, and analyzes for specific character strings to characterize actions quickly and accurately.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual analysis of hacker recordings is performed, then analysis accuracy is maintained, but analysis time becomes excessively long and productivity decreases
Solution Approach 1:
The patent replaces the manual mechanical analysis process with an automated computer-based system that uses optical character recognition (OCR) to transcribe video recordings into text, then automatically analyzes the text to characterize hacker actions. This substitution of mechanical human analysis with automated computational processes directly resolves the contradiction by dramatically increasing analysis speed while maintaining consistent analysis quality through systematic text processing.
Solution Approach 2:
The system enables self-service analysis by automatically processing hacker recordings without requiring continuous human intervention. The automated pipeline transcribes recordings, extracts relevant information, and characterizes actions independently, freeing operators from tedious manual review while maintaining analysis capabilities. This self-service mechanism resolves the time loss contradiction by enabling parallel processing of multiple recordings simultaneously.
2Loss of information
If all text in recordings is transcribed using OCR, then complete information is captured, but data volume becomes unmanageably large creating storage and processing problems
Solution Approach 1:
The patent extracts only the essential information needed for characterization from the transcribed text, rather than processing or storing all transcribed content. The system identifies and extracts specific action descriptors and key information relevant to hacker behavior classification, discarding redundant data. This extraction principle resolves the contradiction by maintaining complete information capture during transcription while managing data volume through selective extraction of only the necessary elements for analysis.
Solution Approach 2:
The analysis process segments the transcribed text into distinct actionable elements and characteristics, processing them in manageable units. By dividing the continuous text stream into discrete action segments that can be independently characterized and classified, the system handles large volumes of transcribed data efficiently without being overwhelmed by the total data quantity, thus resolving the information completeness versus data volume contradiction.
3Quantity of substance
If video stream is sampled at regular intervals for transcription, then data volume is reduced, but some malicious acts occurring between samples may be missed
Solution Approach 1:
The patent maintains continuous monitoring and transcription of the video stream without gaps, ensuring that all hacker actions are captured regardless of when they occur. The system processes the video stream continuously and transcribes text as it appears, eliminating the blind spots that would exist with periodic sampling. This continuous action approach resolves the contradiction by ensuring complete detection of malicious acts while managing data volume through efficient real-time processing rather than accumulation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to an automated analysis device (60) for the actions of a user remotely connected to a server (14) comprising a capture tool (61) for at least one image of a session of said user, said capture tool (61) being controlled asynchronously by the detection of the use of at least one predefined command; said analysis device (60) comprising: - a transcription tool (62) into text of the at least one image captured by the capture tool (61), - an analysis tool (63) enabling the detection of at least one predetermined string of characters within the text captured by the transcription tool (62); and - a characterization tool (64) of at least one action performed by the user based on said at least one detected string of characters.