Network Storage Lure Response for Unauthorized Access Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network storage systems face challenges in detecting and mitigating unauthorized access attempts by malicious actors, as passive monitoring techniques are difficult to implement effectively, allowing potential data breaches and adverse events to go undetected.
Innovation Solution
A method involving a network-connected storage system that transmits a 'lure response' message with attractive information to identify malicious activity, using a lure identifier and query message to detect unauthorized access attempts and trigger remediation actions, such as blocking access or alerting administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If passive monitoring techniques are used to detect unauthorized access attempts, then detection capability is improved, but implementation difficulty increases and system complexity worsens
Solution Approach 1:
Instead of passively monitoring for suspicious activity patterns, the system actively sends lure messages containing fake or misleading information to entice attackers to reveal themselves. This inverts the traditional detection approach from passive observation to active provocation, making the detection mechanism simpler and more effective.
Solution Approach 2:
The system converts the harmful curiosity of attackers into a beneficial detection mechanism. By sending lure messages that appeal to attacker interests, the system transforms what would normally be invisible malicious activity into detectable signals, effectively using the attacker's own motives against them to reveal their presence.
2Difficulty of detecting and measuring
If active lure response messages are transmitted to detect malicious activity, then detection effectiveness is improved, but system performance may be adversely affected
Solution Approach 1:
The system transmits only partial lure messages containing specific enticing information rather than comprehensive data, minimizing the impact on normal system operations while maintaining detection effectiveness. This selective action ensures that the lure mechanism does not overwhelm system resources or interfere with legitimate operations.
Solution Approach 2:
The lure response messages act as intermediaries between the storage system and potential attackers. These messages serve as a buffer that allows the system to probe for malicious activity without directly engaging in harmful interactions, protecting system performance while enabling detection.
3Difficulty of detecting and measuring
If lure identifiers with attractive information are used, then attacker attraction is improved, but false positive risk increases
Solution Approach 1:
The lure messages contain locally tailored enticing information that appears relevant to potential attackers based on their observed behavior patterns or target preferences. This localized customization increases attraction to legitimate attackers while maintaining distinguishability from normal system operations, reducing false positives.
Solution Approach 2:
The system incorporates feedback mechanisms to analyze responses to lure messages and adjust future lure strategies accordingly. By continuously learning from attacker responses, the system refines its lure identifiers to be more attractive to actual threats while minimizing false attraction to benign entities.
Data Source
AI summary
A network-attached storage of a computing system connected to a network may monitor the network for file access commands from equipment of another computing system to identify whether one of the file access commands corresponds to a nefarious attempt to access information stored at the storage. A service, application, or script, running at the storage, may create a fake query and a fake response thereto. The fake query or corresponding response may contain information generated to attract an attacker that may be using the other computing system to passively monitor the network and, upon detecting the attractive, but fake, message information, transmit a request according to an address, or path, or other information that the fake message(s) may include. The service/app/script may notify the computing system that a potential hacker has infiltrated the system when it receives a request for information at the fake address or path.


