Virtual Traffic Decoys for Network Security Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions rely on defensive approaches that spend significant compute cycles continuously analyzing transactions for suspicious activity, while attackers wait for vulnerabilities to launch attacks, resulting in an inefficient use of resources.

Innovation Solution

Implementing a virtual traffic decoy system that generates and sends enticing network traffic to potential attackers, using contextual information to bait them into revealing their malicious intentions, thereby reducing the waiting time for both security devices and attackers and avoiding real vulnerability exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security solutions continuously analyze each transaction against configured or learned rules to identify suspicious activity, then detection capability is improved, but compute cycle consumption increases significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidcompute cycle consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system pre-generates multiple decoy traffic profiles representing different vulnerability states before actual attacks occur. These profiles are prepared in advance and stored for rapid deployment, eliminating the need to create analysis rules on-demand during security incidents.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates synthetic copies of vulnerable traffic patterns (decoy profiles) that mimic real vulnerability signatures without containing actual vulnerabilities. These copied profiles are used to bait attackers, allowing security analysis without exposing real systems to risk.

Inventive Principle:
Principle #26Copying

2Measurement precision

If network security solutions wait for attacks to be identified before responding, then false positive reduction is improved, but response time worsens

Engineering Contradiction:
Improveattack identification accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system proactively deploys decoy traffic profiles that anticipate potential attack vectors before actual attacks materialize. By having defensive measures already in place and actively monitoring for attacks against the decoys, the system eliminates the waiting period between attack occurrence and security response.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system continuously monitors attacker responses to decoy profiles and uses this feedback to refine and update the decoy profile collection. This creates a closed-loop system where detection accuracy improves over time while maintaining rapid response capability through active monitoring.

Inventive Principle:
Principle #23Feedback

3Reliability

If attackers wait for vulnerable clients to make connections before launching attacks, then attack success rate is improved, but the time attackers spend waiting increases

Engineering Contradiction:
Improveattack success rateVSAvoidattacker waiting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system proactively presents decoy vulnerability profiles to potential attackers before real vulnerabilities are exploited. This preliminary defensive action forces attackers to either reveal themselves by attacking the decoys or abandon their attempts, eliminating the passive waiting period attackers would otherwise experience.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If network security devices continuously identify and classify suspicious activity, then security monitoring quality is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity monitoring qualityVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system replaces complex real-time analysis of actual traffic with comparison against pre-generated decoy profiles. Instead of analyzing every transaction against multiple rules, the system matches traffic patterns against known decoy signatures, significantly simplifying the analysis process while maintaining monitoring quality.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11075947B2Virtual traffic decoys
Publication Date: 2021.07.27 CISCO TECHNOLOGY INC
  • US11075947B2 patent drawing
  • US11075947B2 patent drawing
  • US11075947B2 patent drawing

AI summary

A network security method is provided. The method includes obtaining, at a network security device, first network traffic from a network device destined for a potential attacker; determining if the first network traffic is suspicious; when the first network traffic is determined to be suspicious: generating second network traffic based on the context of the network device and the first network traffic; providing the second network traffic to the potential attacker; obtaining, from the potential attacker, third network traffic in response to the second network traffic; and designating the potential attacker as malicious based on the third network traffic is disclosed. An apparatus and one or more non-transitory computer readable storage media are also disclosed.