Proactive Web Application Security via Decoy Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional web application security systems rely on a reactive approach, failing to detect and counter malicious activities proactively, such as attacker profiling, skill evaluation, and real-time response, due to limited visibility into potential threats and vulnerabilities.

Innovation Solution

A proactive administrative proxy server injects decoys into executing web applications to identify and counter attempted exploitation, enabling real-time security measures and data collection for future threat anticipation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security systems (firewalls, IDS) are deployed to protect web applications, then basic attack detection is provided, but real-time proactive security measures and attacker profiling capability are lost

Engineering Contradiction:
Improveweb application securityVSAvoidreal-time threat detection and response capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent embeds decoys into the web application before attacks occur. These decoys are designed to be discovered and exploited by attackers in real-time, enabling proactive detection and response before actual vulnerabilities are exploited. The decoys serve as preliminary security measures that anticipate and prepare for potential attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a proactive administrative proxy server as an intermediary between the web application and the attacker. This proxy server receives requests, detects decoy interactions, and provides real-time responses including attacker profiling and counter-measures, thereby mediating the security response without blocking legitimate traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If reactive security systems are used to detect malicious activity, then attack detection is provided, but visibility into attacker behavior, skill level, and attack attempts is limited

Engineering Contradiction:
Improveattacker behavior visibilityVSAvoidattacker profiling data
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the proactive administrative proxy server continuously monitors attacker interactions with decoys, collects data on attack methods, skill levels, and patterns, and uses this information to refine real-time responses and improve future security measures. This feedback loop enables comprehensive attacker profiling.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates copies of real vulnerabilities in the form of decoys. These decoys replicate the appearance and behavior of actual vulnerabilities, allowing attackers to interact with them and reveal their attack methodologies. The decoys serve as informational copies that provide insights into attacker capabilities without exposing real system weaknesses.

Inventive Principle:
Principle #26Copying

3Productivity

If decoys are injected into web applications to enable proactive security measures, then real-time attacker detection is improved, but application complexity increases

Engineering Contradiction:
Improvereal-time security response capabilityVSAvoidweb application structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the security function from the core web application by using a separate proactive administrative proxy server. The proxy server handles all decoy management, attacker detection, and response logic, while the web application simply serves its primary function. This segmentation maintains real-time security capabilities while minimizing impact on application structure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8949988B2Methods for proactively securing a web application and apparatuses thereof
Publication Date: 2015.02.03 JUNIPER NETWORKS INC
  • US8949988B2 patent drawing
  • US8949988B2 patent drawing
  • US8949988B2 patent drawing

AI summary

A method, non-transitory computer readable medium, and apparatus that proactively secures a web application includes injecting one or more decoys into an executing web application. An attempt to exploit one of the one more injected decoys in the executing application is identified. At least one action to secure the executing application from the attempted exploitation is performed.