Automatic deployment of breadcrumbs

The automatic deployment of deception breadcrumbs addresses inefficiencies in static deployment by adapting to attack phases, optimizing resource use, and enhancing cyber defense deception effectiveness.

WO2025180750A1PCT designated stage Publication Date: 2025-09-04BRITISH TELECOM PLC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/052274
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-28
Filing Date
2025-01-29
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

Existing cyber defense deception systems face inefficiencies due to static deployment of breadcrumbs, which impact computational processing and memory usage, and fail to adapt dynamically to different phases of an attack cycle.

Method used

An automatic deployment system that analyzes network traffic to determine the appropriate phases of an attack and deploys deception breadcrumbs only when needed, using machine learning and deep learning to optimize resource use and enhance deception effectiveness.

Benefits of technology

Enhances cyber defense deception by optimizing resource use and improving efficiency by deploying breadcrumbs dynamically based on attack phases, reducing computational and memory impact while enhancing security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025052274_04092025_PF_FP_ABST
    Figure EP2025052274_04092025_PF_FP_ABST
Patent Text Reader

Abstract

Cyber defensive deception (CDD) encompasses a range of techniques which can be used to mislead and deceive an attacker. A cyber deception method comprises detecting a network intrusion, determining one or more deception breadcrumbs to deploy in response to the network intrusion, and deploying the one or more deception breadcrumbs in response to the intrusion.
Need to check novelty before this filing date? Find Prior Art

Description

AUTOMATIC DEPLOYMENT OF BREADCRUMBS

[0001] The present invention relates to a method of deploying a cyber defence deception strategy.BACKGROUND

[0002] Deception relates to manipulating an attacker’s beliefs to mislead their decision making, i.e. inducing the attacker to act sub-optimally so as to delay their attack and save the assets. Deception technology typically implements traps to monitor the suspicious activities in an attack chain and provide an understanding of the attacker’s behaviour and intentions.

[0003] The examples described herein are not limited to examples which solve problems mentioned in this background section.SUMMARY

[0004] Examples of preferred aspects and embodiments of the invention are as set out in the accompanying independent and dependent claims.

[0005] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0006] According to a first aspect there is a computer-implemented cyber deception method comprising: detecting a network intrusion; determining one or more deception breadcrumbs to deploy in response to the network intrusion; and deploying the one or more deception breadcrumbs in response to the intrusion.

[0007] In some examples, determining one or more deception breadcrumbs to deploy comprises determining one or more target nodes, wherein the one or more deception breadcrumbs are deployed to the target nodes.

[0008] In some examples, determining one or more deception breadcrumbs to deploy comprises: searching a breadcrumb database to identify one or more suitable breadcrumbs; responsive to identifying one or more suitable breadcrumbs, retrieving the one or more suitable breadcrumbs; responsive to identifying no suitable breadcrumbs, generating one or more new breadcrumbs and storing the one or more new breadcrumbs in the breadcrumb database.

[0009] In some examples, deception breadcrumbs are determined based on at least one of in attacker identity, an attack type and an attack target.

[0010] In a second aspect, there is a computer system including a processor and memory storing computer program code for performing the steps of: detecting a network intrusion; determining one or more deception breadcrumbs to deploy in response to the network intrusion; and deploying the one or more deception breadcrumbs in response to the intrusion.

[0011] In some examples, determining one or more deception breadcrumbs to deploy comprises determining one or more target nodes, wherein the one or more deception breadcrumbs are deployed to the target nodes.

[0012] In some examples, determining one or more deception breadcrumbs to deploy comprises: searching a breadcrumb database to identify suitable breadcrumbs; responsive to identifying suitable breadcrumbs, retrieving the suitable breadcrumbs; responsive to identifying no suitable breadcrumbs, generating new breadcrumbs and storing the new breadcrumbs in the breadcrumb database.

[0013] In some examples, deception breadcrumbs are determined based on at least one of in attacker identity, an attack type and an attack target.

[0014] In a third aspect, there is a computer program element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer to perform the steps of: detecting a network intrusion; determining one or more deception breadcrumbs to deploy in response to the network intrusion; and deploying the one or more deception breadcrumbs in response to the intrusion.

[0015] In some examples, determining one or more deception breadcrumbs to deploy comprises determining one or more target nodes, wherein the one or more deception breadcrumbs are deployed to the target nodes.

[0016] In some examples, determining one or more deception breadcrumbs to deploy comprises: searching a breadcrumb database to identify suitable breadcrumbs; responsive to identifying suitable breadcrumbs, retrieving the suitable breadcrumbs; responsive to identifying no suitable breadcrumbs, generating new breadcrumbs and storing the new breadcrumbs in the breadcrumb database.

[0017] In some examples, deception breadcrumbs are determined based on at least one of in attacker identity, an attack type and an attack target.

[0018] It will also be apparent to anyone of ordinary skill in the art, that some of the preferred features indicated above as preferable in the context of one of the aspects of the disclosed technology indicated may replace one or more preferred features of other ones of the preferred aspects of the disclosed technology. Such apparent combinations are not explicitly listed above under each such possible additional aspect for the sake of conciseness.

[0019] Other examples will become apparent from the following detailed description, which, when taken in conjunction with the drawings, illustrate by way of example the principles of the disclosed technology.BRIEF DESCRIPTION OF THE DRAWINGS

[0020] FIG. 1 is a schematic diagram of a cyber defense deception deployment architecture;

[0021] FIG. 2 is a schematic diagram of an automatic breadcrumbs deployment system;

[0022] FIG. 3 is a schematic diagram of how the automatic breadcrumbs deployment system fits within the cyber defense deception deployment architecture; and

[0023] FIG. 4 is a flow diagram of an exemplary method of operation of automatic breadcrumbs deployment.

[0024] The accompanying drawings illustrate various examples. The skilled person will appreciate that the illustrated element boundaries (e.g., boxes, groups of boxes, or other shapes) in the drawings represent one example of the boundaries. It may be that in some examples, one element may be designed as multiple elements or that multiple elements may be designed as one element. Common reference numerals are used throughout the figures, where appropriate, to indicate similar features.DETAILED DESCRIPTION

[0025] The following description is made for the purpose of illustrating the general principles of the present technology and is not meant to limit the inventive concepts claimed herein. As will be apparent to anyone of ordinary skill in the art, one or more or all of the particular features described herein in the context of one embodiment are also present in some other embodiment(s) and / or can be used in combination with other described features in various possible combinations and permutations in some other embodiment(s).

[0026] A key concept of deception is to manipulate an attacker’s beliefs to mislead their decision making, inducing them to act sub-optimally thus delaying attacks and save the assets. Deception technology can form a stand-alone platform that implements effective traps to monitor the suspicious activities in the attack chain and provides deep understanding of the attacker’s behaviour. Cyber defensive deception(CDD) encompasses a range of techniques which can be used to mislead and deceive an attacker. CDD protects the organization's important data by deploying various artefacts of deception technologies such as decoys, breadcrumbs, baits and lure.

[0027] To implement these deception techniques, four deceptive artefacts are typically required: decoys, breadcrumbs, baits and lure. Decoys are IT assets that either use real licensed operating system software or are emulations of real devices. Examples of decoys include: servers, workstations, applications, printers, loT / OT / ICS, network services, mailbox, AD forest. Breadcrumbs are deception assets deployed on to the devices of real environment and used to divert / lead to decoys. Examples of breadcrumbs include: registry entries, files and folders, memory credentials, browser history, mapped drive, credential store. Baits are deception assets used as host tripwires. Examples of baits include: beaconing docs, database rows, ransomware, files and folders, DNS records, processes, directory browsing, tainted tools, fake AV, listeners. Lures are the deception assets to make the traps (decoys, breadcrumbs, and baits) attractive for adversaries. Examples of lures include: vulnerability, misconfigurations, default / weak credentials, weak permission, registration in catalogues like AD, entity names.

[0028] There are numerous frameworks to model and understand attacker’s behaviour. These frameworks provide a better understanding of adversaries’ capabilities, intentions, and potential points of weakness to develop more effective defensive postures. The concept is to use an end-to-end cyberattack taxonomy as a reference to gain intruder perspective. Two well-known frameworks are Lockheed Martin’s Cyber Kill Chain and MITRE ATT&CK.

[0029] The cyber kill chain is a set of steps that track the stages of a cyberattack, beginning with reconnaissance and ending with data exfiltration. Cyber Kill has a clearly defined linear sequence of phases.

[0030] MITRE ATT&CK steers away from preventative methods and rather uses detection and response solutions. The MITRE ATT&CK framework is centred on the concept of adversary tactics and techniques. A tactic is what an attacker is trying to achieve. A technique is how an attacker is achieving unauthorised access to a system or a network. The MITRE ATT&CK framework is a matrix of intrusion techniques that is not confined to a specific order of operations.

[0031] ATT&CK and the Cyber Kill Chain are complementary. ATT&CK sits at a lower level of definition to describe adversary behaviour than the Cyber Kill Chain. ATT&CK Tactics are unordered and may not all occur in a single intrusion because adversary tactical goals can change throughout an operation, whereas the Cyber Kill Chain uses ordered phases to describe high-level adversary objectives.

[0032] The present invention provides a system for an automatic deployment of a deception artefact, specifically a breadcrumb, after analysing the network traffic during at least one phase of an attack cycle. Automatic breadcrumbs deployment may form part of a Cyber Defence Deception (CDD) security system.

[0033] An increased number of deceptive artefacts will increase the security but in terms of cyber security more deceptive artefacts deployment will also impact the computational processing and memory usage that will impact overall efficiency of the network. Thus, deceptive artefacts should be deployed as and when required for CDD.

[0034] In some examples, the present invention involves the use of deceptive strategies to automatically deploy the breadcrumbs based on attack phases of attack analysis frameworks such as reconnaissance phase of kill chain or initial access phase of a MITRE ATT&CK framework. Existing solutions consider only static deployment of breadcrumbs on a machine or automatic deployment of breadcrumbs on a group of machines based on static information.

[0035] An automatic breadcrumbs deployment approach has many benefits including: (i) design new breadcrumbs automatically as needed after network analysis, (ii) optimal use of a real asset by installing only the required breadcrumbs, (iii) modify the installed breadcrumbs only if needed, (iv) respond to all phases of an attack cycle and (v) improve overall efficiency of CDD.

[0036] Figure 1 is a block diagram of an exemplary computer architecture 100 comprising four modules 101 -104 that are configured individually.

[0037] An environment analysis module 101 is associated with the environment information 105 provided as input by a user so as to facilitate the design of deception strategy. The environment analysis explores the environment information 105 as input by the user(s) in a variety of ways, including segregating the information in useful blocks, extracting the vulnerabilities / risks could be exploited by an attacker, and / or categorise devices in groups.

[0038] A deception strategy module 102 is responsible for designing the deception strategy based on input from environmental analysis module 101 . In some examples, the deception strategy module 102 additionally designs the deception strategy on the basis of the deception constraints 106. There are several possible deception strategies that can be employed, such as resolving the vulnerabilities detected and informed by the environment analysis module 101 or ranking the device groups. Another possible deception strategy, and the subject of the present invention, is calculating the number of deception artefacts needed to enhance the environment security. In some examples, a deception effectiveness metric is utilised by the deception strategy module 102.

[0039] A deception deployment module 103 creates and deploys the deception artefacts, based on the deception strategy.

[0040] A deception analysis module 104 evaluates the deception deployment module 103 so that any required improvements are recorded.

[0041] In some examples, there is a human in the loop 108 that operates to verify the result of each module and perform the changes / updates if required. In some examples, the human in the loop 108 is not a human user, but instead a model programmed to verify the results of each module. The human in the loop I model 108 may verify the result / solution of each module by a variety of methods, including: populating a database by users or organization data and / or previous recording to check the generated reactions by each module, matching the threats to reduce false positives, and / or confirming the deception artefacts and connections.

[0042] FIG. 2 is an exemplary schematic diagram of an automatic breadcrumb deployment system. The automatic breadcrumb deployment system consists of 5 main components: Network analysis, Match Breadcrumbs, Create Breadcrumbs, Populate Breadcrumb Database and Deploy Breadcrumbs. The Network Analysis component analyses the traffic to capture any suspicious activity to identify at least one targeted host and match attack stages to the activity. The Match Breadcrumbs component checks the existing breadcrumbs in the database for the identified activity. In the scenario that no breadcrumbs are matched with the identified activity, new breadcrumbs are created by the Create Breadcrumbs component. The Populate Breadcrumb Database component uploads the new created breadcrumb to the database for future use if required. The Deploy Breadcrumbs component deploys the specific breadcrumb on the targeted host(s).

[0043] Fig. 3 shows how the breadcrumbs automatic deployment components are placed in modules of the CDD architecture. The network analysis component is part of the Environment Analysis, the Breadcrumb matching is part of Deception Strategy and the breadcrumb creation and deployment components form part of the Deception Deployment. The new breadcrumb is populated to the breadcrumb database in Validation module (which may be a human in the loop).

[0044] Fig. 4 is a flowchart that represents exemplary implementation of the automatic deployment of breadcrumbs. The captured network traffic is analysed and, based on the phase where adversary behaviour is detected, appropriate breadcrumb information is considered. If similar information breadcrumb is available in a breadcrumb database database, that breadcrumb is installed at the host where needed. Otherwise, a new breadcrumb is generated and uploaded to the breadcrumb database.

[0045] In one example, in a Reconnaissance phase, an attacker may attempt to target a specific database such as MySQL Database. For that reason, the attacker perform a port scan to search for the port number the MySQL Database is listening to. The attacker may then try to perform an application investigation to detect whether the application version in that phase can detect the port scanning for a specific port number and type of application the attacker is looking for, and based on that then the automatic breadcrumb deployment system can create at least one breadcrumb for the credentials of the MySQL with an application access policy and set said breadcrumb(s) in the machines the attacker has access to. Therefore, based on the IP address range the attacker has been scanning and set of subnets the attacker was able to scan, the system can limit the range of the machines that the breadcrumbs with fake MySQL information are spread to.

[0046] In another example in a kill chain stage “initial Access”, an attacker will attempt to gain remote access to the system to run a command on the system. By analysing the traffic and detecting Remote Access for command execution, the system of the present invention will automatically create a fake PowerShell script to specific systems the attacker is trying to access. In some examples, the PowerShell breadcrumbs may have limited access and may simply capture the attacker commands without executing the actual malicious commands or scripts on the system. This has a similar advantage as the reconnaissance phase example as only required breadcrumbs are deployed based on accessed traffic monitoring. This in turns reduces the amount of resources required on a machine to run all possible breadcrumbs, and limits the number of machines required to spread the breadcrumbs to only the machines visible by the attacker based on the scanning range of the attacker.

[0047] By analysing the various phases of adversary behaviour analysis frameworks, only the required breadcrumbs are automatically deployed on the fly to improve the deception effectiveness for CDD. The automatic breadcrumb deployment system may employ various advanced techniques such as machine learning or deep learning to select the optimal features to facilitate breadcrumb design.

[0048] The steps of the methods described herein may be carried out in any suitable order, or simultaneously where appropriate. The arrows between boxes in the figures show one example sequence of method steps but are not intended to exclude other sequences or the performance of multiple steps in parallel. Additionally, individual blocks may be deleted from any of the methods without departing from the spirit and scope of the subject matter described herein. Aspects of any of the examples described above may be combined with aspects of any of the other examples described to form further examples without losing the effect sought. Where elementsof the figures are shown connected by arrows, it will be appreciated that these arrows show just one example flow of communications (including data and control messages) between elements. The flow between elements may be in either direction or in both directions. Where the description has explicitly disclosed in isolation some individual features, any apparent combination of two or more such features is considered also to be disclosed, to the extent that such features or combinations are apparent and capable of being carried out based on the present specification as a whole in the light of the common general knowledge of a person skilled in the art, irrespective of whether such features or combinations of features solve any problems disclosed herein. In view of the foregoing description it will be evident to a person skilled in the art that various modifications may be made within the scope of the invention.

Claims

CLAIMS1 . A computer-implemented cyber deception method comprising: detecting a network intrusion; determining one or more deception breadcrumbs to deploy in response to the network intrusion, wherein a deception breadcrumb is a deception assets deployed on to a device and used to lead to decoys; and deploying the one or more deception breadcrumbs in response to the intrusion.

2. The method of claim 1 , Wherein determining one or more deception breadcrumbs to deploy comprises determining one or more target nodes, wherein the one or more deception breadcrumbs are deployed to the target nodes.

3. The method of claim 1 or 2, wherein determining one or more deception breadcrumbs to deploy comprises: searching a breadcrumb database to identify one or more suitable breadcrumbs; responsive to identifying one or more suitable breadcrumbs, retrieving the one or more suitable breadcrumbs; responsive to identifying no suitable breadcrumbs, generating one or more new breadcrumbs and storing the one or more new breadcrumbs in the breadcrumb database.

4. The method of any preceding claim, where the one or more deception breadcrumbs are determined based on at least one of an attacker identity, an attack type and an attack target.

5. A computer system including a processor and memory storing computer program code for performing the steps of any preceding claim.

6. A computer program element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer to perform the steps of a method as claimed in any of claims 1 to 4.

Citation Information

Patent Citations

  • Deception defense method and device, medium and computing equipment

    CN116781383A

  • Cyber security deception system

    GB2606591A

  • Procedures for Improving Security in an Electronic Communications Network

    US20220353278A1