Active Decoy Data for Unauthorized Exfiltration Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Despite implementing network security best practices, malicious users can still access and exfiltrate protected data, either internally or externally, exploiting vulnerabilities or using zero-day exploits, making it difficult to detect unauthorized data usage.
Innovation Solution
Deployment of active decoy data within the network that includes executable instructions, designed to entice unauthorized access and instrumented to detect exfiltration, initiating alerts or notifications to a central reporting site with identifying information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security measures (firewalls, credential management) are implemented, then network security is improved, but unauthorized data exfiltration cannot be detected
Solution Approach 1:
The patent embeds executable instructions within decoy data files before deployment. These instructions are pre-configured to detect specific conditions (such as unauthorized copying or execution) and automatically report them. This preliminary embedding of detection capabilities allows the system to identify unauthorized data usage without requiring additional monitoring infrastructure or changing existing security protocols.
Solution Approach 2:
The patent introduces decoy data files as intermediaries between the protected data and potential thieves. These decoy files contain embedded instructions that act as mediators to detect and report unauthorized access. The decoy files serve as a bridge that enables detection capability without requiring direct modification of the actual protected data or complex monitoring systems.
2Difficulty of detecting and measuring
If decoy data with executable instructions is deployed, then detection of data theft is improved, but data structure complexity increases
Solution Approach 1:
The patent combines multiple functions into the decoy data files: they serve as both protective bait and detection mechanisms. The executable instructions are merged directly into the data file structure, eliminating the need for separate monitoring software or complex detection infrastructure. This merging simplifies the overall system architecture while maintaining effective detection capabilities.
Solution Approach 2:
The decoy data files are self-sufficient, containing all necessary executable instructions within their own structure. They automatically detect unauthorized access and generate reports without requiring external monitoring systems or complex infrastructure. This self-service capability reduces system complexity by eliminating the need for additional detection layers.
Data Source
AI summary
Disclosed are various embodiments for active data that tracks usage. The active data includes instructions that are executable by a computing device. The computing device is scanned to identify characteristics of the computing device. The characteristics of the computing device are utilized to determine whether the usage of the active data is authorized. Data is transmitted to a network service, including identifying information for the particular computing device and data that identifies a deployment of the active data.


