Adaptive Cyber Deception Through Decoy File Placement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-deception strategies fail to effectively deter Advanced Persistent Threats (APTs) while minimizing disruption to legitimate network users and resources, as they do not account for evolving network conditions and adversary tactics.

Innovation Solution

A system and method that utilizes surveillance services, user-defined parameters, and machine learning algorithms to generate decoy file content and placement strategies, applying game theoretic optimization to maximize attacker costs and minimize network impact, with continuous deception operations to adapt to changing threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deception objects are deployed strategically within the network to maximize the probability that an APT will steal deception objects rather than legitimate files, then the effectiveness of cyber deception increases, but the complexity of deployment and strategy generation increases

Engineering Contradiction:
Improveeffectiveness of cyber deceptionVSAvoidcomplexity of deployment and strategy generation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically changes parameters such as decoy file locations, content, and placement strategies based on evolving network conditions and adversary tactics. Surveillance services continuously monitor the network state, and the system adjusts deception parameters in real-time to maintain effectiveness without requiring manual reconfiguration of the entire deception infrastructure.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The deception strategy is made dynamic rather than static. The system continuously adapts its deception objects and placement strategies in response to changing network conditions and observed adversary behavior. This dynamic approach allows the system to maintain high effectiveness while the automation handles the complexity of continuous adaptation.

Inventive Principle:
Principle #15Dynamics

2Reliability

If deterrence schemes are implemented to effectively deter cyber-attacks, then security improvement is achieved, but disruption or frustration to legitimate uses of the computing network may increase

Engineering Contradiction:
Improvesecurity improvementVSAvoiddisruption to legitimate uses
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies deception selectively to specific network locations and files rather than implementing blanket security measures across the entire network. By placing decoy objects strategically in specific directories and files based on surveillance data and risk assessment, the system provides targeted security improvement while minimizing impact on legitimate user operations in other parts of the network.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If deception strategies are updated continuously to adapt to changing threats, then the ability to frustrate APTs increases, but the computational resources and time required for strategy generation increase

Engineering Contradiction:
Improveability to adapt to changing threatsVSAvoidtime for strategy generation
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-generating multiple candidate deception strategies and evaluating them using game theoretic models before deployment. Surveillance services continuously monitor the network and pre-compute response strategies, so when an adversary action is detected, the system can quickly select and deploy an appropriate pre-evaluated strategy rather than generating strategies from scratch in real-time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where surveillance services monitor both legitimate network operations and adversary activities, feeding this information back to the deception strategy generator. This feedback mechanism allows the system to adapt to changing threats efficiently by learning from observed patterns, reducing the computational burden of generating strategies for every possible scenario.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12425417B2Systems and methods for generation and implementation of cyber deception strategies
Publication Date: 2025.09.23 THE MITRE CORPORATION
  • US12425417B2 patent drawing
  • US12425417B2 patent drawing
  • US12425417B2 patent drawing

AI summary

Described herein are systems and methods for generating a cyber-deception strategy that adaptively implement a decoy file placement strategy for thwarting malicious activity on a computing network. The systems and methods can include a plurality of surveillance services that can monitor the evolving conditions and states of a target computing network. The information from the external surveillance services can be combined with one or more user defined parameters to serve as inputs to a system that can use the input data to generate a decoy file content and placement strategy so as to effect a cyber-deception strategy. In one or more examples, can identify one or more target objects to use as decoys and use the identified targeted objects as well as information about the target network, to generate a high-level guidelines that will be used to generate one or more deception plans for implementation on the target network.