Automated Honey Token Deployment for Cloud Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for deploying honey tokens in remote computing resource systems are manual and labor-intensive, making them cumbersome and potentially ineffective, as attackers may recognize fictitious resources and adjust their behavior accordingly, limiting threat intelligence gathering.
Innovation Solution
The technology automates the generation and deployment of honey tokens by allocating provisioned resources with corresponding access credentials and creating data entries in a token mapping store, enabling efficient intrusion detection and threat intelligence collection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual creation and deployment of honey tokens is used, then administrators can deploy honey tokens, but the process becomes complicated and onerous, discouraging or limiting administrators from utilizing honey tokens
Solution Approach 1:
The system performs self-service by automatically generating and deploying honey tokens without requiring manual administrator intervention. The automated system creates honey tokens, assigns them to resource modules, and monitors for access attempts, eliminating the need for administrators to manually manage the complex process of honey token deployment and monitoring.
Solution Approach 2:
The system performs preliminary actions by pre-generating and pre-deploying honey tokens to resource modules before any attack occurs. The automated system prepares honey tokens in advance and configures them within the cloud environment, so that when attacks happen, the detection mechanism is already in place and operational.
2Reliability
If fictitious honey tokens are used, then legitimate users are unlikely to attempt access, but attackers may recognize the fictitious nature and avoid further access attempts, limiting threat intelligence gathering
Solution Approach 1:
The system changes the parameter of honey token authenticity by using real, functional resources instead of fictitious ones. The honey tokens are actual resource modules with legitimate access credentials that could be used by attackers. This parameter change ensures that when attackers access these tokens, they are using real resources, allowing the system to gather comprehensive threat intelligence about attacker methods and patterns.
3Productivity
If automated generation and deployment of honey tokens is implemented, then deployment efficiency improves, but the system complexity increases
Solution Approach 1:
The system achieves universality by creating a multi-functional platform that handles honey token generation, deployment, monitoring, and threat intelligence collection through a single automated system. The same system infrastructure serves multiple purposes: creating honey tokens, assigning them to various resource modules, monitoring access logs, detecting attacks, and gathering threat intelligence, thereby improving productivity without proportionally increasing complexity.
Data Source
AI summary
Methods, systems, and media are shown for creating and deploying honey tokens for intrusion detection in a remote computing resource system. Resource modules provisioned for a tenant are identified for intrusion detection. For each identified resource modules, a provisioned resource having a corresponding access credential is allocated and the access credential is deployed in the identified resource module. A data entry is created in a token mapping store that identifies the access credential and the resource module. Access logs are scanned to detect access attempts. For each access attempt, the token mapping store is searched for a data entry with an access credential that matches the access credential of the access attempt. If found, an alert is generated that includes the identified resource module of the matching data entry.


