Automated Honey Token Deployment for Cloud Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for deploying honey tokens in remote computing resource systems are manual and labor-intensive, making them cumbersome and potentially ineffective, as attackers may recognize fictitious resources and adjust their behavior accordingly, limiting threat intelligence gathering.

Innovation Solution

The technology automates the generation and deployment of honey tokens by allocating provisioned resources with corresponding access credentials and creating data entries in a token mapping store, enabling efficient intrusion detection and threat intelligence collection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual creation and deployment of honey tokens is used, then administrators can deploy honey tokens, but the process becomes complicated and onerous, discouraging or limiting administrators from utilizing honey tokens

Engineering Contradiction:
Improveease of honey token deploymentVSAvoidcomplexity of honey token management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically generating and deploying honey tokens without requiring manual administrator intervention. The automated system creates honey tokens, assigns them to resource modules, and monitors for access attempts, eliminating the need for administrators to manually manage the complex process of honey token deployment and monitoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-generating and pre-deploying honey tokens to resource modules before any attack occurs. The automated system prepares honey tokens in advance and configures them within the cloud environment, so that when attacks happen, the detection mechanism is already in place and operational.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If fictitious honey tokens are used, then legitimate users are unlikely to attempt access, but attackers may recognize the fictitious nature and avoid further access attempts, limiting threat intelligence gathering

Engineering Contradiction:
Improveeffectiveness of honey token in detecting malicious activityVSAvoidloss of threat intelligence
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system changes the parameter of honey token authenticity by using real, functional resources instead of fictitious ones. The honey tokens are actual resource modules with legitimate access credentials that could be used by attackers. This parameter change ensures that when attackers access these tokens, they are using real resources, allowing the system to gather comprehensive threat intelligence about attacker methods and patterns.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automated generation and deployment of honey tokens is implemented, then deployment efficiency improves, but the system complexity increases

Engineering Contradiction:
Improveproductivity of honey token deploymentVSAvoidcomplexity of automated system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves universality by creating a multi-functional platform that handles honey token generation, deployment, monitoring, and threat intelligence collection through a single automated system. The same system infrastructure serves multiple purposes: creating honey tokens, assigning them to various resource modules, monitoring access logs, detecting attacks, and gathering threat intelligence, thereby improving productivity without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12289321B2Automated generation and deployment of honey tokens in provisioned resources on a remote computer resource platform
Publication Date: 2025.04.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12289321B2 patent drawing
  • US12289321B2 patent drawing
  • US12289321B2 patent drawing

AI summary

Methods, systems, and media are shown for creating and deploying honey tokens for intrusion detection in a remote computing resource system. Resource modules provisioned for a tenant are identified for intrusion detection. For each identified resource modules, a provisioned resource having a corresponding access credential is allocated and the access credential is deployed in the identified resource module. A data entry is created in a token mapping store that identifies the access credential and the resource module. Access logs are scanned to detect access attempts. For each access attempt, the token mapping store is searched for a data entry with an access credential that matches the access credential of the access attempt. If found, an alert is generated that includes the identified resource module of the matching data entry.