Bait Computing Resource Virtualization for Security Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security solutions often fail to detect sophisticated security threats as attackers may deceive these systems, leading to false positives and unnecessary investigations.

Innovation Solution

The implementation of a system that virtualizes a bait computing resource to prevent false positives by hiding it from trusted applications, using an operating system filter driver to monitor and detect attempts to access the resource, and reporting any unauthorized access attempts to administrators for investigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security solutions monitor all computing resources, then security threat detection capability is improved, but false positive rate increases

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system segments computing resources into two distinct categories: bait computing resources (virtualized, hidden from trusted applications) and non-bait computing resources (visible to trusted applications). This segmentation allows the security system to monitor only the bait resources for threat detection, while preventing false positives from trusted applications that might otherwise trigger unnecessary alerts on monitored resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between the bait computing resource and trusted applications. This virtualization layer hides the bait resource from trusted applications, preventing them from generating false positive security alerts, while still allowing the resource to be monitored for actual security threats by the security system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If bait computing resources are made visible to all applications, then ease of operation is improved, but false positive occurrences increase

Engineering Contradiction:
Improveaccessibility of bait computing resourceVSAvoidfalse positive rate
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system applies different visibility properties to different application types regarding the bait computing resource. Untrusted applications can access and interact with the bait resource (maintaining local quality of accessibility for security monitoring), while trusted applications are hidden from it (preventing false positives). This localized quality differentiation resolves the contradiction between ease of operation and false positive reduction.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10769275B2Systems and methods for monitoring bait to protect users from security threats
Publication Date: 2020.09.08 CA TECH INC
  • US10769275B2 patent drawing
  • US10769275B2 patent drawing
  • US10769275B2 patent drawing

AI summary

The disclosed computer-implemented method for monitoring bait to protect users from security threats may include (i) monitoring a bait computing resource to detect attempts to access the bait computing resource, (ii) virtualizing the bait computing resource to prevent a false positive by hiding the bait computing resource from at least one trusted application that has been categorized as safe, (iii) detecting an attempt by a different application to access the virtualized bait computing resource, and (iv) performing a security action to protect a trusted user by reporting the attempt to access the virtualized bait computing resource by the different application. Various other methods, systems, and computer-readable media are also disclosed.