Bait Computing Resource Virtualization for Security Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security solutions often fail to detect sophisticated security threats as attackers may deceive these systems, leading to false positives and unnecessary investigations.
Innovation Solution
The implementation of a system that virtualizes a bait computing resource to prevent false positives by hiding it from trusted applications, using an operating system filter driver to monitor and detect attempts to access the resource, and reporting any unauthorized access attempts to administrators for investigation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security solutions monitor all computing resources, then security threat detection capability is improved, but false positive rate increases
Solution Approach 1:
The system segments computing resources into two distinct categories: bait computing resources (virtualized, hidden from trusted applications) and non-bait computing resources (visible to trusted applications). This segmentation allows the security system to monitor only the bait resources for threat detection, while preventing false positives from trusted applications that might otherwise trigger unnecessary alerts on monitored resources.
Solution Approach 2:
The patent introduces a virtualization layer as an intermediary between the bait computing resource and trusted applications. This virtualization layer hides the bait resource from trusted applications, preventing them from generating false positive security alerts, while still allowing the resource to be monitored for actual security threats by the security system.
2Ease of operation
If bait computing resources are made visible to all applications, then ease of operation is improved, but false positive occurrences increase
Solution Approach 1:
The system applies different visibility properties to different application types regarding the bait computing resource. Untrusted applications can access and interact with the bait resource (maintaining local quality of accessibility for security monitoring), while trusted applications are hidden from it (preventing false positives). This localized quality differentiation resolves the contradiction between ease of operation and false positive reduction.
Data Source
AI summary
The disclosed computer-implemented method for monitoring bait to protect users from security threats may include (i) monitoring a bait computing resource to detect attempts to access the bait computing resource, (ii) virtualizing the bait computing resource to prevent a false positive by hiding the bait computing resource from at least one trusted application that has been categorized as safe, (iii) detecting an attempt by a different application to access the virtualized bait computing resource, and (iv) performing a security action to protect a trusted user by reporting the attempt to access the virtualized bait computing resource by the different application. Various other methods, systems, and computer-readable media are also disclosed.


