Canary Records for Cloud Data Access Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based service providers face challenges in detecting and preventing the exfiltration of sensitive data from their computing resources, as malicious entities can attempt to access and steal sensitive information stored in these systems.
Innovation Solution
The implementation of canary records, which are decoy data sets indistinguishable from real records, is used to monitor and detect improper access events. These canary records are generated and placed alongside actual client records, allowing service providers to identify suspicious access and take preventive measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional data storage and access monitoring methods are used, then system simplicity is maintained, but the ability to detect malicious data access is insufficient
Solution Approach 1:
The patent introduces canary records as intermediary decoy data elements that are inserted among real data records. These canary records serve as mediators to detect malicious access attempts - when accessed, they trigger alerts without exposing actual sensitive data. This intermediary mechanism enhances detection capability while maintaining relative system simplicity.
Solution Approach 2:
The patent creates copies of real data records in the form of canary records that mimic the structure and appearance of legitimate data. These copied decoy records are indistinguishable from real data to attackers but are tracked by the system to detect unauthorized access patterns, thereby improving reliability without significantly increasing complexity.
2Reliability
If canary records are inserted among real data records, then the ability to detect malicious access is improved, but data structure complexity increases
Solution Approach 1:
The patent applies local quality by making canary records locally indistinguishable from real records in terms of data structure and format, while globally they serve a different detection function. Each canary record is designed with specific local characteristics that match real data patterns, enabling accurate detection without requiring complete restructuring of the data system.
Solution Approach 2:
The patent utilizes parameter changes by modifying certain attributes of canary records (such as metadata flags or tracking identifiers) that are imperceptible to attackers but detectable by the system. This allows the data structure to maintain its original form while incorporating detection capabilities through subtle parameter variations.
3Reliability
If canary records are made indistinguishable from real records, then detection effectiveness is improved, but the difficulty of identifying canary records increases
Solution Approach 1:
The patent employs hidden identifiers or metadata markers within canary records that act as intermediaries - invisible to attackers attempting to access data but detectable by the monitoring system. This allows canary records to remain indistinguishable from real records to malicious users while enabling the system to easily identify and track them for detection purposes.
Data Source
AI summary
This disclosure describes techniques implemented partly by a service provider to monitor a cloud-based service by generating and placing canary records in storage locations along with real records to identify improper access events of the records or other data. The service provider may detect an access event where records in a storage location were accessed, and determine whether a canary record was accessed. If a canary record was accessed, the service provider may determine that the access event was potentially performed by a malicious entity because authorized users generally may not have reason to access a canary record when utilizing their cloud-based service. The service provider may generate canary records that are difficult to identify by a malicious entity, and may position canary records in the storage locations to help ensure that the canary records are accessed by a malicious entity during an improper access event.


