Canary Records for Cloud Data Access Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based service providers face challenges in detecting and preventing the exfiltration of sensitive data from their computing resources, as malicious entities can attempt to access and steal sensitive information stored in these systems.

Innovation Solution

The implementation of canary records, which are decoy data sets indistinguishable from real records, is used to monitor and detect improper access events. These canary records are generated and placed alongside actual client records, allowing service providers to identify suspicious access and take preventive measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional data storage and access monitoring methods are used, then system simplicity is maintained, but the ability to detect malicious data access is insufficient

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces canary records as intermediary decoy data elements that are inserted among real data records. These canary records serve as mediators to detect malicious access attempts - when accessed, they trigger alerts without exposing actual sensitive data. This intermediary mechanism enhances detection capability while maintaining relative system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates copies of real data records in the form of canary records that mimic the structure and appearance of legitimate data. These copied decoy records are indistinguishable from real data to attackers but are tracked by the system to detect unauthorized access patterns, thereby improving reliability without significantly increasing complexity.

Inventive Principle:
Principle #26Copying

2Reliability

If canary records are inserted among real data records, then the ability to detect malicious access is improved, but data structure complexity increases

Engineering Contradiction:
Improveaccess detection accuracyVSAvoiddata structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making canary records locally indistinguishable from real records in terms of data structure and format, while globally they serve a different detection function. Each canary record is designed with specific local characteristics that match real data patterns, enabling accurate detection without requiring complete restructuring of the data system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes parameter changes by modifying certain attributes of canary records (such as metadata flags or tracking identifiers) that are imperceptible to attackers but detectable by the system. This allows the data structure to maintain its original form while incorporating detection capabilities through subtle parameter variations.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If canary records are made indistinguishable from real records, then detection effectiveness is improved, but the difficulty of identifying canary records increases

Engineering Contradiction:
Improvedetection effectivenessVSAvoidcanary record identification difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent employs hidden identifiers or metadata markers within canary records that act as intermediaries - invisible to attackers attempting to access data but detectable by the monitoring system. This allows canary records to remain indistinguishable from real records to malicious users while enabling the system to easily identify and track them for detection purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10977379B1Utilizing canary data to identify improper data access
Publication Date: 2021.04.13 AMAZON TECH INC
  • US10977379B1 patent drawing
  • US10977379B1 patent drawing
  • US10977379B1 patent drawing

AI summary

This disclosure describes techniques implemented partly by a service provider to monitor a cloud-based service by generating and placing canary records in storage locations along with real records to identify improper access events of the records or other data. The service provider may detect an access event where records in a storage location were accessed, and determine whether a canary record was accessed. If a canary record was accessed, the service provider may determine that the access event was potentially performed by a malicious entity because authorized users generally may not have reason to access a canary record when utilizing their cloud-based service. The service provider may generate canary records that are difficult to identify by a malicious entity, and may position canary records in the storage locations to help ensure that the canary records are accessed by a malicious entity during an improper access event.