Cloud Deception Scoring for Low-Noise Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional deception technology solutions require on-premises appliances, which do not scale and necessitate infrastructure in the customer network, and security teams struggle to separate signal from noise in detecting advanced cyber threats.

Innovation Solution

A cloud-based deception technology system that integrates deception technology with a cloud-based security system, utilizing breadcrumbs (fake data) for targeted threat detection and dynamic risk scoring, with each breadcrumb looking unique and user-type specific.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional deception technology uses on-premises appliances, then deployment is straightforward, but scalability is limited and infrastructure requirements increase

Engineering Contradiction:
ImprovescalabilityVSAvoidinfrastructure requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the deception technology from on-premises appliances and relocates it to a cloud-based platform. The system removes the need for customer infrastructure by implementing deception technology as a cloud service that can be accessed remotely, thereby eliminating scalability limitations and reducing infrastructure requirements while maintaining core deception functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud-based intermediary platform that mediates between the customer's network and the deception technology. This intermediary handles all deception operations, data collection, and analysis in the cloud, eliminating the need for on-premises appliances while providing scalable deployment capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If deception technology monitors all network activity, then comprehensive threat detection is achieved, but signal-to-noise ratio deteriorates

Engineering Contradiction:
Improvebreach detection accuracyVSAvoidsignal-to-noise ratio
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by creating deception elements with specific, targeted characteristics that are locally relevant to the customer's environment. Each deception element is designed with unique attributes (such as specific file names, paths, and data structures) that make them distinguishable from legitimate activity, allowing the system to focus detection on meaningful threats rather than generic network noise

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent employs asymmetry by creating deception elements that have distinct, unnatural characteristics compared to legitimate network activity. The deception elements use asymmetric patterns in data structures, file naming conventions, and access patterns that are highly unlikely to occur in normal operations, enabling reliable differentiation between true breaches and background noise

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS12592968B2Cloud-based deception technology with granular scoring for breach detection
Publication Date: 2026.03.31 ZSCALER INC
  • US12592968B2 patent drawing
  • US12592968B2 patent drawing
  • US12592968B2 patent drawing

AI summary

Cloud-based deception systems and methods include monitoring activity associated with a plurality of decoys hosted in a decoy cloud environment for a customer, wherein the decoy cloud environment is separate from a real environment of the customer, and wherein the activity is between one or more fake assets on user devices of users associated with the customer; scoring the activity based on various steps taken between a fake asset and a decoy; and detecting a breach of the customer based on the scoring of the activity. The scoring includes increasing a score based on any activity by an attacker between the fake asset and the decoy.