Cloud Deception Breadcrumbs for Role-Based Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional deception technology solutions require on-premises appliances, which do not scale and necessitate infrastructure in the customer network, leading to inefficiencies in threat detection and response.

Innovation Solution

A cloud-based deception technology system that integrates deception technology with a cloud-based security system, utilizing breadcrumbs (fake data) on user devices for targeted threat detection and dynamic risk scoring, without the need for on-premises appliances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional deception technology uses on-premises appliances, then threat detection capability is provided, but scalability is limited and infrastructure complexity increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the deception technology from on-premises appliances and relocates it to a cloud-based platform. The system removes the need for physical appliances by implementing deception technology as a cloud service that can be accessed remotely, thereby eliminating scalability limitations and reducing infrastructure complexity while maintaining threat detection capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud-based intermediary platform that mediates between the deception technology and the customer network. This intermediary enables threat detection without requiring direct deployment of appliances in the customer network, allowing scalable access while maintaining security monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If on-premises appliances are deployed, then local threat detection is enabled, but infrastructure installation and maintenance complexity increases

Engineering Contradiction:
Improvelocal threat detectionVSAvoidinfrastructure installation and maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts threat detection functionality from physical appliances and implements it as a cloud-based service. This removes the need for infrastructure installation and maintenance of on-premises hardware while maintaining the ability to detect threats locally through cloud-accessible monitoring mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If deception technology is deployed without on-premises appliances, then scalability is improved, but deployment and configuration complexity may increase

Engineering Contradiction:
ImprovescalabilityVSAvoiddeployment and configuration
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements self-service capabilities where the cloud-based platform automatically handles deployment and configuration tasks. The system provisions deception technology components, manages updates, and configures monitoring parameters without requiring manual intervention, thereby simplifying deployment while maintaining scalability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12495073B2Cloud-based deception technology with auto-decoy and breadcrumb creation based on user's role and without on-premises appliances
Publication Date: 2025.12.09 ZSCALER INC
  • US12495073B2 patent drawing
  • US12495073B2 patent drawing
  • US12495073B2 patent drawing

AI summary

Cloud-based deception systems and methods include monitoring activity of a user on a user device; analyzing the activity to determine a role of a plurality of roles, for the user at a customer; and creating one or more fake assets on the user device based on the determined role, wherein the one or more fake assets include any of files, passwords, breadcrumbs, lures, cookies, and sessions that are contextually relevant to the user's role, and wherein the one or more fake assets are configured to interact with one or more decoys hosted in a decoy cloud environment for the customer.