Cloud Protection Agent Decoy Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face significant security concerns when migrating to cloud environments due to frequent security breaches and the risk of data disclosure or system unavailability, which distracts them from their core business and undermines customer trust.

Innovation Solution

A cloud protection method is implemented where a security intrusion is detected, and a cloud protection agent shuts down the enterprise system in the source cloud environment, migrating it to a target environment while creating a feigned system to monitor and entice the intruder, thereby tracking their actions and securing critical resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprises migrate to cloud environments to outsource IT management and physical assets, then productivity and focus on core business are improved, but security reliability deteriorates due to frequent security breaches and system compromises

Engineering Contradiction:
Improvefocus on core businessVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary security assessments and vulnerability scans before migration, and prepares contingency plans in advance. The feigned system is created beforehand to serve as a trap, and the migration process is pre-coordinated with security protocols already in place to detect and respond to intrusions before they can compromise the actual enterprise system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A feigned system acts as an intermediary between the intruder and the actual enterprise system. This decoy system absorbs the intruder's attention and actions, allowing security personnel to monitor and study the intrusion methods without the actual enterprise system being compromised. The feigned system serves as a buffer that protects the real system while providing valuable intelligence.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are strengthened to protect cloud environments from breaches, then security reliability is improved, but device complexity and operational overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of implementing multiple complex security layers on the actual enterprise system, the invention creates a simplified copy or feigned system that mimics the appearance and structure of the real system. This decoy system is easier to manage and monitor, and it absorbs the complexity of security operations away from the critical enterprise system while maintaining security effectiveness.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The feigned system operates autonomously to attract and engage intruders, automatically logging their actions and providing security intelligence without requiring constant human intervention. The system self-manages the complexity of monitoring and analysis, reducing the operational burden on security personnel while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Loss of information

If a feigned system is created to monitor intruder actions, then security intelligence is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity intelligenceVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The feigned system is created as a simplified replica of the actual enterprise system, copying only the essential characteristics needed to attract and monitor intruders. This selective copying reduces resource requirements compared to duplicating the entire enterprise system, while still providing valuable security intelligence about intrusion methods and vulnerabilities.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10341383B2Cloud protection techniques
Publication Date: 2019.07.02 MICRO FOCUS LLC
  • US10341383B2 patent drawing
  • US10341383B2 patent drawing
  • US10341383B2 patent drawing

AI summary

Cloud protection techniques are provided. A security breach is detected in a source cloud environment. An enterprise system processing in the source cloud environment is immediately locked down and is dynamically migrated to a target cloud environment. While the enterprise system is migrating, the source cloud environment creates a fake environment with fake resources within the source cloud environment to dupe an intruder having access as a result of the security breach. Metrics and logs are gathered with respect to activities of the intruder within the source cloud environment.