Cyber Deception Token Deployment via Metadata Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber threat detection and deception systems face challenges in designing a suitable deception deployment plan that meets deterrence objectives while adhering to cost constraints, and there is a need to improve the time-to-deployment for these systems.

Innovation Solution

The system leverages metadata collected by the data storage management system to analyze for anomalies, detect suspicious behavior, and deploy cyber deception plans. This involves deploying sensors or emulation traps in cyber-threat appliances within the data network, configuring tokens on suspected assets to redirect attackers to these traps, and optionally using deep deception traps to enhance the deception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deception techniques are deployed to detect cyber threats, then deterrence effectiveness is improved, but deployment complexity and time consumption increase

Engineering Contradiction:
Improvedeterrence effectivenessVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The deception system is divided into modular components including sensors deployed in cyber-threat appliances, tokens configured on specific assets, and emulation traps positioned throughout the network. Each component performs a specific function and can be independently deployed and managed, reducing overall deployment complexity while maintaining deterrence effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by automatically analyzing metadata to detect suspicious behavior patterns before deploying deception elements. Anomaly detection and threat assessment are conducted in advance, allowing the system to pre-position sensors, tokens, and emulation traps proactively rather than reactively, thereby reducing deployment time.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive metadata analysis is performed to detect anomalies, then threat detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts only the most relevant metadata fields and anomaly indicators from the vast amount of available data. By focusing on specific high-value metadata elements rather than analyzing every piece of data, the system maintains high detection accuracy while significantly reducing processing time and computational overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates simplified copies or representations of complex metadata structures, using standardized schemas and aggregated views that preserve essential anomaly-detection capabilities while reducing data volume and processing requirements. This allows rapid analysis without sacrificing detection precision.

Inventive Principle:
Principle #26Copying

3Productivity

If tokens are deployed on multiple assets to redirect attackers, then coverage and detection capability are improved, but system cost and complexity increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The token design implements multi-functionality by enabling a single token type to operate across diverse asset types and network locations. The tokens can be deployed on servers, workstations, cloud resources, and other assets using a unified configuration approach, expanding detection coverage without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250039236A1Efficient token deployment in cyber threat detection and deception system
Publication Date: 2025.01.30 COMMVAULT SYSTEMS INC
  • US20250039236A1 patent drawing
  • US20250039236A1 patent drawing
  • US20250039236A1 patent drawing

AI summary

The disclosed cyber threat detection and deception system leverages metadata information collected by the data storage management system. Using the metadata collected by the data storage management system, the cyber threat detection and deception system analyzes that metadata to detect any anomalies. Once suspicious or abnormal behavior is detected in an asset, the cyber threat detection and deception system creates and deploys a cyber deception plan for that asset. The cyber deception plan is implemented by way of deploying sensors or emulation traps in any number of cyber-threat appliances within the data network. Lures or tokens are configured and deployed on the suspected assets themselves to redirect attackers to the emulation traps.