Data Inflation for Breach Detection and Exfiltration Deterrence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer systems face challenges in protecting data from unauthorized access while ensuring uninterrupted access for authorized parties, as existing security measures are often breached, leading to economic impacts and operational disruptions.
Innovation Solution
The implementation of data inflation techniques, where spurious data is generated and added to responsive data to deceive attackers, increasing the data volume significantly, making it difficult for unauthorized parties to extract usable information, while authorized parties can filter out the spurious data using provided characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data security measures are implemented to protect stored data from unauthorized access, then data protection is improved, but authorized access may be disrupted and operations may be suspended
Solution Approach 1:
The system performs preliminary actions by detecting breaches before significant data loss occurs and proactively responding by inflating data with spurious information. This advance detection and response mechanism protects data while maintaining operational continuity, as the system remains functional rather than suspending operations.
Solution Approach 2:
The system converts the harmful breach event into a beneficial outcome by using the detected breach as a trigger to inflate data with spurious information. This transforms the security incident into an opportunity to deceive attackers while maintaining normal operations, thereby protecting data without disrupting productivity.
2Reliability
If data is inflated with spurious information to deceive attackers, then data protection is improved, but data volume increases making processing more complex
Solution Approach 1:
The system applies local quality by selectively inflating only the portions of data that are relevant to the breach, rather than uniformly processing all data. The spurious information is generated with specific characteristics tailored to the breach context, making the protection mechanism more efficient and less complex than comprehensive data processing.
Solution Approach 2:
The system changes parameters by modifying data characteristics through inflation with spurious information that has different statistical properties than genuine data. This parameter transformation deceives attackers without requiring complex processing systems, as the changes are applied at the data level rather than requiring complex infrastructure.
3Reliability
If breach detection is implemented to identify unauthorized access, then security monitoring is improved, but false positives may disrupt authorized access
Solution Approach 1:
The system uses an intermediary approach by introducing spurious data as a mediator between the breach detection and the actual data protection. This intermediary layer allows the system to respond to detected breaches without directly blocking authorized access, as the spurious information is mixed with genuine data rather than creating hard barriers.
Solution Approach 2:
The system applies partial action by inflating only specific data portions relevant to the breach rather than blocking all access. This selective response provides security monitoring without excessive disruption to authorized operations, maintaining ease of operation while improving security.
Data Source
AI summary
A method and apparatus for deterring exfiltration of data from are provided. In the method and apparatus, it is determined that data is to be inflated. A request for access to data is received and data responsive to the request is retrieved. Spurious data is also generated and provided together with the responsive data in response to the request.


