Data Inflation for Breach Detection and Exfiltration Deterrence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems face challenges in protecting data from unauthorized access while ensuring uninterrupted access for authorized parties, as existing security measures are often breached, leading to economic impacts and operational disruptions.

Innovation Solution

The implementation of data inflation techniques, where spurious data is generated and added to responsive data to deceive attackers, increasing the data volume significantly, making it difficult for unauthorized parties to extract usable information, while authorized parties can filter out the spurious data using provided characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data security measures are implemented to protect stored data from unauthorized access, then data protection is improved, but authorized access may be disrupted and operations may be suspended

Engineering Contradiction:
Improvedata protectionVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by detecting breaches before significant data loss occurs and proactively responding by inflating data with spurious information. This advance detection and response mechanism protects data while maintaining operational continuity, as the system remains functional rather than suspending operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the harmful breach event into a beneficial outcome by using the detected breach as a trigger to inflate data with spurious information. This transforms the security incident into an opportunity to deceive attackers while maintaining normal operations, thereby protecting data without disrupting productivity.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If data is inflated with spurious information to deceive attackers, then data protection is improved, but data volume increases making processing more complex

Engineering Contradiction:
Improvedata protectionVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by selectively inflating only the portions of data that are relevant to the breach, rather than uniformly processing all data. The spurious information is generated with specific characteristics tailored to the breach context, making the protection mechanism more efficient and less complex than comprehensive data processing.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters by modifying data characteristics through inflation with spurious information that has different statistical properties than genuine data. This parameter transformation deceives attackers without requiring complex processing systems, as the changes are applied at the data level rather than requiring complex infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If breach detection is implemented to identify unauthorized access, then security monitoring is improved, but false positives may disrupt authorized access

Engineering Contradiction:
Improvesecurity monitoringVSAvoidauthorized access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses an intermediary approach by introducing spurious data as a mediator between the breach detection and the actual data protection. This intermediary layer allows the system to respond to detected breaches without directly blocking authorized access, as the spurious information is mixed with genuine data rather than creating hard barriers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies partial action by inflating only specific data portions relevant to the breach rather than blocking all access. This selective response provides security monitoring without excessive disruption to authorized operations, maintaining ease of operation while improving security.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10110630B2Breach detection-based data inflation
Publication Date: 2018.10.23 AMAZON TECH INC
  • US10110630B2 patent drawing
  • US10110630B2 patent drawing
  • US10110630B2 patent drawing

AI summary

A method and apparatus for deterring exfiltration of data from are provided. In the method and apparatus, it is determined that data is to be inflated. A request for access to data is received and data responsive to the request is retrieved. Spurious data is also generated and provided together with the responsive data in response to the request.