Decoy Data Elements for Unauthorized Access Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data leakage prevention systems require significant cooperation from business units, resource-intensive maintenance, and lengthy integration processes, often leaving enterprises vulnerable during implementation, disrupting daily operations and exposing them to data threats.

Innovation Solution

A system and method for deploying deceptive decoy elements in a computerized environment, which generates and deploys decoy elements based on folder sensitivity levels to detect unauthorized access, providing an electronic indication of unauthorized access attempts without disrupting normal operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DLP systems are deployed to prevent data breaches, then data security is improved, but enterprise productivity deteriorates due to interruption of daily work

Engineering Contradiction:
Improvedata securityVSAvoidenterprise productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces decoy data elements as intermediary objects that mediate between security monitoring and user operations. These decoys are embedded within legitimate files and folders, allowing the system to detect unauthorized access attempts without requiring active monitoring or blocking of actual business operations. The decoys serve as passive traps that trigger alerts only when accessed by unauthorized entities, thus maintaining normal productivity while improving security detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional DLP systems are implemented to protect sensitive data, then data security is improved, but integration time worsens, exposing the enterprise without protection during implementation

Engineering Contradiction:
Improvedata securityVSAvoidintegration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-deploying decoy data elements into the file system before any actual security monitoring or blocking rules are activated. These decoys are embedded within legitimate files and folders in advance, creating an immediate passive detection network. This allows the system to provide security protection from the moment of deployment without requiring lengthy integration, configuration, or business unit cooperation that traditional DLP systems need.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional DLP systems are deployed to detect data breaches, then data security is improved, but device complexity worsens due to requirement of cooperation with business units and resource-intensive maintenance

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by designing a system where the decoy data elements autonomously perform security detection functions without requiring continuous human intervention, configuration, or maintenance. The decoys are embedded within files and folders and automatically monitor for unauthorized access attempts. This eliminates the need for ongoing cooperation with business units to update security policies or for resource-intensive system maintenance, significantly reducing operational complexity while maintaining security effectiveness.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11687650B2Utilization of deceptive decoy elements to identify data leakage processes invoked by suspicious entities
Publication Date: 2023.06.27 ITSMINE LTD
  • US11687650B2 patent drawing
  • US11687650B2 patent drawing
  • US11687650B2 patent drawing

AI summary

A method and system for a deployment of deceptive decoy elements in a computerized environment to identify data leakage processes invoked by suspicious entities are presented. The method includes generating at least one deceptive decoy element; and deploying the generated at least one deceptive decoy element in a folder in a file system of the computerized environment, wherein the deployment is based on a sensitivity level of the folder, wherein the at least one deceptive decoy element is configured to provide an indication of unauthorized access upon an attempt by an unauthorized entity to access the folder.