Decoy Data Sentinel Detection for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying unauthorized access to confidential data in data stores is challenging due to the difficulty in distinguishing between legitimate and malicious activities, especially in networked environments where decoy data can be inadvertently or maliciously introduced.

Innovation Solution

The implementation of an automated system that places decoy data in data store responses and uses sentinels to detect its presence through signature comparison, allowing for the differentiation between authorized and unauthorized access based on predefined policies and encoding rules, such as steganographic and cryptographic techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decoy data is placed in data store responses to identify unauthorized access, then security detection capability is improved, but system complexity increases due to the need for automated placement and sentinel detection mechanisms

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by automatically placing decoy data into data store responses before any access attempt occurs. This proactive preparation enables subsequent detection of unauthorized access without requiring complex real-time analysis, as the decoy data is already positioned to be detected by sentinels in compromised systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces decoy data as an intermediary element that mediates between the data store and potential unauthorized access. This intermediary serves as a detectable marker that can be embedded in legitimate data responses, allowing sentinels to identify compromised systems without directly monitoring all data access patterns, thereby simplifying the detection architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If sentinels are deployed to detect decoy data through signature comparison, then unauthorized access detection accuracy is improved, but processing overhead increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts the detection function into separate sentinel components that operate independently from the main data store. These sentinels are deployed only where needed (in client systems or network points) and perform simple signature comparison operations, separating the heavy detection logic from the core data management system and reducing overall processing overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses copying by creating signature representations of the decoy data that can be efficiently compared against received data. Instead of analyzing entire data responses, sentinels compare compact signature copies, dramatically reducing processing requirements while maintaining high detection accuracy through precise signature matching.

Inventive Principle:
Principle #26Copying

3Reliability

If decoy data is used to differentiate legitimate from unauthorized access, then security monitoring capability is improved, but data integrity challenges increase due to the presence of embedded decoy elements

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoiddata integrity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies local quality by embedding decoy data with specific identifying characteristics (signatures) that distinguish it from legitimate data content. This localized differentiation allows sentinels to identify and handle decoy data separately, maintaining the integrity of actual data while enabling security monitoring through the unique properties of the embedded decoy elements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9990507B2Adapting decoy data present in a network
Publication Date: 2018.06.05 AMAZON TECH INC
  • US9990507B2 patent drawing
  • US9990507B2 patent drawing
  • US9990507B2 patent drawing

AI summary

Disclosed are various embodiments for obtaining policy data specifying decoy data eligible to be inserted within a response to an access of a data store. The decoy data is detected in the response among a plurality of non-decoy data based at least upon the policy data. An action associated with the decoy data is initiated in response to the access of the data store meeting a configurable threshold.