Decoy Data Sentinel Detection for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identifying unauthorized access to confidential data in data stores is challenging due to the difficulty in distinguishing between legitimate and malicious activities, especially in networked environments where decoy data can be inadvertently or maliciously introduced.
Innovation Solution
The implementation of an automated system that places decoy data in data store responses and uses sentinels to detect its presence through signature comparison, allowing for the differentiation between authorized and unauthorized access based on predefined policies and encoding rules, such as steganographic and cryptographic techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If decoy data is placed in data store responses to identify unauthorized access, then security detection capability is improved, but system complexity increases due to the need for automated placement and sentinel detection mechanisms
Solution Approach 1:
The system performs preliminary actions by automatically placing decoy data into data store responses before any access attempt occurs. This proactive preparation enables subsequent detection of unauthorized access without requiring complex real-time analysis, as the decoy data is already positioned to be detected by sentinels in compromised systems.
Solution Approach 2:
The patent introduces decoy data as an intermediary element that mediates between the data store and potential unauthorized access. This intermediary serves as a detectable marker that can be embedded in legitimate data responses, allowing sentinels to identify compromised systems without directly monitoring all data access patterns, thereby simplifying the detection architecture.
2Measurement precision
If sentinels are deployed to detect decoy data through signature comparison, then unauthorized access detection accuracy is improved, but processing overhead increases
Solution Approach 1:
The system extracts the detection function into separate sentinel components that operate independently from the main data store. These sentinels are deployed only where needed (in client systems or network points) and perform simple signature comparison operations, separating the heavy detection logic from the core data management system and reducing overall processing overhead.
Solution Approach 2:
The patent uses copying by creating signature representations of the decoy data that can be efficiently compared against received data. Instead of analyzing entire data responses, sentinels compare compact signature copies, dramatically reducing processing requirements while maintaining high detection accuracy through precise signature matching.
3Reliability
If decoy data is used to differentiate legitimate from unauthorized access, then security monitoring capability is improved, but data integrity challenges increase due to the presence of embedded decoy elements
Solution Approach 1:
The system applies local quality by embedding decoy data with specific identifying characteristics (signatures) that distinguish it from legitimate data content. This localized differentiation allows sentinels to identify and handle decoy data separately, maintaining the integrity of actual data while enabling security monitoring through the unique properties of the embedded decoy elements.
Data Source
AI summary
Disclosed are various embodiments for obtaining policy data specifying decoy data eligible to be inserted within a response to an access of a data store. The decoy data is detected in the response among a plurality of non-decoy data based at least upon the policy data. An action associated with the decoy data is initiated in response to the access of the data store meeting a configurable threshold.


