Decoy Documents for Data Loss Prevention Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data loss prevention defenses are inadequate in detecting sophisticated threats within networks, as they rely on technical tell-tale signs and lack realism, making it difficult to identify malicious activity, especially when attackers infiltrate deeper into the network.

Innovation Solution

A method and apparatus for creating, distributing, and tracking decoy documents and traffic to identify malicious activity, using a data loss prevention system that generates decoy traffic and bait data to lure in threats, allowing for early detection and diversion of efforts towards discriminating true data from decoy data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If honeypots are used to detect threats, then threat detection capability is improved, but the lure factor and realism are insufficient to attract sophisticated threats

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidlure factor
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates decoy documents that are copies or replicas of legitimate organizational documents, embedded within the actual document set. These decoys mirror the appearance, format, and content structure of real sensitive documents, making them indistinguishable to attackers. This copying approach enhances the lure factor while maintaining threat detection capability through embedded tracking mechanisms.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces decoy documents as an intermediary element between the organization's real data and the attacker. These decoys act as a mediator that attracts and engages sophisticated threats, allowing detection without exposing actual sensitive information. The decoys serve as a buffer that maintains realism while protecting underlying assets.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If traditional DLP defenses focus on technical tell-tale signs, then detection of obvious malicious activity is improved, but sophisticated stealthy operations remain undetected

Engineering Contradiction:
Improvedetection accuracyVSAvoidstealthy malicious activity
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent embeds tracking mechanisms and unique identifiers within decoy documents before they are exposed to attackers. This preliminary action ensures that when sophisticated threats interact with these documents, the pre-placed tracking elements are already in position to capture and report the interaction, enabling detection of stealthy operations that would otherwise evade traditional DLP measures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs subtle modifications or markers within decoy documents that are imperceptible to human attackers but detectable by monitoring systems. These changes act as visual or digital signals that differentiate decoys from real documents without affecting their apparent legitimacy, allowing precise detection of sophisticated threats that attempt to avoid traditional technical tell-tale signs.

Inventive Principle:
Principle #32Color changes

3Adaptability or versatility

If decoy documents are distributed throughout the network, then the ability to lure sophisticated threats is improved, but the complexity of tracking and managing decoys increases

Engineering Contradiction:
Improvelure effectivenessVSAvoidtracking and management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates decoy documents that serve multiple functions simultaneously: they act as lures to attract sophisticated threats, serve as tracking vehicles with embedded identifiers, and function as protective measures by diverting attacker attention from real data. This multi-functionality reduces the need for separate systems while enhancing lure effectiveness and managing complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The decoy documents are designed to be self-tracking and self-reporting through embedded mechanisms. Once distributed, they automatically monitor their own interactions and report suspicious activity without requiring external management intervention for each individual document. This self-service capability reduces tracking and management complexity while maintaining widespread distribution for effective lure operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8549643B1Using decoys by a data loss prevention system to protect against unscripted activity
Publication Date: 2013.10.01 GEN DIGITAL INC
  • US8549643B1 patent drawing
  • US8549643B1 patent drawing
  • US8549643B1 patent drawing

AI summary

A computing device executing a data loss prevention (DLP) system tracks bait data on at least one of the computing device or a network. The DLP system identifies a potential security threat in response to detecting unscripted activity associated with the bait data. The DLP system performs an action in response to identifying the potential security threat.