Decoy Document Balancing Against Lateral Network Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large networks face challenges in protecting against lateral movement cyberattacks, where threat actors exploit a single point-of-entry and expand within the network, making it difficult to maintain high-level security at every entry point, especially with internal firewalls often being weaker than external ones.
Innovation Solution
Implementing a system that uses decoy documents and decoy servers to deceive threat actors, mirroring legitimate servers to divert their attention while monitoring and analyzing their actions, and generating decoy content to replace sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If decoy documents and decoy servers are implemented to divert threat actors, then security effectiveness is improved, but system complexity increases
Solution Approach 1:
The patent creates decoy documents and decoy servers that are copies or replicas of legitimate documents and servers. These decoys mimic the appearance and behavior of real targets to lure and divert threat actors, allowing the system to maintain security effectiveness without requiring comprehensive protection of every actual asset
Solution Approach 2:
The system introduces decoy documents and decoy servers as intermediary elements between threat actors and legitimate assets. These intermediaries absorb the initial attack momentum and redirect threat actor attention away from critical systems, reducing the direct burden on security infrastructure
2Reliability
If decoy content replaces sensitive information to protect data, then data security is improved, but information accuracy deteriorates
Solution Approach 1:
The patent applies different quality characteristics to different parts of the system. Decoy documents contain placeholder or fabricated information that is intentionally inaccurate, while legitimate documents retain their original accurate content. This local differentiation allows the system to sacrifice information accuracy only in decoy elements while preserving it in real assets
Solution Approach 2:
The system segments documents into distinct decoy portions and legitimate portions. Decoy content is inserted as separate replaceable elements within or alongside authentic information, allowing the system to maintain accurate sensitive data while presenting inaccurate decoy information to potential attackers
Data Source
AI summary
An example method includes receiving, from a user, a request to access a target document; determining that the request is unauthorized based on a characteristic of at least one of the user, the request, or the target document; in response to the determination, dynamically generating a decoy document and replacing the target document with the decoy document; and presenting the decoy document to the user, wherein the decoy document comprises an identical format to the target document.


