Decoy System Generation for Networked Computing Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional automated honeypot generation in cloud environments is limited as it either affects valid users or allows attackers to easily identify the decoy environments, and systems that create honeypots in response to attacks face challenges in diverting attacker attention away from the valid system.
Innovation Solution
The method involves detecting a breach in a production system, generating a new system with a patch, converting the original system to a decoy with replicated low-value data, and creating a reduced security honeypot system with additional vulnerabilities to lure attackers and monitor their actions for new vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If honeypots are created upfront in cloud environments, then attackers can be lured to decoy environments, but legitimate users must be routed to valid environments which attackers can easily identify
Solution Approach 1:
The system performs preliminary actions by creating multiple valid system copies before an attack occurs. When a breach is detected, the system has already prepared patched copies that can be rapidly deployed, eliminating the need for complex real-time routing decisions and user redirection.
Solution Approach 2:
The invention creates copies of the valid production system that include security patches. These copies serve as both backup systems and honeypots, allowing the system to maintain multiple identical-looking environments without complex routing logic, as attackers cannot easily distinguish between copies.
2Reliability
If honeypots are created in response to an attack, then the valid system can be protected, but attackers can monitor user flow to recognize compromised environments
Solution Approach 1:
The system creates identical copies of the production environment that include security patches. These copies are indistinguishable from the original system, preventing attackers from monitoring user flow to detect compromised environments. The copying ensures consistency across all system versions.
Solution Approach 2:
The invention replaces the mechanical approach of monitoring and reacting to user flow patterns with an automated system that proactively manages multiple patched copies. This substitution eliminates the information loss associated with attacker monitoring by maintaining system equivalence across all copies.
3Productivity
If traditional honeypots are used, then attacker activity can be analyzed, but the honeypot value is limited to non-targeted attackers
Solution Approach 1:
The system performs preliminary patching actions on system copies before they are needed. When creating honeypot environments, the patches are already in place, allowing immediate deployment and analysis of attacker behavior without delays. This preliminary preparation enhances both productivity in attacker analysis and reliability of honeypot effectiveness.
4Reliability
If valid systems are migrated away from exposed systems, then security can be improved, but users need to be migrated to new systems which attackers can monitor
Solution Approach 1:
The invention creates identical copies of the production system that include security patches. Users are migrated to these copies without disruption, and the copies remain indistinguishable from the original system. This eliminates the loss of user flow information that would otherwise reveal the migration to attackers.
Data Source
AI summary
Approaches for providing data protection in a networked computing environment are provided. A method includes detecting, by at least one computer device, a breach of a first system in the networked computing environment. The method also includes generating, by the at least one computer device, a second system in the networked computing environment, wherein the second system includes a patch based on the breach. The method additionally includes converting, by the at least one computer device, the first system to a decoy system. The method further includes generating, by the at least one computer device, a third system in the networked computing environment, wherein the third system has reduced security relative to the first system.


