Decoy Text System for Impersonation Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Impersonation attacks occur when malicious users mimic legitimate users' language patterns to gain access to secure systems or data, posing a risk of catastrophic damage.

Innovation Solution

A computer-implemented method using online decoy text is employed, where actual text is intercepted and replaced with decoy text, and a machine learning model is trained to recognize decoy language patterns, enabling detection and thwarting of impersonation attacks by identifying matching language patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If legitimate users post actual text online, then communication and information sharing are enabled, but malicious users can analyze language patterns to launch impersonation attacks

Engineering Contradiction:
Improveonline communicationVSAvoidimpersonation attack risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system replaces legitimate users' actual text with decoy text that mimics language patterns, converting the harmful effect of text analysis by attackers into a beneficial deception mechanism. The decoy text serves as a trap that causes attackers to learn incorrect patterns, thereby protecting the legitimate user's actual language characteristics from being exploited

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

Decoy text acts as an intermediary between the legitimate user and the online platform. Instead of posting actual text directly, the system posts decoy text that mediates the communication by providing fake language patterns to attackers, preventing them from analyzing the real user's writing style

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If decoy text is posted online to train machine learning models, then impersonation detection capability is improved, but legitimate text posting is blocked

Engineering Contradiction:
Improveimpersonation detection accuracyVSAvoidtext posting functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by replacing actual text with decoy text before the text is posted online. This preemptive substitution ensures that only decoy text appears on the platform, which is then used to train machine learning models to recognize impersonation patterns without exposing legitimate language characteristics

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of legitimate text in the form of decoy text that mimics language patterns. These decoy copies are posted online instead of the original text, allowing the system to train detection models while preserving the authenticity of the user's actual postings

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10757137B1Thwarting an impersonation attack using online decoy text
Publication Date: 2020.08.25 GEN DIGITAL INC
  • US10757137B1 patent drawing
  • US10757137B1 patent drawing
  • US10757137B1 patent drawing

AI summary

Thwarting an impersonation attack using online decoy text. In one embodiment, a method may include intercepting first actual text submitted online by a first user, generating decoy text to replace the first actual text, sending the decoy text for posting online, training a machine learning model using the decoy text to make the machine learning model capable of recognizing a decoy language pattern in the decoy text, intercepting second actual text submitted to a web server by a second user purporting to be the first user, determining, using the machine learning model, that a language pattern in the second actual text matches the decoy language pattern in the decoy text, and, in response, determining that the second user is impersonating the first user in an impersonation attack and thwarting the impersonation attack by performing a remedial action at the web server to protect the web server from the impersonation attack.