Dynamic Chaffing Engine for Log Obfuscation via Artificial Record Interleaving

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security teams often fail to prioritize and effectively manage security exposure landscapes, leading to inadequate protection and awareness of shifting security risks within entities.

Innovation Solution

A system for dynamic chaffing of log obfuscation based on shifting exposure portfolios, which involves generating artificial records, tagging them with authentication codes, interleaving with event records, and encrypting logs to create a chaffed event log, stored in an event database, while authorizing access through authentication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If event logs are stored in plain text for easy access and analysis, then ease of operation is improved, but security and confidentiality of sensitive information deteriorates

Engineering Contradiction:
Improveaccess to event logsVSAvoidunauthorized access to sensitive information
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption/decryption system between the event logs and users. Event logs are encrypted using authentication codes before storage, and only authorized users with valid credentials can decrypt and access them. This mediator mechanism protects sensitive information while maintaining controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different security qualities to different parts of the system. Event logs containing sensitive information are encrypted with higher security measures, while metadata and non-sensitive portions remain more accessible. This localized application of security measures balances protection with operational ease.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If event logs are encrypted to protect sensitive information, then security is improved, but ease of operation and access efficiency deteriorates

Engineering Contradiction:
Improveprotection of sensitive informationVSAvoidaccess to encrypted logs
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary encryption of event logs before storage, and preliminary authentication of users before granting access. Authentication codes are generated and stored in advance, enabling efficient decryption without compromising security. This preliminary preparation reduces the operational burden during actual access operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption and decryption system is designed to be self-service through automated authentication protocols. The system automatically verifies user credentials, manages authentication codes, and handles encryption/decryption operations without requiring manual security interventions, thus maintaining ease of operation despite encryption.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive security monitoring and authentication protocols are implemented, then security management is improved, but device complexity and processing overhead increases

Engineering Contradiction:
Improvesecurity managementVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security system into distinct functional modules: authentication code generation, credential verification, encryption/decryption operations, and access control management. Each module handles a specific aspect of security, making the overall complex system manageable through modular design and independent operation of each component.

Inventive Principle:
Principle #1Segmentation

4Reliability

If authentication credentials are validated for each access request, then security reliability is improved, but processing time and productivity deteriorates

Engineering Contradiction:
Improveaccess authorizationVSAvoidaccess request processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication by validating user credentials before granting access to encrypted event logs. This preliminary action ensures that only authorized users can proceed with decryption and access operations, maintaining security reliability while enabling efficient processing by preventing unauthorized attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system operates autonomously through automated credential verification and authorization decisions. The system self-validates user credentials against stored authentication data without requiring manual security reviews, thus maintaining high reliability while minimizing processing delays through automated decision-making.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11902273B2System for dynamic chaffing for log obfuscation based on shifting exposure portfolio
Publication Date: 2024.02.13 BANK OF AMERICA CORP
  • US11902273B2 patent drawing
  • US11902273B2 patent drawing
  • US11902273B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for dynamic chaffing for log obfuscation based on shifting exposure portfolio. The present invention is configured to receive an event log from one or more sources associated with a resource, wherein the event log comprises one or more event records generated based on one or more action incidences; initiate a chaffing engine on the event log; generate, using the chaffing engine, one or more artificial records based on at least the one or more event records; tag the one or more artificial records and the one or more event records with one or more authentication codes; interleave, using the chaffing engine, the one or more artificial records and the one or more event records to generate an encrypted event log with one or more chaffed event records; and store the encrypted event log in an event database.