Dynamic False User Accounts for Deception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern false computing resources are easily detectable by malicious entities, leading to ineffective deception and increased resource expenditure for organizations, as they lack dynamic behavior and interaction, making it difficult to entice malicious entities to remain engaged and waste time, thereby failing to effectively thwart future attacks.

Innovation Solution

The development of dynamic false user accounts that mimic real accounts by continuously populating them with fresh data, using machine learning techniques to analyze real account patterns and generate realistic false data files, making them indistinguishable from real accounts and enticing malicious entities to interact longer, thereby wasting their time and revealing attack strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If static false computing resources are deployed, then resource expenditure is reduced, but detectability by malicious entities increases

Engineering Contradiction:
Improveresource expenditureVSAvoiddetectability
Core Design Contradiction:
Loss of energyVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies dynamics by transforming static false computing resources into dynamic ones that continuously change their state. The false user accounts are periodically updated with new synthetic data files generated by machine learning models, making them appear alive and active. This dynamic behavior makes detection by malicious entities significantly more difficult while maintaining resource efficiency.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes key parameters of false computing resources from static to dynamic states. Specifically, it introduces time-varying parameters such as data freshness, activity patterns, and interaction responses. The machine learning models generate data files with varying timestamps, file sizes, and content characteristics that evolve over time, making the false resources indistinguishable from real ones.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If static false user accounts are used, then setup resources are minimized, but interaction duration with malicious entities decreases

Engineering Contradiction:
Improvesetup resourcesVSAvoidinteraction duration
Core Design Contradiction:
Ease of manufactureVSDuration of action of moving object

Solution Approach 1:

The system implements dynamics by enabling false user accounts to exhibit continuous activity through automated data generation and response mechanisms. The machine learning models continuously create new data files and update existing ones, simulating ongoing user activity. This dynamic behavior entices malicious entities to remain engaged longer, increasing interaction duration without requiring additional manual setup resources.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The false user accounts are designed to be self-sustaining through automated processes. The machine learning models automatically generate synthetic data files, update account activity, and respond to interactions without human intervention. This self-service capability maintains realistic activity patterns indefinitely, prolonging interaction duration while minimizing ongoing resource expenditure.

Inventive Principle:
Principle #25Self-service

3Reliability

If dynamic false user accounts are deployed, then security effectiveness is improved, but computational complexity increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses copying by creating synthetic replicas of real user data and behavior patterns through machine learning models. Instead of manually crafting complex false accounts, the system trains models on real user data and generates numerous synthetic copies that replicate authentic behavior. This approach improves security effectiveness by creating realistic false accounts while managing computational complexity through automated generation processes.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system manages computational complexity by optimizing parameter changes in the machine learning models. It focuses on generating data files with key varying parameters (timestamps, sizes, content characteristics) rather than replicating entire user behaviors. This selective parameter approach maintains security effectiveness while controlling computational resource requirements.

Inventive Principle:
Principle #35Parameter changes

4Loss of energy

If conventional false computing resources are used, then resource expenditure is minimized, but time wasted on malicious entities is insufficient

Engineering Contradiction:
Improveresource expenditureVSAvoidtime wasted
Core Design Contradiction:
Loss of energyVSLoss of time

Solution Approach 1:

The patent applies dynamics by making false computing resources continuously evolve, which significantly extends the time malicious entities spend investigating them. The periodic updates with fresh synthetic data create the appearance of active, living accounts, preventing malicious entities from quickly identifying them as false. This dynamic behavior wastes more of the malicious entities' time while keeping resource expenditure minimal compared to manual management approaches.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3815330B1Enhanced techniques for generating and deploying dynamic false user accounts
Publication Date: 2024.11.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3815330B1 patent drawingFigure 1
  • EP3815330B1 patent drawingFigure 2
  • EP3815330B1 patent drawingFigure 3

AI summary

Technologies described herein facilitate generating and deploying dynamic false user accounts. Embodiments disclosed herein obtain a false tenant model that is usable to dynamically populate a false user account with messages and/or data files. Rather than containing only a static set of documents, a "dynamic" false user account is continually populated with fresh documents. This results in dynamic false user accounts appearing practically indistinguishable from real user accounts that are continually populated with new real email messages and/or new real hosted files as they are used by account owners to perform legitimate business activities. The realistic nature of the dynamic false user accounts described herein significantly reduces the ability of malicious entities to identify a user account as being false in nature.