Endpoint Sensor Modules Redirect Attackers to Decoy Network Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Attackers compromise endpoint systems to harvest data and move laterally in the network, posing a threat to unauthorized access to application data.

Innovation Solution

Implementing a sensor module on endpoints that intercepts file system commands and modifies or generates deception data to mimic production data, using a BotSink to engage attackers while preventing access to actual data, and incorporating database deception into directory services to simulate responses and lure attackers into decoy systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are used to protect production data, then data security is maintained, but attackers can still access and harvest data through compromised endpoints

Engineering Contradiction:
Improvedata securityVSAvoidunauthorized data access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates deception data that copies the structure and appearance of production data but contains no sensitive information. This decoy data is presented to attackers instead of real data, allowing security monitoring without exposing actual enterprise assets. The copying principle resolves the contradiction by providing a realistic-looking alternative that protects the original data while maintaining system responsiveness.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The deception data acts as an intermediary between attackers and production data. Instead of attackers directly accessing production data, they interact with the decoy system that mediates all data requests. This intermediary layer enables security monitoring and attacker engagement while preventing direct access to sensitive information, thus resolving the security contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If deception data is implemented to engage attackers, then attacker detection is improved, but system complexity increases

Engineering Contradiction:
Improveattacker detectionVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The deception data system is segmented into distinct components: deception data generation modules, data presentation layers, and monitoring systems. This segmentation allows each component to be developed and maintained independently, reducing overall system complexity while enabling sophisticated attacker detection capabilities. The modular approach resolves the contradiction by making the complex detection system manageable and maintainable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12432253B2Deceiving attackers accessing network data
Publication Date: 2025.09.30 SENTINELONE INC
  • US12432253B2 patent drawing
  • US12432253B2 patent drawing
  • US12432253B2 patent drawing

AI summary

Endpoints in a network execute a sensor module that intercepts commands to obtain information regarding a remote network resource. The sensor module compares a source of commands to a sanctioned list of applications. If the source is not sanctioned, then a simulated response can be provided to the source that references a decoy server.