Honeyfile Creation Using File-System Learning and Tokenized Templates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing honeyfile creation methods are user-centric and do not scale well to large repositories, lacking flexibility and realism, leading to high false-positive rates and inefficiencies in deception and intelligence gathering.
Innovation Solution
A method for automatically creating honeyfiles by surveying a file system to identify tokenisable data, tokenising it, and applying substitution methods to generate realistic and deceptive files using token sequences and metadata, allowing for scalable and flexible honeyfile deployment and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If user-centric methods are used to create honeyfiles with handcrafted content or template documents, then the honeyfiles can be realistic and enticing to attackers, but the approach does not scale to large repositories of generic documents and requires significant user time and effort
Solution Approach 1:
The patent uses template documents as copies that can be automatically instantiated with substituted content. Instead of handcrafting each honeyfile individually, the system creates copies of template structures and fills them with automated content generation, maintaining realism while enabling scale across large document repositories
Solution Approach 2:
The system changes parameters from manual user-centric creation to automated parameter-driven generation. By using templates with substitutable parameters and automated content insertion, the system maintains the quality characteristics of handcrafted honeyfiles while achieving scalability through parameterized document generation
2Manufacturing precision
If standard formats like tax documents or receipts with fake elements are used, then the honeyfiles are realistic and enticing due to financial information, but they do not scale to large repositories and lack flexibility
Solution Approach 1:
The patent creates template documents that serve multiple functions and can be adapted to various document types. The same template framework can generate tax documents, receipts, invoices, and other financial-looking documents by changing parameters and content, providing both realism and versatility across different document formats
Solution Approach 2:
The system transitions from static, fixed-format honeyfiles to dynamic, parameterizable templates. The templates can adapt their content and structure based on input parameters, allowing the same template to generate different types of realistic documents dynamically rather than requiring separate static templates for each document type
3Reliability
If users manually select and place honeyfiles in locations believed to be attractive to intruders, then the deception may be effective, but the process is time-consuming and does not scale to large file systems
Solution Approach 1:
The system enables self-service deployment by automatically analyzing the file system structure, identifying appropriate locations for honeyfiles based on patterns of real documents, and placing them without requiring manual user selection. This maintains deception effectiveness through intelligent placement while eliminating the time-consuming manual selection process
Solution Approach 2:
The patent performs preliminary analysis of the file system structure and document patterns before deployment. By pre-identifying optimal locations and pre-generating appropriate honeyfile templates based on the analyzed patterns, the system prepares everything in advance, enabling rapid deployment across large file systems without manual intervention during the actual placement phase
4Productivity
If automated methods are used to generate honeyfiles, then scalability and flexibility are improved, but the realism and fidelity to actual file system data may be reduced
Solution Approach 1:
The patent uses template documents as intermediaries between automated generation and realistic output. The templates serve as a mediating structure that guides automated content substitution while ensuring the output maintains the characteristics of real documents, bridging the gap between automation and fidelity
Solution Approach 2:
The system segments document creation into separate components: template structure, content parameters, and substitution rules. This segmentation allows automated processing of each component independently while maintaining the overall realism through structured assembly, enabling both automation and fidelity
Data Source
AI summary
A method of automatically manipulating a lifecycle of a honeyfile on a file system, includes: implementing a learning algorithm on a file system; identifying a real file; training the learning algorithm by observing temporal events involving the real file; training a model with the learning algorithm; implementing a user agent on the file system; creating a honeyfile on the file system; deploying the honeyfile on the file system; using the trained model to generate user agent actions; evaluating the honeyfile; and either: deleting the honeyfile; or re-using the trained model to generate user agent actions to automatically modify the honeyfile.


