Marked Account Traps for Database Breach Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Undetected data breaches in databases can go unnoticed for months or even years, allowing hackers to steal and misuse customer information without the affected entities being aware, due to the evolving nature of security infrastructure and the difficulty in consistently detecting database breaches.
Innovation Solution
A method is introduced to identify hacked databases by generating marked accounts and data, which are then used in databases storing customer information. When the marked data is used by hackers or unauthorized individuals, the system notifies the relevant authorities, allowing for the identification of compromised databases and the source of stolen data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional database security monitoring is used, then the system maintains normal operation, but data breaches go undetected for months or years
Solution Approach 1:
The system performs preliminary actions by generating marked accounts and placing marked data into the database before any breach occurs. These marked elements serve as traps that will trigger notifications when stolen data is used, enabling detection at the moment of unauthorized use rather than requiring continuous monitoring throughout the breach period.
Solution Approach 2:
The system establishes a feedback mechanism where the use of marked data automatically generates a notification to the entity. This feedback loop ensures that when hackers or unauthorized individuals use the stolen marked data, the system immediately detects and reports the breach, closing the detection time gap.
2Reliability
If marked accounts and data are generated and placed in the database, then breach detection capability is improved, but system complexity increases
Solution Approach 1:
The system creates copies of legitimate customer data elements (accounts, personal information) and marks them with unique identifiers. These marked copies are placed in the database alongside real data, and when used, they trigger breach notifications. This copying approach adds detection capability without fundamentally altering the database structure or requiring complex new systems.
Data Source
AI summary
A method, computer system, and a computer program product for identifying a hacked database is provided. The present invention may include generating a marked account using a plurality of data. The present invention may then include initiating a first transaction using the generated marked account. The present invention may also include determining that a second transaction has occurred using the generated marked account. The present invention may further include receiving notification of the second transaction based on determining that the second transaction occurred.


