Noisy Token Anomaly Detection for Enterprise End Stations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying and utilizing honeypots and honey tokens in enterprises is challenging due to issues like false alarms and tokens being inadvertently removed or becoming ineffective.

Innovation Solution

The implementation of noisy tokens, which are placed on end stations to generate network traffic that can differentiate between normal and malicious activities, allowing for the detection of compromises by identifying deviations from established patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If honey tokens are deployed in enterprise networks to detect intrusions, then intrusion detection capability is improved, but false alarm rate increases and token reliability decreases due to inadvertent removal or deactivation by users

Engineering Contradiction:
Improvetoken effectivenessVSAvoidfalse alarms
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system dynamically adjusts token behavior based on operational context. Tokens are configured to generate network traffic only under specific conditions (e.g., when accessed from external networks or at unusual times), allowing them to remain dormant during normal operations and activate only when suspicious activity is detected, thereby reducing false alarms while maintaining detection capability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameters of tokens based on their deployment location and purpose. Tokens are configured with different trigger conditions, traffic patterns, and monitoring thresholds depending on whether they are deployed on internal or external networks, which optimizes their effectiveness while minimizing false alarms from legitimate user activities

Inventive Principle:
Principle #35Parameter changes

2Reliability

If honey tokens are placed in accessible locations to maximize detection probability, then intrusion detection capability is improved, but tokens are more likely to be inadvertently removed or deactivated by authorized users

Engineering Contradiction:
Improvetoken persistenceVSAvoiduser interaction with tokens
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system introduces an intermediary layer between users and tokens through network proxies and traffic routing mechanisms. Tokens are placed in locations where they can be effectively monitored, but their network communications are mediated through proxy servers that can detect and block attempts to access or modify the tokens, preventing inadvertent removal while maintaining detection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements preliminary protective measures by configuring tokens with monitoring agents and network policies that detect and prevent attempts to access, modify, or remove them before such actions can occur. Authorized users are blocked from interacting with tokens through network-level restrictions, while the tokens remain positioned to effectively detect external intrusions

Inventive Principle:
Principle #9Preliminary anti-action

3Measurement precision

If noisy tokens are configured to generate network traffic for all local operations, then detection sensitivity is improved, but network performance degradation increases and false alarms rise

Engineering Contradiction:
Improveanomaly detection sensitivityVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial monitoring by configuring tokens to generate network traffic only for specific types of operations or under certain conditions, rather than monitoring all local operations. This selective approach maintains adequate detection sensitivity for security-critical activities while reducing the overall network traffic burden and minimizing performance degradation

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system uses periodic sampling of token operations instead of continuous monitoring. Tokens generate network traffic at intervals or in response to specific triggers (e.g., every N operations, or only on detected anomalies), which maintains detection capability while significantly reducing network overhead and preventing performance degradation from constant traffic generation

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10469523B2Techniques for detecting compromises of enterprise end stations utilizing noisy tokens
Publication Date: 2019.11.05 IMPERVA INC
  • US10469523B2 patent drawing
  • US10469523B2 patent drawing
  • US10469523B2 patent drawing

AI summary

Noisy tokens can be placed in locations of client end stations such that local operations performed upon the noisy tokens generate network traffic. A traffic monitoring module (TMM) can determine normal activity patterns of network traffic resulting from one or more of the placed noisy tokens being activated by one or more non-malicious operations, and identify that other network traffic resulting from one or more of the noisy tokens being activated does not meet the one or more normal activity patterns. In response, the TMM can cause an alert to be generated.