Specious Data Defense for Cloud Service Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems face challenges in protecting data from unauthorized access while ensuring uninterrupted access for authorized parties, as existing security measures are often breached, leading to economic impacts and operational disruptions.

Innovation Solution

Implementing a system that generates and provides specious data in response to unauthorized access requests, using triggers such as authentication failures or malformed queries, and employs tarpiting techniques and Data Loss Prevention (DLP) to delay and detect attacks, with specious data generated based on grammars and rules to mimic actual data attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are implemented to protect data, then data security is improved, but the system becomes vulnerable to sophisticated attacks that can still breach security and cause economic losses

Engineering Contradiction:
Improvedata securityVSAvoidattack success rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system converts harmful attack attempts into beneficial security enhancements by analyzing attack patterns to improve detection capabilities and generate more effective specious data responses that confuse and delay attackers

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system creates copies of legitimate data (specious data) that mimic real data attributes to confuse attackers. These fake data copies are generated based on grammars and rules that replicate the structure and appearance of actual data, making it difficult for attackers to distinguish between real and fabricated information

Inventive Principle:
Principle #26Copying

2Reliability

If security measures are strengthened to prevent unauthorized access, then data protection is improved, but authorized access may be interrupted or delayed

Engineering Contradiction:
Improvedata protectionVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different response qualities to different access requests based on their characteristics. Legitimate requests receive normal service, while suspicious requests receive specious data responses. This localized differentiation allows the system to maintain normal operations for authorized users while providing enhanced protection against attackers

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an intermediary layer that analyzes access requests and generates appropriate responses. This intermediary component sits between the attacker and the actual data, filtering and transforming requests to protect data while maintaining legitimate access through the same interface

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If the system provides detailed data to satisfy access requests, then data availability is improved, but attackers can more effectively exfiltrate and utilize the data

Engineering Contradiction:
Improvedata access efficiencyVSAvoiddata exfiltration effectiveness
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The system generates copies of data that replicate the structure, format, and apparent validity of real data. These specious data copies satisfy attacker requests for detailed information while containing no actual valuable data, thereby maintaining data availability for legitimate purposes while preventing effective exfiltration

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes the parameters of data responses based on the characteristics of access requests. For suspicious requests, the system modifies data parameters to create specious responses that appear legitimate but contain fabricated information, thereby changing the quality of data provided without affecting the quantity or structure expected by attackers

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11055425B2Service defense techniques
Publication Date: 2021.07.06 AMAZON TECH INC
  • US11055425B2 patent drawing
  • US11055425B2 patent drawing
  • US11055425B2 patent drawing

AI summary

A request to access a computing resource of a computing resource service provider is determined to be associated with specious data previously generated by the computing resource service provider. Information about an entity associated with the request is determined from the request. The information is provided to a breach detection system as notification of a potential attack against the computing resource service provider.