WebAssembly Deception Binaries for Scalable IT Asset Decoys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current deception technology solutions are inefficient, costly, and vulnerable due to the use of honeypots, scalability issues, and shared host operating systems, leading to ineffective deceptions and increased maintenance costs.
Innovation Solution
Utilizing Web Assembly technology to generate deception binaries that are compatible with various operating systems and browsers, eliminating the need for intermediary trap servers and containers, and deploying customized deceptions through an agent-less approach.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If honeypots are used for deception, then deception capability is provided, but device complexity and maintenance overhead increase
Solution Approach 1:
The patent uses WebAssembly binaries as lightweight copies of deception assets that can be deployed across multiple endpoints without requiring full honeypot installations. These binaries replicate the deceptive functionality while consuming minimal system resources, eliminating the need for complex honeypot infrastructure and reducing maintenance overhead significantly.
Solution Approach 2:
The WebAssembly deception binaries are designed to be lightweight, disposable artifacts that can be rapidly deployed and replaced. Unlike traditional honeypots that require ongoing maintenance and management, these binaries are self-contained and can be updated or replaced without affecting the underlying host system, reducing long-term maintenance complexity.
2Adaptability or versatility
If containers are used to deploy deceptions, then deployment flexibility is improved, but resource utilization increases
Solution Approach 1:
The patent extracts the deception functionality from resource-intensive container environments and embeds it directly into lightweight WebAssembly binaries that run natively on host systems. This extraction eliminates the overhead of container runtime, image management, and isolation layers while maintaining deployment flexibility across diverse endpoints.
3Ease of operation
If intermediary trap servers are used, then deception management is enabled, but device complexity and cost increase
Solution Approach 1:
The WebAssembly deception binaries are designed to be self-contained and self-managing artifacts that do not require intermediary trap servers for coordination or control. Each binary independently provides deception functionality on its host endpoint, eliminating the need for complex server infrastructure and reducing both device complexity and operational costs.
4Adaptability or versatility
If multiple operating systems are supported, then compatibility is improved, but manufacturing precision requirements increase
Solution Approach 1:
The WebAssembly binary format provides a universal execution environment that can run across multiple operating systems and architectures without requiring system-specific customization. The binary is designed to be architecture-agnostic, using standardized system calls and interfaces that work consistently across different platforms, eliminating the need for precise binary customization for each target system.
Data Source
AI summary
Deception management is provided. Configuration of a plurality of assets in an information technology (IT) environment of an entity is detected based on a scan of the plurality of assets. A plurality of deceptions is generated by customizing predefined deceptions based on specific needs of the entity corresponding to a geographic location of the IT environment. The plurality of deceptions are deployed among the plurality of assets within the IT environment based on the configuration of the plurality of assets in the IT environment.


