Patent Application for Decoy File Placement System to Protect Against Insider Threats
A new patent application has been filed for a system designed to protect against insider threats by automatically placing decoy files that match the theme of information attempted to be leaked by internal fraudsters. The system uses an access log to estimate the theme of information the high-risk user is attempting to leak, and then places a decoy file matching that theme in the target system. This approach aims to make it difficult for the internal fraudster to realize that the files are decoys, thus increasing the effectiveness of the deception system.
Key Takeaways:
- The patent application describes a system that estimates a decoy theme based on an access log indicating access in the target system by a high-risk user.
- The system places a decoy file matching the estimated decoy theme in the target system to deceive the internal fraudster.
- The high-risk user may be an internal fraudster or a malicious employee with the intention to leak information.
- The system calculates a risk value corresponding to each user based on their access pattern in the target system, and considers the user with a risk value equal to or greater than a risk criterion value as a high-risk user.
- The system selects a file from a database storing files that are candidates for the decoy file based on the estimated decoy theme.
- The system generates a file name for the decoy file based on the estimated decoy theme, and uses the selected file as the decoy file.
- The system estimates the decoy theme using natural language processing and a theme list consisting of multiple themes each of which is a candidate for the decoy theme.
- The system generates a file based on the estimated decoy theme as the decoy file.
- The system selects a template file from a database storing candidates for a template file corresponding to the decoy file based on the estimated decoy theme, and modifies the selected template file based on the estimated decoy theme.
- The system estimates the decoy theme based on a viewing time by the high-risk user of each file stored in the target system.
Statistics:
- The system is designed to protect against insider threats by placing decoy files that match the theme of information attempted to be leaked by internal fraudsters.
- The system uses an access log to estimate the theme of information the high-risk user is attempting to leak.
- The system places a decoy file matching the estimated decoy theme in the target system to deceive the internal fraudster.
- The system selects a file from a database storing files that are candidates for the decoy file based on the estimated decoy theme.
- The system generates a file name for the decoy file based on the estimated decoy theme, and uses the selected file as the decoy file.
- The system estimates the decoy theme using natural language processing and a theme list consisting of multiple themes each of which is a candidate for the decoy theme.
Sources:
- IWASAKI, Aiko; YAMAMOTO, Takumi. Information Processing Device, Information Processing Method, And Non-Transitory Computer Readable Medium. U.S. Patent Application Number 20250307392, filed June 17, 2025 and posted October 2, 2025. Patent URL: https://ppubs.uspto.gov/pubwebapp/external.html?q=(20250307392)&db=US-PGPUB&type=ids