Techniques for incentivized intrusion detection system
The present disclosure relates generally to security solutions. More specifically, techniques (e.g., systems, methods, and devices) are provided to implement an incentivized-based intrusion detection system to detect malicious acts against an asset. The incentive may lure or facilitate the actor to provide information detecting malicious actions against an asset.
1. A method comprising:
deploying a plurality of assets to a target environment, wherein each of the plurality of assets is associated with a respective incentive of a plurality of incentives;
deploying a smart contract to a distributed ledger, wherein initiation of the smart contract is based on at least one asset of the plurality of assets and causes a respective at least one incentive of the plurality of incentives to be transferred and wherein transactions relating to the smart contract are written to the distributed ledger;
monitoring the distributed ledger; and
in response to detecting, on the distributed ledger, a transfer of an incentive of the plurality of incentives caused by initiation of the smart contract, detecting an intrusion of the target environment.
2. The method of claim 1 , wherein the smart contract is configured to be:
initiated using a first asset of the plurality of assets to cause a first incentive of the plurality of incentives to be transferred; and
initiated using a second asset of the plurality of assets to cause a second incentive of the plurality of incentives to be transferred.
3. The method of claim 2 , wherein the smart contract is configured to be initiated using the second asset only after the smart contract is initiated using the first asset.
4. The method of claim 1 , wherein the plurality of incentives are valid for a limited time.
5. The method of claim 1 , wherein values of the plurality of incentives decrease over time.
6. The method of claim 1 , further comprising generating an alert based on the intrusion of the target environment.
7. The method of claim 1 , further comprising detecting access of an asset of the plurality of assets in the target environment.
8. The method of claim 7 , further comprising, based on detecting access of the asset of the plurality of assets in the target environment, obtaining at least a portion of metadata associated with the asset.
9. The method of claim 8 , wherein the at least a portion of the metadata comprises a script that initiates the smart contract.
10. An intrusion-detection system comprising:
at least one memory; and
at least one processor coupled to the at least one memory and configured to:
deploy one or more assets to a repository on a digital environment;
detect that a first incentive, associated with a first asset of the one or more assets, has been claimed through initiation of a smart contract using the first asset;
detect that a second incentive, associated with a second asset of the one or more assets, has been claimed through initiation of the smart contract using the second asset; and
responsive to detecting that the first incentive has been claimed, detect access of the repository.
11. The intrusion-detection system of claim 10 , wherein the smart contract is configured to be initiated using the second asset only after the smart contract is initiated using the first asset.
12. The intrusion-detection system of claim 10 , wherein the first incentive and the second incentive are valid for a limited time.
13. The intrusion-detection system of claim 10 , wherein a first value of the first incentive decreases over time and wherein a second value of the second incentive decreases over time.
14. The intrusion-detection system of claim 10 , further comprising generating an alert based detecting access of the repository.
15. A non-transitory computer-readable storage medium having stored thereon instructions that, when executed by at least one processor, cause the at least one processor to:
deploy a plurality of assets to a target environment, wherein each of the plurality of assets is associated with a respective incentive of a plurality of incentives;
deploy a smart contract to a distributed ledger, wherein initiation of the smart contract is based on at least one asset of the plurality of assets and causes a respective at least one incentive of the plurality of incentives to be transferred and wherein transactions relating to the smart contract are written to the distributed ledger;
monitor the distributed ledger; and
in response to detecting, on the distributed ledger, a transfer of an incentive of the plurality of incentives, detect an intrusion of the target environment.
16. The non-transitory computer-readable storage medium of claim 15 , wherein the smart contract is configured to be:
initiated using a first asset of the plurality of assets to cause a first incentive of the plurality of incentives to be transferred; and
initiated using a second asset of the plurality of assets to cause a second incentive of the plurality of incentives to be transferred.
17. The non-transitory computer-readable storage medium of claim 16 , wherein the smart contract is configured to be initiated using the second asset only after the smart contract is initiated using the first asset.
18. The non-transitory computer-readable storage medium of claim 15 , wherein the plurality of incentives are valid for a limited time.
19. The non-transitory computer-readable storage medium of claim 15 , wherein values of the plurality of incentives decrease over time.
20. The non-transitory computer-readable storage medium of claim 15 , further comprising generating an alert based on the intrusion of the target environment.