IP Library Granted Patent US 9,807,114
Granted Patent B2
US 9,807,114 · App. 14/844,844 · Granted Oct 31, 2017

System and a method for identifying the presence of malware using mini-traps set at network endpoints

Inventors: Doron Kolton (Pardesia, IL); Rami Mizrahi (Herzelia, IL); Omer Zohar (Rishon-LeZion, IL); Benny Ben-Rabi (Beit-Shemesh, IL); Alex Barbalat (Rishon-LeZion, IL); Shlomi Gabai (Rishon-LeZion, IL)
Assignee: TOPSPIN SECURTIY LTD
H04L63/1491H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,807,114
App. No.
14/844,844
Granted
Oct 31, 2017
Kind
B2
Abstract

A system for identifying the presence of advanced persistent threats on a network including a plurality of resources, interconnected to form a network, at least one decoy resource, at least one mini-trap installed on at least one of the plurality of resources and functionally associated with at one of the at least one decoy resource, the at least one mini-trap comprising deceptive information directing malware accessing the at least one mini-trap to the decoy resource associated therewith, and a manager node forming part of the network, locally or remotely, and configured to manage placement of the at least one mini-trap on the at least one of the plurality of resources and association between the at least one mini-trap and the decoy resource associated therewith.

Claims (26)

1. A system for identifying the presence of advanced persistent threats on a network, comprising:

a plurality of resources, interconnected to form a network;

at least one decoy resource forming part of said network, at least one of said at least one decoy resource comprising a virtual decoy resource;

at least one mini-trap installed on at least one of said plurality of resources and functionally associated with at least one of said at least one decoy resource, said at least one mini-trap comprising deceptive information directing malware accessing said at least one mini-trap to said decoy resource associated therewith, such that said malware proceeds from said at least one mini-trap to said decoy resource associated therewith; and

a manager node forming part of said network and configured to manage placement of said at least one mini-trap on said at least one of said plurality of resources and association between said at least one mini-trap and said decoy resource associated therewith

wherein each of said at least one mini-trap is associated with a unique value, such that when infecting malware accesses one of said at least one mini-trap located on a specific one of said plurality of resources, the mini-trap being accessed is uniquely identified, thereby uniquely identifying the specific resource as being infected.

2. The system of claim 1 , wherein said deceptive information comprises faked credentials.

3. The system of claim 1 , wherein said at least one mini-trap comprises a plurality of mini traps, said at least one decoy resource comprises a plurality of decoy resources, and wherein at least two of said plurality of mini-traps are associated with different ones of said plurality of decoy resources.

4. The system of claim 1 , wherein said at least one mini-trap comprises a plurality of mini traps, and wherein at least two of said plurality of mini-traps are associated with the same one of said at least one decoy resource.

5. The system of claim 1 , wherein said manager node comprises a user interface, allowing a user to configure said network, set up one or more of said at least one mini-trap and of said at least one decoy resource, and gather information from said at least one decoy resource.

6. The system of claim 1 , wherein said network comprises at least two Local Area Networks (LANs), said at least one mini-trap is installed on a resource in a first of said at least two LANs, and said at least one decoy resource associated with said at least one mini-trap is on a second of said at least two LANs.

7. The system of claim 6 , wherein said at least two LANs are geographically distributed.

8. The system of claim 1 , further comprising at least one traffic sniffer functionally associated with said at least one mini-trap, configured to sniff use of said at least one mini-trap and thereby to indicate the presence of infecting malware.

9. A method for identifying the presence of advanced persistent threats on a network including a plurality of resources, the method comprising:

providing at least one decoy resource forming part of the network, at least one of said at least one decoy resource comprising a virtual decoy resource;

installing at least one mini-trap on at least one of said plurality of resources, said at least one mini-trap being functionally associated with at least one of said at least one decoy resource, said at least one mini-trap comprising deceptive information directing malware accessing said at least one mini-trap to said at least one decoy resource associated therewith, such that said malware proceeds from said at least one mini-trap to said decoy resource associated therewith;

associating each of said at least one mini-trap with a unique value, such that when infecting malware accesses one of said at least one mini-trap located on a specific one of said plurality of resources, the mini-trap being accessed is uniquely identified, thereby uniquely identifying the specific resource as being infected;

detecting use of said at least one mini-trap by infecting malware by detecting said unique value associated with said at least one mini-trap, thereby to identify the presence of malware on said at least one of said plurality of resources where said at least one mini-trap is installed; and

managing placement of said at least one mini-trap on said at least one of said plurality of resources and association between said at least one mini-trap and said decoy resources associated therewith.

10. The method of claim 9 , wherein said detecting comprises sniffing use of said at least one mini-trap in traffic in said network.

11. The method of claim 9 , wherein said installing comprises at least one of the following:

planting said at least one mini-trap on said one of said plurality of resources using Active Directory GPO tools;

planting said at least one mini-trap on said one of said plurality of resources using administrator credentials and authorizations;

directly accessing said one of said plurality of resources to plant said at least one mini-trap thereon; and

running agents on said plurality of resources for planting said at least one mini-trap thereon.

12. The method of claim 9 , further comprising periodically updating said functional association between said at least one mini-trap and said at least one decoy resource.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2023
From: FIDELIS CYBERSECURITY, INC.
To: RUNWAY GROWTH FINANCE CORP.
Reel/Frame 065041/0694 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: RUNWAY GROWTH FINANCE CORP. (F/K/A RUNWAY GROWTH CREDIT FUND INC.)
To: FIDELIS SECURITY LLC
Reel/Frame 064455/0804 →
SECURITY INTEREST Recorded Jul 27, 2023
From: FIDELIS CYBERSECURITY, INC.
To: RUNWAY GROWTH CREDIT FUND INC.
Reel/Frame 064404/0315 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: TOPSPIN SECURITY LTD
To: FIDELIS CYBERSECURITY, INC.
Reel/Frame 050600/0295 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2015
From: KOLTON, DORON; MIZRAHI, RAMI; ZOHAR, OMER; BEN-RABI, BENNY; BARBALAT, ALEX; GABAI, SHLOMI
To: TOPSPIN SECURITY LTD
Reel/Frame 036490/0913 →
Continuity (2)
Provisional Application 62046319 · Sep 5, 2014
Related Publication 20160072838A1 · Mar 10, 2016