IP Library Granted Patent US 9,992,225
Granted Patent B2
US 9,992,225 · App. 14/847,315 · Granted Jun 5, 2018

System and a method for identifying malware network activity using a decoy environment

Inventors: Doron Kolton (Pardesia, IL); Rami Mizrahi (Herzelia, IL); Omer Zohar (Rishon-LeZion, IL); Benny Ben-Rabi (Beit-Shemesh, IL); Alex Barbalat (Rishon-LeZion, IL); Shlomi Gabai (Rishon-LeZion, IL)
H04L63/1491H04L63/145H04L63/1416H04L63/1441H04L2463/142H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,992,225
App. No.
14/847,315
Granted
Jun 5, 2018
Kind
B2
Abstract

A system for gathering information about malware and a method of use therefor, the system comprising a working environment including physical working environment servers, physical working environment endpoints, a working environment network, a switch, and a router directing traffic between said working environment network and an external network, a decoy environment including at least one physical machine, a decoy environment server, a decoy environment endpoint, a decoy environment network and a decoy environment router, a file directing mechanism directing at least some files to the decoy environment, and a threat tracking mechanism tracking and observing actions triggered by the files in the decoy environment.

Claims (23)

1. A method for identifying malware and for gathering information about identified malware in a decoy environment associated with a working environment, the method comprising:

providing a decoy environment including:

at least one physical machine;

at least one decoy environment server;

at least one decoy environment endpoint;

a decoy environment network interconnecting said at least one physical machine, said at least one decoy environment server and said at least one decoy environment endpoint; and

at least one traffic directing mechanism for directing traffic from an external network to said decoy environment network;

directing at least some files intended for the working environment to said at least one physical machine of said decoy environment;

executing said at least some files directed to said decoy environment on said at least one physical machine of said decoy environment; and

tracking and observing actions triggered by said at least some files in said decoy environment, and

upon receipt of a network request in said decoy environment network, said network request originating from attacking malware running in said decoy environment, generating in said decoy environment network a network response to said network request, the network response mimicking a response that would be made by a network of said working environment, said generating including:

collecting requests made to nodes in said network of said working environment and responses associated therewith in a database, said decoy environment network having access to said database, including collecting at least one of single request-response pairs and sessions of requests and responses;

upon receipt of said network request by said decoy environment network, finding in said database a past request, similar to said received network request; and

from said decoy environment network, providing a response to said received request, said response based on a past response associated with said past request in said database.

2. The method of claim 1 , wherein said collecting comprises maintaining, in said collected requests and responses, a structure of traffic within said network of said organization.

3. The method of claim 1 , wherein said database is dedicated to a specific type of communication or server, and wherein said collected requests and responses relate to said specific type of communication or server.

4. The method of claim 1 , further comprising identifying suspicious files intended for said working environment, and transferring said suspicious files to said traffic directing mechanism for directing to said decoy environment.

5. The method of claim 1 , wherein said directing at least some files comprises directing all files intended for said working environment to said decoy environment.

6. The method of claim 1 , at least one of said at least one decoy environment server and said at least one decoy environment endpoint comprises said at least one physical machine.

7. The method of claim 1 , at least one of said at least one decoy environment server and said at least one decoy environment endpoint comprises a virtual machine.

8. The method of claim 1 , said tracking and observing further comprising providing information about tracked and observed actions triggered by one or more of said at least some files to said working environment.

9. The method of claim 1 , wherein said working environment includes network traffic, and said providing said decoy environment includes providing in said decoy environment network, network traffic mimicking said network traffic in said working environment.

10. The method of claim 1 , wherein said at traffic directing mechanism comprises at least one router.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2023
From: FIDELIS CYBERSECURITY, INC.
To: RUNWAY GROWTH FINANCE CORP.
Reel/Frame 065041/0694 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: RUNWAY GROWTH FINANCE CORP. (F/K/A RUNWAY GROWTH CREDIT FUND INC.)
To: FIDELIS SECURITY LLC
Reel/Frame 064455/0804 →
SECURITY INTEREST Recorded Jul 27, 2023
From: FIDELIS CYBERSECURITY, INC.
To: RUNWAY GROWTH CREDIT FUND INC.
Reel/Frame 064404/0315 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: TOPSPIN SECURITY LTD
To: FIDELIS CYBERSECURITY, INC.
Reel/Frame 050600/0295 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2015
From: KOLTON, DORON; MIZRAHI, RAMI; ZOHAR, OMER; BEN-RABI, BENNY; BARBALAT, ALEX; GABAI, SHLOMI
To: TOPSPIN SECURITY LTD
Reel/Frame 036509/0889 →
Continuity (2)
Provisional Application 62049650 · Sep 12, 2014
Related Publication 20160080414A1 · Mar 17, 2016