IP Library Granted Patent US 9,954,878
Granted Patent B2
US 9,954,878 · App. 15/175,052 · Granted Apr 24, 2018

Multi-factor deception management and detection for malicious actions in a computer network

Inventors: Shlomo Touboul (Kfar Chaim, IL); Hanan Levin (Tel Aviv, IL); Stephane Roubach (Herzliya, IL); Assaf Mischari (Petach Tikva, IL); Itai Ben David (Tel Aviv, IL); Itay Avraham (Tel Aviv, IL); Adi Ozer (Shoham, IL); Chen Kazaz (Tel Aviv, IL); Ofer Israeli (Tel Aviv, IL); Olga Vingurt (Shderot, IL); Liad Gareh (Herzliya, IL); Israel Grimberg (Ra'anana, IL); Cobby Cohen (Tel Aviv, IL); Sharon Sultan (Tel Aviv, IL); Matan Kubovsky (Tel Aviv, IL)
Assignee: ILLUSIVE NETWORKS LTD.
H04L63/1416H04L63/1491H04L29/06904H04L63/10H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,954,878
App. No.
15/175,052
Granted
Apr 24, 2018
Kind
B2
Abstract

A network surveillance system, including a management server within a network of resources in which users access the resources in the network based on credentials, including a deployment module planting honeytokens in resources in the network, wherein a honeytoken is an object in memory or storage of a first resource that may be used by an attacker to access a second resource using decoy credentials, and wherein the deployment module plants a first honeytoken in a first resource, R 1 , used to access a second resource, R 2 , using first decoy credentials, and plants a second honeytoken in R 2 , used to access a third resource, R 3 , using second decoy credentials, and an alert module alerting that an attacker is intruding the network only in response to both an attempt to access R 2 using the first decoy credentials, and a subsequent attempt to access R 3 using the second decoy credentials.

Claims (8)

1. A system for multi-factor network surveillance to detect attackers, comprising:

a management server within a network of resources in which users access the resources based on credentials, comprising a memory containing instructions and a processor that executes the instructions to plant decoy credentials DC 1 , DC 2 , and DC 3 , in memory or storage of respective resources R 1 , R 2 and R 3 , wherein the decoy credentials DC 1 DC 2 and DC 3 may be used by an attacker to access respective resources R 2 , R 3 and R 4 , and wherein R 1 is a bona fide enterprise resource, and R 2 , R 3 and R 4 are decoy resources for the purpose of intrusion detection; and

a security manager comprising a memory containing instructions and a processor that executes the instructions to receive reports of attempts to use decoy credentials and to generate an alert that an attacker is intruding the network only when attempts to use the three decoy credentials DC 1 DC 2 and DC 3 are reported.

2. The system of claim 1 wherein credentials include passwords for accessing resources in the network, and wherein the decoy credentials include respective hash versions of corresponding passwords.

3. The system of claim 1 wherein credentials include members of the group consisting of user credentials, FTP server credentials and SSH server credentials.

4. A system for multi-factor network surveillance to detect attackers, comprising:

a management server within a network of resources, comprising a memory containing instructions and a processor that executes the instructions to plant honeytokens HT 1 HT 2 and HT 3 in respective resources R 1 , R 2 and R 31 wherein honeytokens HT 1 HT 2 and HT 3 are objects in memory or storage of R 1 , R 2 and R 3 , respectively, that may be used by an attacker to discover existence of R 2 , R 3 and R 4 , respectively, and wherein R 1 is a bona fide enterprise resource and R 2 , R 3 and R 4 are decoy resources for the purpose of intrusion detection; and

a security manager comprising a memory containing instructions and a processor that executes the instructions to receive reports of attempts to access resources, and to generate an alert that an attacker is intruding the network only when attempts to access the three resources R 2 , R 3 and R 4 are reported.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2024
From: ILLUSV NETWORKS LTD.
To: PROOFPOINT ISRAEL HOLDINGS LTD.
Reel/Frame 069461/0191 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2016
From: TOUBOUL, SHLOMO; LEVIN, HANAN; ROUBACH, STEPHANE; MISCHARI, ASSAF; BEN DAVID, ITAI; AVRAHAM, ITAY; OZER, ADI; KAZAZ, CHEN; ISRAELI, OFER; VINGURT, OLGA; GAREH, LIAD; GRIMBERG, ISRAEL; COHEN, COBBY; SULTAN, SHARON; KUBOVSKY, MATAN
To: ILLUSIVE NETWORKS LTD.
Reel/Frame 039695/0169 →
Continuity (6)
Provisional Application 62172251 · Jun 8, 2015
Provisional Application 62172253 · Jun 8, 2015
Provisional Application 62172255 · Jun 8, 2015
Provisional Application 62172259 · Jun 8, 2015
Provisional Application 62172261 · Jun 8, 2015
Related Publication 20170230384A1 · Aug 10, 2017