IP Library Granted Patent US 10,599,842
Granted Patent B2
US 10,599,842 · App. 15/383,522 · Granted Mar 24, 2020

Deceiving attackers in endpoint systems

Inventors: Venu Vissametty (San Jose, CA); Muthukumar Lakshmanan (Bangalore, IN); Harinath Vishwanath Ramchetty (Bengaluru, IN); Vinod Kumar A. Porwal (Bangalore, IN)
Assignee: ATTIVO NETWORKS INC.
G06F21/556G06F21/6218G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,599,842
App. No.
15/383,522
Granted
Mar 24, 2020
Kind
B2
Abstract

Endpoints in a network execute a sensor module that intercepts commands. The sensor module compares a source of commands to a sanctioned list of applications received from a management server. If the source does not match a sanctioned application and the command is a write or delete command, the command is ignored and a simulated acknowledgment is sent. If the command is a read command, deception data is returned instead. In some embodiments, certain data is protected such that commands will be ignored or modified to refer to deception data where the source is not a sanctioned application. The source may be verified to be a sanctioned application by evaluating a certificate, hash, or path of the source.

Claims (46)

1. A method comprising:

providing on a computer system a listing of sanctioned applications;

receiving, by the computer system, a command referencing subject data from a source;

(a) determining, by the computer system, that the command was not received from one of the sanctioned applications by determining that a certificate of the source does not match a certificate of one of the sanctioned applications, a hash of binary code for the source does not match a hash of one of the sanctioned applications, and that a path to the binary code for the source does not match a path of one of the sanctioned applications; and

(b) in response to (a) refraining from executing the command with respect to the subject data;

(c) determining, by the computer system, that the command is a request for the subject data;

in response to (c), passing, by the computer system, the command to an operating system executing on the computer system having a reference to the subject data replaced with a reference to deception data that is different from the subject data, the subject data having a format, the deception data being decoy data having the format, the subject data referencing a production server and the deception data referencing a decoy server that is different from the production server and coupled to the computer system by a network;

(d) detecting, by the decoy server, an attempt by a module to access the deception server using the deception data;

in response to (d), engaging and monitoring the module;

(e) determining that the command is a request to modify the subject data; and

in response to (e), refraining from executing the request to modify the subject data and returning to a source of the command an indication that the request to modify the subject data was executed successfully.

2. The method of claim 1 , further comprising:

providing on the computer system a listing of protected data;

(e) determining that the subject data is included in the protected data; and

performing (a) and (b) in response to (e).

3. The method of claim 1 , wherein the command is a first command, the method further comprising:

receiving a second command referencing the subject data;

(e) determining that the second command was generated by an application in the list of sanctioned applications; and

in response to (e), executing the second command with respect to the subject data.

4. A system comprising one or more processing devices and one or more memory devices operably coupled to the one or more processing devices, the one or more memory devices storing executable code to cause the one or more processing devices to:

store a listing of sanctioned applications;

execute one or more instances of one or more of the sanctioned applications;

receive, by an operating system, a command referencing subject data from a source; and

in response to receiving the command referencing the subject data—

intercepting, by a sensor, the command;

(a) if the a certificate of the source does not match a certificate of one of the sanctioned applications, a hash of binary code for the source does not match a hash of one of the sanctioned applications, and that a path to the binary code for the source does not match a path of one of the sanctioned applications, prevent execution of the command by the operating system with respect to the subject data;

wherein the one or more memory devices further store executable code to cause the one or more processing devices to:

if the command is a request for the subject data, the subject data being included in protected data, and the command was not received from one of the one or more instances, pass the command to the operating system having a reference to the subject data replaced with a reference to deception data that is different from the subject data but has a format corresponding to the subject data;

if the command is a request to modify the subject data, the subject data is included in the protected data, and the command was not received from one of the one or more instances, refrain from executing the request to modify the subject data and return to the source an indication that the request to modify the subject data was executed successfully;

wherein the system further comprises an engagement computing device connected to the one or more processing devices by a network, the deception data referencing the engagement computing device, the engagement computing device being programmed to engage modules attempting to access the engagement computing device using the deception data.

5. The system of claim 4 , wherein the one or more memory devices further store executable code to cause the one or more processing devices to:

store a listing of protected data;

in response to receiving the command referencing the subject data—

perform (a) only if the subject data is included in the protected data.

6. The system of claim 4 , wherein the one or more memory devices further store executable code to cause the one or more processing devices to permit execution of the command by the operating system with respect to the subject data only if at least one of:

a source of the command has a certificate matching one of the sanctioned applications;

a hash of binary code for a source of the command matches a hash of one of the sanctioned applications; and

a path to binary code corresponding a source of the command matches a path to one of the sanctioned applications.

7. The system of claim 4 , wherein the subject data is a browsing history file and the deception data is a simulated browser history file.

8. The system of claim 4 , wherein the command is a shadowcopy delete command and the subject data is a backup volume.

9. The system of claim 4 , wherein:

the subject data is a registry of the computer system;

the command is a query to determine whether the registry references an antivirus program; and

wherein the one or more memory devices further store executable code to cause the one or more processing devices to:

simulate a response to the command that indicates that the registry references the antivirus program even though the registry does not reference the antivirus program.

10. The system of claim 4 , wherein the deception data is a credential that is sufficient to authenticate with respect to the engagement computing device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2023
From: ATTIVO NETWORKS, INC.
To: SENTINELONE, INC.
Reel/Frame 062607/0046 →
SECURITY INTEREST Recorded May 7, 2020
From: ATTIVO NETWORKS, INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 052601/0978 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2016
From: VISSAMSETTY, VENU; LAKSHMANAN, MUTHUKUMAR; RAMCHETTY, HARINATH VISHWANATH; PORWAL, VINOD KUMAR A.
To: ATTIVO NETWORKS INC.
Reel/Frame 040672/0350 →
Continuity (1)
Related Publication 20180173876A1 · Jun 21, 2018
Cited By (15)
US 12,206,698 US 12,235,962 US 12,244,626 US 12,259,967 US 12,261,884 US 12,341,814 US 12,363,151 US 12,418,565 US 12,423,078 US 12,432,253 US 12,450,351 US 12,452,273 US 12,468,810 US 12,579,268 US 12,664,258