IP Library Granted Patent US 9,742,805
Granted Patent B2
US 9,742,805 · App. 15/406,731 · Granted Aug 22, 2017

Managing dynamic deceptive environments

Inventors: Shlomo Touboul (Kfar Chaim, IL); Hanan Levin (Tel Aviv, IL); Stephane Roubach (Herzliya, IL); Assaf Mischari (Petach Tikva, IL); Itai Ben David (Tel Aviv, IL); Itay Avraham (Tel Aviv, IL); Adi Ozer (Shoham, IL); Chen Kazaz (Tel Aviv, IL); Ofer Israeli (Tel Aviv, IL); Olga Vingurt (Shderot, IL); Liad Gareh (Herzliya, IL); Israel Grimberg (Ra'anana, IL); Cobby Cohen (Tel Aviv, IL); Sharon Sultan (Tel Aviv, IL); Matan Kubovsky (Tel Aviv, IL)
Assignee: ILLUSIVE NETWORKS LTD.
H04L63/1491G06N99/005H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,742,805
App. No.
15/406,731
Granted
Aug 22, 2017
Kind
B2
Abstract

A deception management system (DMS) to detect attackers within a network of computer resources, including a discovery tool auto-learning the network naming conventions for user names, workstation names, server names and shared folder names, and a deception deployer generating one or more decoy attack vectors in the one or more resources in the network based on the network conventions learned by the discovery tool, so that the decoy attack vectors conform with the network conventions, wherein an attack vector is an object in a first resource of the network that has a potential to lead an attacker to access or discover a second resource of the network.

Claims (30)

1. A deception management system (DMS) to detect attackers within a network of computer resources, comprising:

a deception deployer planting one or more decoy attack vectors in memory or storage of one or more real resources in the network, an attack vector, of the one or more decoy attack vectors, being an object in a real resource of the network that has a potential to lead an attacker to access or discover a decoy resource of the network;

a deception adaptor self-triggering modification of activity logs of login access and data editing for one or more decoy resources, the one or more decoy resources appearing to the attacker as being active in the network; and

an access governor authorizing access to resources in the network, and issuing a notification upon recognizing an attempt to access one or more of the decoy resources of the network via one or more of the decoy attack vectors planted by said deception deployer.

2. The DMS of claim 1 wherein said deception deployer generates the one or more decoy resources.

3. The DMS of claim 1 further comprising a discovery tool inspecting the network to find real attack vectors that exist in real resources of the network and that have a potential to lead the attacker to access or discover other real resources of the network, and wherein said deception deployer plants decoy attack vectors that resemble the real attack vectors found by said discovery tool.

4. The DMS of claim 3 wherein said discovery tool learns characteristics of the network comprising at least one member of management tools, asset management, configuration management, user management, device management, installed applications, tools and data, and wherein the one or more decoy attack vectors planted by said deception deployer conform with the network characteristics.

5. The DMS of claim 4 , wherein said discovery tool learns the characteristics of the network based on information extracted from one or more of the following network resource management and administration modules: directory access, user management, asset management, configuration management, resource management, device management, storage management, application management, and file management.

6. The DMS of claim 1 , wherein the one or more decoy attack vectors planted by said deception deployer include at least one member of

a username and a password,

an RDP (Remote Desktop Protocol) username and a password,

a username and an authentication ticket,

an FTP (File Transfer Protocol) server address and a username and a password,

a database server address and a username and a password, and

an SSH (Secure Shell) server address and a username and a password.

7. A method for detecting attackers within a network of computer resources, comprising:

planting one or more decoy attack vectors in memory or storage of one or more real resources in the network, an attack vector, of the one or more decoy attacked vectors, being an object in a real resource of the network that has a potential to lead an attacker to access or discover a decoy resource of the network;

self-triggering modification of activity logs of login access and data editing for one or more decoy resources, the one or more decoy resources appearing to the attacker as being active in the network; and

issuing a notification upon recognizing an attempt to access one or more of the decoy resources of the network via one or more of the decoy attack vectors planted by said planting.

8. The method of claim 7 further comprising generating the one or more decoy resources.

9. The method of claim 7 further comprising inspecting the network to find real attack vectors that exist in real resources of the network and that have a potential to lead the attacker to access or discover other real resources of the network, and wherein said planting plants decoy attack vectors that resemble the real attack vectors found by said inspecting.

10. The method of claim 7 further comprising learning characteristics of the network comprising at least one member of management tools, asset management, configuration management, user management, device management, installed applications, tools and data, and wherein the one or more decoy attack vectors planted by said planting conform with the network characteristics.

11. The method of claim 10 , wherein said learning learns the characteristics of the network based on information extracted from one or more of the following network resource management and administration modules: directory access, user management, asset management, configuration management, resource management, device management, storage management, application management, and file management.

12. The method of claim 7 , wherein the one or more decoy attack vectors planted by said planting include at least one member of

a username and a password,

an RDP (Remote Desktop Protocol) username and a password,

a username and an authentication ticket,

an FTP (File Transfer Protocol) server address and a username and a password,

a database server address and a username and a password, and

an SSH (Secure Shell) server address and a username and a password.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2024
From: ILLUSV NETWORKS LTD.
To: PROOFPOINT ISRAEL HOLDINGS LTD.
Reel/Frame 069461/0191 →
Continuity (7)
Continuation 15175048 · Jun 7, 2016
Provisional Application 62172251 · Jun 8, 2015
Provisional Application 62172253 · Jun 8, 2015
Provisional Application 62172255 · Jun 8, 2015
Provisional Application 62172259 · Jun 8, 2015
Provisional Application 62172261 · Jun 8, 2015
Related Publication 20170134421A1 · May 11, 2017