IP Library Granted Patent US 10,091,238
Granted Patent B2
US 10,091,238 · App. 15/448,581 · Granted Oct 2, 2018

Deception using distributed threat detection

Inventors: Choung-Yaw Shieh (Palo Alto, CA); Marc Woolward (Santa Cruz, CA); Zhiping Liu (Saratoga, CA); Cheng-Lin Hou (San Jose, CA); Matthew M. Williamson (Marblehead, MA); Yi Hung Cheng (Taipei, TW); Chien Yang Hsu (New Taipei, TW); Hsin Tien Tseng (Taipei, TW)
Assignee: vArmour Networks, Inc.
H04L63/1491H04L63/029H04L63/0263H04L63/10H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,091,238
App. No.
15/448,581
Granted
Oct 2, 2018
Kind
B2
Abstract

Methods and systems for deception using distributed threat detection are provided. Exemplary methods by an enforcement point, the enforcement point communicatively coupled to a first data network and a second data network, the enforcement point not providing services in the second data network, include: receiving, from a first workload in the second data network, a data packet addressed to a second workload in the second data network, the data packet requesting a service from the second workload; determining the data packet is for unauthorized access of the second workload, the determining using at least some of a 5-tuple of the data packet; identifying a deception point using the service, the deception point being in the first data network and including a decoy for the service; and redirecting the data packet to the deception point in the first data network.

Claims (52)

1. A method by an enforcement point, the enforcement point communicatively coupled to a first data network and a second data network, the enforcement point not providing services in the second data network, the method comprising:

receiving, from a first workload in the second data network, a data packet addressed to a second workload in the second data network, the data packet requesting a service from the second workload;

determining the data packet is for unauthorized access of the second workload, the determining using at least some of a 5-tuple of the data packet;

identifying a deception point using the service, the deception point being in the first data network and including a decoy for the service; and

redirecting the data packet to the deception point in the first data network, the deception point:

getting the data packet;

emulating an application providing the service;

producing a response to the data packet using the emulating and the data packet; and

providing the response to the first workload such that the response appears to originate from the second workload.

2. The method of claim 1 , wherein the deception point is at least one of a bare-metal server and virtual machine.

3. The method of claim 1 , wherein the deception point further performs a method comprising:

getting an image for an application;

creating an instance of the application in a container using the image, the creating including:

producing the container using the image;

allocating a filesystem of a host operating system to the container;

adding a read-write layer to the image; and

launching a process specified by the image; and

monitoring behavior from the processing, the monitoring including intercepting library calls, function calls, messages, and events from the container.

4. The method of claim 1 , wherein the redirecting includes using a tunnel to forward the data packet to the deception point.

5. The method of claim 1 , wherein the determining includes comparing the at least some of the 5-tuple of the data packet to a low-level rule set.

6. The method of claim 5 , wherein the low-level rule set is produced using a high-level policy.

7. The method of claim 1 , wherein the determining comprises analyzing the data packet using predefined attack signatures.

8. The method of claim 1 , wherein the providing the response to the first workload includes sending the response through the enforcement point.

9. The method of claim 1 , wherein the providing the response to the first workload includes using network address translation to send the response.

10. The method of claim 1 , wherein the first data network and the second data network are in the same logical subnetwork and in different physical networks.

11. An enforcement point, the enforcement point communicatively coupled to a first data network and a second data network, the enforcement point not providing services in the second data network, the enforcement point comprising:

at least one hardware processor; and

a memory coupled to the at least one hardware processor, the memory storing instructions executable by the at least one hardware processor to perform a method comprising:

receiving, from a first workload in the second data network, a data packet addressed to a second workload in the second data network, the data packet requesting a service from the second workload;

determining the data packet is for unauthorized access of the second workload, the determining using at least some of a 5-tuple of the data packet;

identifying a deception point using the service, the deception point being in the first data network and including a decoy for the service; and

redirecting the data packet to the deception point in the first data network, the deception point:

getting the data packet;

emulating an application providing the service;

producing a response to the data packet using the emulating and the data packet; and

providing the response to the first workload such that the response appears to originate from the second workload.

12. The enforcement point of claim 11 , wherein the deception point is at least one of a bare-metal server and virtual machine.

13. The enforcement point of claim 11 , wherein the deception point further performs a method comprising:

getting an image for an application;

creating an instance of the application in a container using the image, the creating including:

producing the container using the image;

allocating a filesystem of a host operating system to the container;

adding a read-write layer to the image; and

launching a process specified by the image; and

monitoring behavior from the processing, the monitoring including intercepting library calls, function calls, messages, and events from the container.

14. The enforcement point of claim 11 , wherein the redirecting includes using a tunnel to forward the data packet to the deception point.

15. The enforcement point of claim 11 , wherein the determining includes comparing the at least some of the 5-tuple of the data packet to a low-level rule set.

16. The enforcement point of claim 15 , wherein the low-level rule set is produced using a high-level security policy.

17. The enforcement point of claim 11 , wherein the determining comprises analyzing the data packet using predefined attack signatures.

18. The enforcement point of claim 11 , wherein the providing the response to the first workload includes sending the response through the enforcement point.

19. The enforcement point of claim 11 , wherein the providing the response to the first workload includes using network address translation to send the response.

20. The enforcement point of claim 11 , wherein the first data network and the second data network are in the same logical subnetwork and in different physical networks.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Jul 18, 2025
From: GRYPHO5, LLC
To: EVP CREDIT SPV I LP
Reel/Frame 072053/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: VARMOUR NETWORKS, INC.
To: GRYPHO5, LLC
Reel/Frame 070287/0007 →
SECURITY INTEREST Recorded Feb 22, 2024
From: VARMOUR NETWORKS, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 066530/0399 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2018
From: SHIEH, CHOUNG-YAW; WOOLWARD, MARC; LIU, ZHIPING; HOU, CHENG-LIN; WILLIAMSON, MATTHEW M.; CHENG, YI HUNG; HSU, CHIEN YANG; TSENG, HSIN TIEN
To: VARMOUR NETWORKS, INC.
Reel/Frame 045149/0739 →
Continuity (10)
Continuation In Part 14480318 · Sep 8, 2014
Continuation In Part 14677827 · Apr 2, 2015
Continuation In Part 15413417 · Jan 24, 2017
Continuation In Part 14480318 · Sep 8, 2014
Continuation In Part 15299433 · Oct 20, 2016
Continuation In Part 15201351 · Jul 1, 2016
Continuation In Part 15192967 · Jun 24, 2016
Continuation In Part 15394640 · Dec 29, 2016
Provisional Application 61965981 · Feb 11, 2014
Related Publication 20170180421A1 · Jun 22, 2017
Cited By (2)
US 12,647,444 US 12,647,445