IP Library Granted Patent US 10,230,761
Granted Patent B1
US 10,230,761 · App. 15/613,606 · Granted Mar 12, 2019

Method and system for detecting network compromise

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,230,761
App. No.
15/613,606
Granted
Mar 12, 2019
Kind
B1
Abstract

A method and system are described for detecting unauthorized access to one or more of a plurality of networked victim computers in a victim cloud. The networked victim computers connect to one or more DNS servers. The system includes one or more decoy bot computers, which are operated as victim computers in the victim cloud. The system also includes one or more decoy control computers, which are operated as control computers that communicate with victim computers in the victim cloud. Threats are identified by analyzing data traffic communicated with the decoy bot computers and decoy control computers for information suspected of having being sent from a victim's computer without proper authorization, and by monitoring whether behavior of a DNS server deviates from expected behaviors.

Claims (33)

1. A method for detecting unauthorized access to a network of victim computers in a victim cloud, comprising:

operating one or more decoy control computers among one or more control computers that communicates with one or more victim computers in the victim cloud;

identifying threats by analyzing data traffic communicated with the one or more victim computers and the one or more decoy control computers; and

upon identifying information suspected of being stolen by a hacker, if the identified information was identified from a victim computer from among the one or more victim computers in communication with a control computer used by the hacker, routing traffic from the victim computer to a sinkhole computer;

if the identified information was identified from a decoy control computer from among the one or more decoy control computers, intercepting a transmission and removing data suspected of being stolen from the data traffic while maintaining ongoing communications between the decoy control computer and the hacker.

2. The method of claim 1 , further comprising:

terminating the control computer upon identifying information transmitted by the control computer that is suspected of having being sent from the victim computer to a hacker.

3. The method of claim 2 , further comprising:

upon terminating the control computer through which the victim computer was communicating with a suspected hacker, connecting the victim computer to a sinkhole;

subjecting traffic routed through the sinkhole to packet inspection; and

correlating results of the packet inspection with threat data obtained from other sources to analyze the likelihood that the victim computer has been compromised.

4. The method of claim 1 , further comprising:

terminating a DNS server in communication with the control computer upon identifying information transmitted by the control computer that is suspected of having being sent from the victim computer to a hacker.

5. The method of claim 4 , wherein when DNS servers are terminated, monitoring a request rate for a next domain name or subdomain name by a control computer to determine whether the control computer is suspicious.

6. The method of claim 1 , wherein a plurality of victim computers in the victim cloud operate within a corporate network that includes an internal threat monitor,

and wherein the step of identifying threats additionally comprises analyzing threat data communicated by the internal threat monitor.

7. The method of claim 6 , wherein a plurality of corporate networks that include internal threat monitors are included in the victim cloud,

and wherein the step of identifying threats additionally comprises analyzing threat data communicated by the internal threat monitors.

8. A system for detecting unauthorized access to a network of victim computers in a victim cloud comprising:

at least one decoy control computer operating among one or more control computers that communicates with one or more victim computers in the victim cloud;

a sinkhole computer;

and a threat analyzer in communication with the at least one decoy control computer and the sinkhole computer,

wherein the threat analyzer (i) identifies threats by analyzing data traffic communicated with the at least one decoy control computer for information suspected of having been sent from a victim computer from among the one or more victim computers, without proper authorization, and (ii) intercepts transmissions and removes data suspected of being stolen; from the data traffic, while maintaining ongoing communications between the at least one decoy control computer and a hacker that uses a control computer from among the one or more control computers,

wherein the victim computer is connected to the sinkhole computer upon identifying the information as having been sent from the victim computer by routing traffic from the victim computer to the sinkhole computer.

9. The system of claim 8 , wherein the threat analyzer is additionally in communication with at least one of the DNS servers and monitors whether behavior of the at least one of the DNS servers deviates from expected behaviors.

10. The system of claim 8 , wherein the threat analyzer terminates the decoy control computer upon identifying information transmitted by the decoy control computer that is suspected of having being sent from the victim computer to a hacker.

11. The system of claim 10 , further comprising:

wherein a victim computer is connected to the sinkhole upon terminating the control computer through which the victim computer was communicating with a suspected hacker.

12. The system of claim 8 , wherein the threat analyzer terminates a DNS server in communication with a control computer is upon identifying information transmitted by the control computer that is suspected of having being sent from the victim computer to a hacker.

13. The system of claim 8 , wherein a plurality of victim computers in the victim cloud operate within a corporate network that includes an internal threat monitor, and the threat analyzer analyzes threat data communicated by the internal threat monitor.

14. The system of claim 13 , wherein a plurality of corporate networks that include internal threat monitors are included in the victim cloud, and the threat analyzer identifies threat data communicated by the internal threat monitors.

15. The system of claim 8 , wherein the threat analyzer further includes a correlation engine.

16. The system of claim 8 , further comprising a report generator that notifies owners of victim computers upon determination by the threat analyzer that an intrusion potentially has occurred.

Assignments (13)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON JANUARY 23, 2025 AT REEL 069991 FRAME 0390 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072928/0289 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2025
From: VERCARA, LLC
To: DIGICERT, INC.
Reel/Frame 071781/0348 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2025
From: VERCARA, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 069991/0330 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2025
From: VERCARA, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 069991/0390 →
CHANGE OF NAME Recorded Mar 21, 2024
From: SECURITY SERVICES, LLC
To: VERCARA, LLC
Reel/Frame 066867/0462 →
SECOND LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Dec 3, 2021
From: UBS AG, STAMFORD BRANCH
To: NEUSTAR, INC.; MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.
Reel/Frame 058300/0739 →
FIRST LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Dec 3, 2021
From: BANK OF AMERICA, N.A.
To: NEUSTAR, INC.; MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.
Reel/Frame 058300/0762 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: NEUSTAR, INC.
To: SECURITY SERVICES, LLC
Reel/Frame 057327/0418 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2018
From: JOFFE, RODNEY L.
To: NEUSTAR, INC.
Reel/Frame 046667/0525 →
SECURITY INTEREST Recorded Aug 22, 2017
From: MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.; NEUSTAR, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 043633/0440 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Aug 22, 2017
From: MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.; NEUSTAR, INC.
To: UBS AG, STAMFORD BRANCH
Reel/Frame 043633/0527 →
Cited By (2)
US 12,659,239 US 12,659,323