IP Library Granted Patent US 9,794,283
Granted Patent B2
US 9,794,283 · App. 15/619,547 · Granted Oct 17, 2017

Predicting and preventing an attacker's next actions in a breached network

Inventors: Shlomo Touboul (Kfar Chaim, IL); Hanan Levin (Tel Aviv, IL); Stephane Roubach (Herzliya, IL); Assaf Mischari (Petach Tikva, IL); Itai Ben David (Tel Aviv, IL); Itay Avraham (Tel Aviv, IL); Adi Ozer (Shoham, IL); Chen Kazaz (Tel Aviv, IL); Ofer Israeli (Tel Aviv, IL); Olga Vingurt (Shderot, IL); Liad Gareh (Herzliya, IL); Israel Grimberg (Ra'anana, IL); Cobby Cohen (Tel Aviv, IL); Sharon Sultan (Tel Aviv, IL); Matan Kubovsky (Tel Aviv, IL)
Assignee: ILLUSIVE NETWORKS LTD.
H04L63/1441G06F21/55
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,794,283
App. No.
15/619,547
Granted
Oct 17, 2017
Kind
B2
Abstract

A method for cyber security, including detecting, by a management server, a breach by an attacker of a resource within a network of resources, wherein access to the resources via network connections is governed by a firewall, predicting, by the management server, which servers in the network are compromised, based on connections created during the breach, and creating, by the management server, firewall rules to block access to the predicted compromised servers from the breached resource, in response to said predicting which servers.

Claims (42)

1. A method for cyber security, comprising:

detecting, by a decoy management server, a breach by an attacker of a specific resource within a network of resources in which users access the resources based on credentials, wherein access to the resources via network connections is governed by a firewall, wherein each resource has a domain name server (DNS) record stored on a DNS server, and wherein some of the resources are servers that are accessed via IP addresses;

changing, by the decoy management server, the DNS record for the breached resource on the DNS server, in response to said detecting;

predicting, by the decoy management server, which credentials are compromised, based on credentials stored on the breached resource;

changing, by the decoy management server, those credentials that were predicted to be compromised, in response to said predicting which credentials are compromised;

predicting, by the decoy management server, which servers in the network are compromised, based on connections created during the breach;

changing, by the decoy management server, IP addresses of the predicted compromised servers in response to said predicting which servers are compromised;

creating, by the decoy management server, firewall rules to block access to the predicted compromised servers from the breached resource, in response to said predicting which servers are compromised;

predicting, by the decoy management server, data leakage paths from inside the network to outside the network, based on an open outbound connection during the breach; and

creating, by the decoy management server, firewall rules to block that outbound connection in response to said predicting data leakage paths.

2. The method of claim 1 wherein said changing the DNS record and said changing the predicted compromised credentials are performed automatically.

3. The method of claim 1 wherein said changing the DNS record and said changing the predicted compromised credentials are performed semi-automatically wherein the decoy management server requests confirmation by an administrator of the network prior to changing the DNS record and the predicted compromised credentials.

4. The method of claim 1 wherein said changing the DNS record and said changing the predicted compromised credentials are performed manually wherein the decoy management server recommends these changes to an administrator of the network, who then performs the changes manually.

5. A method for cyber security, comprising:

detecting, by a decoy management server, a breach by an attacker of a specific resource within a network of resources in which users access the resources based on credentials, wherein access to the resources via network connections is governed by a firewall, wherein each resource has a domain name server (DNS) record stored on a DNS server, and wherein some of the resources are servers that are accessed via IP addresses;

changing, by the decoy management server, the DNS record for the breached resource on the DNS server, in response to said detecting;

predicting, by the decoy management server, which credentials are compromised, based on credentials stored on the breached resource;

changing, by the decoy management server, those credentials that were predicted to be compromised, in response to said predicting which credentials are compromised;

predicting, by the decoy management server, which servers in the network are compromised, based on connections created during the breach;

changing, by the decoy management server, IP addresses of the predicted compromised servers in response to said predicting which servers are compromised;

creating, by the decoy management server, firewall rules to block access to the predicted compromised servers from the breached resource, in response to said predicting which servers are compromised;

predicting, by the decoy management server, data leakage paths from inside the network to outside the network, based on an open outbound connection during the breach; and

creating, by the decoy management server, firewall rules to re-direct that outbound connection to a resource within the network, in response to said predicting data leakage paths.

6. The method of claim 5 wherein said changing the DNS record and said changing the predicted compromised credentials are performed automatically.

7. The method of claim 5 wherein said changing the DNS record and said changing the predicted compromised credentials are performed semi-automatically wherein the decoy management server requests confirmation by an administrator of the network prior to changing the DNS record and the predicted compromised credentials.

8. The method of claim 5 wherein said changing the DNS record and said changing the predicted compromised credentials are performed manually wherein the decoy management server recommends these changes to an administrator of the network, who then performs the changes manually.

9. A method for cyber security, comprising:

detecting, by a decoy management server, a breach by an attacker of a specific resource within a network of resources, wherein access to the resources via network connections is governed by a firewall, wherein each resource has a domain name server (DNS) record stored on a DNS server, and wherein some of the resources are servers that are accessed via IP addresses;

predicting, by the decoy management server, which resources of the network were exposed to the attacker, based on address pointers stored on the breached resource;

generating firewall rules to block access to the predicted exposed resources from the breached resource, in response to said predicting which resources were exposed;

predicting, by the decoy management server, which servers in the network are compromised, based on connections created during the breach;

changing, by the decoy management server, IP addresses of the predicted compromised servers in response to said predicting which servers were compromised;

predicting, by the decoy management server, data leakage paths from inside the network to outside the network, based on an open outbound connection during the breach; and

creating, by the decoy management server, firewall rules to block that outbound connection in response to said predicting data leakage paths.

10. A method for cyber security, comprising:

detecting, by a decoy management server, a breach by an attacker of a specific resource within a network of resources, wherein access to the resources via network connections is governed by a firewall, wherein each resource has a domain name server (DNS) record stored on a DNS server, and wherein some of the resources are servers that are accessed via IP addresses;

predicting, by the decoy management server, which resources of the network were exposed to the attacker, based on address pointers stored on the breached resource;

generating firewall rules to block access to the predicted exposed resources from the breached resource, in response to said predicting which resources were exposed;

predicting, by the decoy management server, which servers in the network are compromised, based on connections created during the breach;

changing, by the decoy management server, IP addresses of the predicted compromised servers in response to said predicting which servers are compromised;

predicting, by the decoy management server, data leakage paths from inside the network to outside the network, based on an open outbound connection during the breach; and

creating, by the decoy management server, firewall rules to re-direct that outbound connection to a resource within the network, in response to said predicting data leakage paths.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2024
From: ILLUSV NETWORKS LTD.
To: PROOFPOINT ISRAEL HOLDINGS LTD.
Reel/Frame 069461/0191 →
Continuity (7)
Continuation 15175054 · Jun 7, 2016
Provisional Application 62172251 · Jun 8, 2015
Provisional Application 62172253 · Jun 8, 2015
Provisional Application 62172255 · Jun 8, 2015
Provisional Application 62172259 · Jun 8, 2015
Provisional Application 62172261 · Jun 8, 2015
Related Publication 20170270294A1 · Sep 21, 2017