IP Library Granted Patent US 10,623,442
Granted Patent B2
US 10,623,442 · App. 15/942,593 · Granted Apr 14, 2020

Multi-factor deception management and detection for malicious actions in a computer network

Inventors: Shlomo Touboul (Kfar Chaim, IL); Hanan Levin (Tel Aviv, IL); Stephane Roubach (Herzliya, IL); Assaf Mischari (Petach Tikva, IL); Itai Ben David (Tel Aviv, IL); Itay Avraham (Tel Aviv, IL); Adi Ozer (Shoham, IL); Chen Kazaz (Tel Aviv, IL); Ofer Israeli (Tel Aviv, IL); Olga Vingurt (Shderot, IL); Liad Gareh (Herzliya, IL); Israel Grimberg (Ra'anana, IL); Cobby Cohen (Tel Aviv, IL); Sharon Sultan (Tel Aviv, IL); Matan Kubovsky (Tel Aviv, IL)
Assignee: ILLUSIVE NETWORKS LTD.
H04L63/1491G06F21/55G06F21/554G06F21/56G06F21/577G06N20/00H04L63/102H04L63/1416H04L63/1425H04L63/1441H04L63/20H04L29/06904H04L63/10H04L63/1433H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,623,442
App. No.
15/942,593
Granted
Apr 14, 2020
Kind
B2
Abstract

A network surveillance method to detect attackers, including planting one or more honeytokens in one or more resources in a network of computers in which users access the resources in the network based on credentials, wherein a honeytoken is an object in memory or storage of a first resource that may be used by an attacker to access a second resource using decoy credentials, including planting a first honeytoken in a first resource, R 1 , used to access a second resource, R 2 , using first decoy credentials, and planting a second honeytoken in R 1 , used to access a third resource, R 3 , using second decoy credentials, and alerting that an attacker is intruding the network only in response to both (i) an attempt to access R 2 using the first decoy credentials, and (ii) a subsequent attempt to access R 3 using the second decoy credentials.

Claims (7)

1. A network surveillance method to detect attackers, comprising:

planting one or more honeytokens in one or more resources in a network of computers in which users access the resources in the network based on credentials, wherein a honeytoken is an object in memory or storage of a first resource that may be used by an attacker to access a second resource using decoy credentials, comprising:

planting a first honeytoken in a first resource, R 1 , used to access a second resource, R 2 , using first decoy credentials; and

planting a second honeytoken in R 1 , used to access a third resource, R 3 , using second decoy credentials; and

alerting that an attacker is intruding the network only in response to both (i) an attempt to access R 2 using the first decoy credentials, and (ii) a subsequent attempt to access R 3 using the second decoy credentials.

2. The method of claim 1 wherein credentials include passwords for accessing resources in the network, and wherein the first and second decoy credentials include respective hash versions of first and second passwords.

3. The method of claim 1 wherein credentials of honeytokens include members of the group consisting of user credentials, FTP server credentials and SSH server credentials.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2024
From: ILLUSV NETWORKS LTD.
To: PROOFPOINT ISRAEL HOLDINGS LTD.
Reel/Frame 069461/0191 →
Continuity (7)
Division 15175052 · Jun 7, 2016
Provisional Application 62172251 · Jun 8, 2015
Provisional Application 62172253 · Jun 8, 2015
Provisional Application 62172255 · Jun 8, 2015
Provisional Application 62172259 · Jun 8, 2015
Provisional Application 62172261 · Jun 8, 2015
Related Publication 20180234438A1 · Aug 16, 2018