IP Library Granted Patent US 10,382,483
Granted Patent B1
US 10,382,483 · App. 16/053,773 · Granted Aug 13, 2019

User-customized deceptions and their deployment in networks

Inventors: Alon Kafri (Even-Yehuda, IL); Tom Kahana (Gan Yavne, IL); Shani Margulis (Jerusalem, IL); Tom Sela (Holon, IL); Dolev Ben-Shushan (Netanya, IL); Tomer Shamul (Jerusalem, IL)
Assignee: ILLUSIVE NETWORKS LTD.
H04L63/1491G06F8/61G06F9/54H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,483
App. No.
16/053,773
Granted
Aug 13, 2019
Kind
B1
Abstract

A system for generating and deploying custom deceptions for a network, including an administrator computer for generating custom deception entities (CDEs), each CDE including parameters including inter alia (i) a type of entity, (ii) conditions for deployment of the CDE, and (iii) a deception type, and a management server, comprising an application programming interface for use by the administrator computer to generate CDEs through the medium of a formal language for specifying deceptions, and a translator for translating formal language CDEs to deceptions that are installable in network endpoint computers, wherein the management computer receives a request from a network endpoint computer to retrieve CDEs, selects CDEs that are relevant to the requesting network endpoint computer based on the parameters of the CDE, translates the requested CDEs to installable deceptions, and transmits the installable deceptions to the network endpoint computer for installation thereon.

Claims (24)

1. A system for generating and deploying custom deceptions for a network, comprising:

an administrator computer for generating custom deception entities (CDEs), each CDE comprising parameters including inter alia (i) a type of entity, (ii) conditions for deployment of the CDE, and (iii) a deception type; and

a management server, comprising:

an application programming interface (API) for use by said administrator computer to generate CDEs through a medium of a formal language for specifying deceptions, the formal language comprising keyword placeholders for servers, usernames and passwords; and

a translator for translating formal language CDEs to deceptions that are installable in network endpoint computers, comprising replacing the keyword placeholders for servers, usernames and passwords with actual server names, usernames and passwords,

wherein said management computer receives a request from a network endpoint computer to retrieve CDEs, selects CDEs that are relevant to the requesting network endpoint computer based on the parameters of the CDE, translates the selected CDEs to installable deceptions, and transmits the installable deceptions to the network endpoint computer for installation thereon.

2. The system of claim 1 wherein said management server further comprises:

a policy manager for selecting a deception policy and enforcing it; and

a deployer for planting deceptions in endpoint computers of the network in accordance with the selected deception policy.

3. The system of claim 1 wherein said management server further comprises a forensic application for transmission to a network endpoint computer on which a CDE is installed when an attacker who has breached the network endpoint computer attempts to access the CDE, in order to collect forensics of the attacker's activities.

4. The system of claim 1 wherein said management server receives a request from said administration computer to delete designated CDEs, in response to which said management server deletes the designated CDEs from its storage.

5. A method performed by a management server of a network for generating and deploying custom deceptions for the network, comprising:

providing an application programming interface for generating custom deception entities (CDEs) through a medium of a formal language for specifying deceptions, the formal language comprising keyword placeholders for servers, usernames and passwords, each CDE comprising parameters including inter alia (i) a type of entity, (ii) conditions for deployment of the CDE, and (iii) a deception type;

receiving a request from a network endpoint computer to retrieve CDEs;

selecting CDEs that are relevant to the requesting network endpoint computer based on the parameters of the CDE;

translating the selected CDEs from their formal language description to installable deceptions, comprising replacing the keyword placeholders for servers, usernames and passwords with actual server names, usernames and passwords; and

transmitting the installable deceptions to the network endpoint computer for installation thereon.

6. The method of claim 5 further comprising:

selecting a deception policy; and

planting deceptions in endpoint computers of the network in accordance with the selected deception policy.

7. The method of claim 5 further comprising transmitting a forensic application to a network endpoint computer on which a CDE is installed when an attacker who has breached the network endpoint computer attempts to access the CDE, in order to collect forensics of the attacker's activities.

8. The method of claim 5 further comprising:

further receiving a request to delete designated CDEs; and

in response to said further receiving a request, deleting the designated CDEs from its storage.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2024
From: ILLUSV NETWORKS LTD.
To: PROOFPOINT ISRAEL HOLDINGS LTD.
Reel/Frame 069461/0191 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2018
From: KAFRI, ALON; KAHANA, TOM; MARGULIS, SHANI; SELA, TOM; BEN-SHUSHAN, DOLEV; SHAMUL, TOMER
To: ILLUSIVE NETWORKS LTD.
Reel/Frame 046557/0238 →
Cited By (4)
US 12,348,565 US 12,425,417 US 12,500,918 US 12,506,781