IP Library Granted Patent US 11,075,931
Granted Patent B1
US 11,075,931 · App. 16/237,221 · Granted Jul 27, 2021

Systems and methods for detecting malicious network activity

Inventors: Jeffrey Adam Warren (Ridgewood, NJ); Sean Bergman (Jersey City, NJ)
Assignee: Stealthbits Technologies LLC
H04L63/1425G06F9/547H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,075,931
App. No.
16/237,221
Granted
Jul 27, 2021
Kind
B1
Abstract

Examples of devices and methods for detecting malicious network activity are described. Fake user credentials are saved into memory of a monitored device. The fake user credentials may include a username and a password hash for a nonexistent account. Reconnaissance on the fake user credentials is monitored. A compromised account is detected based on the fake user credential reconnaissance monitoring.

Claims (36)

1. A method, comprising:

deploying fake user credentials to memories of multiple monitored devices, wherein each monitored device receives unique fake user credentials;

monitoring for reconnaissance from a malicious entity on the fake user credentials for the multiple monitored devices, wherein the monitoring for the reconnaissance comprises hooking a directory service application protocol interface (API) and filtering a lightweight directory access protocol (LDAP) query to the directory service API based on the fake user credentials, wherein hook code alters native operating system behavior to intercept a function call;

detecting a compromised account based on the fake user credential reconnaissance monitoring; and

sending an alert in response to detecting fake user credential reconnaissance.

2. The method of claim 1 , wherein the fake user credentials comprise a username and a password hash for a nonexistent account.

3. The method of claim 1 , wherein the query is sent from the malicious entity to determine information about the fake user credentials.

4. The method of claim 1 , wherein detecting the compromised account comprises:

intercepting the LDAP query to the directory service API that includes at least one of the fake user credentials.

5. The method of claim 1 , further comprising performing forensic analysis of the compromised account in response to detecting fake user credential reconnaissance.

6. The method of claim 1 , further comprising:

detecting the compromised account in response to detecting fake user credential reconnaissance associated with a given monitored device.

7. The method of claim 6 , wherein detecting the compromised monitored device comprises identifying a query to a directory service API that includes fake user credentials specific to the given monitored device.

8. A computing device, comprising:

a processor;

a memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable to:

deploy fake user credentials to memories of multiple monitored devices, wherein each monitored device receives unique fake user credentials;

monitor for reconnaissance from a malicious entity on the fake user credentials for the multiple monitored devices, wherein the instructions executable to monitor for reconnaissance comprise instructions executable to hook a directory service application protocol interface (API) and filter a lightweight directory access protocol (LDAP) query to the directory service API based on the fake user credentials, and wherein the instructions executable to hook the directory service API comprise a hook code to alter native operating system behavior to intercept a function call;

detect a compromised account based on the fake user credential reconnaissance monitoring; and

send an alert in response to detecting fake user credential reconnaissance.

9. The computing device of claim 8 , wherein the fake user credentials comprise a username and a password hash for a nonexistent account.

10. The computing device of claim 8 , wherein the instructions executable to detect the compromised account comprise instructions executable to:

determine that the LDAP query includes at least one of the fake user credentials.

11. The computing device of claim 8 , further comprising instructions executable to:

detect the compromised account in response to detecting fake user credential reconnaissance associated with a given monitored device.

12. A non-transitory, tangible computer-readable medium, comprising executable instructions for:

deploying fake user credentials to memories of multiple monitored devices, wherein each monitored device receives unique fake user credentials;

monitoring for reconnaissance from a malicious entity on the fake user credentials for the multiple monitored devices, wherein the executable instructions for monitoring for the reconnaissance comprise executable instructions for hooking a directory service application protocol interface (API) and filtering a lightweight directory access protocol (LDAP) query to the directory service API based on the fake user credentials, and wherein the executable instructions for hooking comprise a hook code for altering native operating system behavior to intercept a function call;

detecting a compromised account based on the fake user credential reconnaissance monitoring; and

sending an alert in response to detecting fake user credential reconnaissance.

13. The computer-readable medium of claim 12 , wherein the fake user credentials comprise a username and a password hash for a nonexistent account.

14. The computer-readable medium of claim 12 , wherein the executable instructions for detecting the compromised account comprise executable instructions for:

intercepting the LDAP query to the directory service API that includes at least one of the fake user credentials.

15. The computer-readable medium of claim 12 , further comprising executable instructions for:

detecting the compromised account in response to detecting fake user credential reconnaissance associated with a given monitored device.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jul 7, 2022
From: TC LENDING, LLC, AS COLLATERAL AGENT
To: STEALTHBITS TECHNOLOGIES LLC (F/K/A STEALTHBITS TECHNOLOGIES II LLC)
Reel/Frame 060430/0798 →
SECURITY INTEREST Recorded Jun 9, 2022
From: NETWRIX CORPORATION; POLICYPAK SOFTWARE, LLC; STEALTHBITS TECHNOLOGIES LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060152/0855 →
MERGER AND CHANGE OF NAME Recorded Feb 25, 2021
From: STEALTHBITS TECHNOLOGIES, INC.; STEALTHBITS TECHNOLOGIES II LLC; STEALTHBITS TECHNOLOGIES II LLC
To: STEALTHBITS TECHNOLOGIES LLC
Reel/Frame 055416/0485 →
PATENT SECURITY AGREEMENT Recorded Dec 31, 2020
From: STEALTHBITS TECHNOLOGIES II LLC
To: TC LENDING, LLC, AS COLLATERAL AGENT
Reel/Frame 054884/0804 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2019
From: WARREN, JEFFREY ADAM; BERGMAN, SEAN
To: STEALTHBITS TECHNOLOGIES, INC.
Reel/Frame 048766/0716 →
Cited By (3)
US 12,225,134 US 12,353,930 US 12,561,458