IP Library Granted Patent US 12,289,321
Granted Patent B2
US 12,289,321 · App. 16/291,963 · Granted Apr 29, 2025

Automated generation and deployment of honey tokens in provisioned resources on a remote computer resource platform

Inventors: Hani Hana Neuvirth (Redmond, WA); Tomer Weinberger (Tel Aviv, IL); Yaniv Zohar (Herzliya, IL); Craig A. Nelson (Redmond, WA); Andrew E. Johnson (Redmond, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L63/1416H04L63/0853H04L63/10H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,321
App. No.
16/291,963
Granted
Apr 29, 2025
Kind
B2
Abstract

Methods, systems, and media are shown for creating and deploying honey tokens for intrusion detection in a remote computing resource system. Resource modules provisioned for a tenant are identified for intrusion detection. For each identified resource modules, a provisioned resource having a corresponding access credential is allocated and the access credential is deployed in the identified resource module. A data entry is created in a token mapping store that identifies the access credential and the resource module. Access logs are scanned to detect access attempts. For each access attempt, the token mapping store is searched for a data entry with an access credential that matches the access credential of the access attempt. If found, an alert is generated that includes the identified resource module of the matching data entry.

Claims (49)

1. A computer-implemented method for intrusion detection in a remote computing resource system, the method comprising:

providing a user interface (UI) by way of the remote computing resource system, the UI identifying a plurality of tenant resource modules provisioned in the remote computing resource system for a tenant of the remote computing resource system to provide resources for the tenant, wherein the tenant resource modules provisioned for the tenant of the remote computing resource system comprise one or more of a key vault, a virtual machine, an application service, an application programming interface, or a domain directory;

receiving a selection by way of the UI of one or more of the plurality of tenant resource modules to be configured for intrusion detection;

responsive to receiving the selection by way of the UI, for the tenant resource modules selected in the UI,

allocating provisioned resources having corresponding access credentials,

deploying the corresponding access credentials in respective tenant resource modules, and

creating one or more data entries in a token mapping store, the data entries providing a mapping between the tenant, the corresponding access credentials and the identified tenant resource modules in which the corresponding access credentials were deployed;

scanning one or more access logs for the remote computing resource system to detect one or more resource access attempts, each access attempt including an access credential for the access attempt; and

for each resource access attempt,

searching the token mapping store for a matching data entry where the access credential of the data entry matches the access credential for the access attempt, and

if the matching data entry is found, generating an alert that identifies the identified resource module of the matching data entry.

2. The computer-implemented method of claim 1 , wherein the provisioned resources comprise at least one of an unused resource allocated for the tenant.

3. The computer-implemented method of claim 1 , wherein the unused resource allocated for the tenant comprises a container with restricted access permissions.

4. The computer-implemented method of claim 1 , wherein the UI further comprises a UI control which, when selected, will cause threat intelligence data to be generated and sent to one or more entities.

5. The computer-implemented method of claim 1 , wherein the UI further comprises selectable fields identifying the plurality of tenant resource modules provisioned in the remote computing resource system for the tenant of the remote computing resource system.

6. An intrusion detection system for detecting intrusion in a remote computing resource system, the system comprising:

one or more processors; and

one or more memory devices in communication with the one or more processors, the memory devices having computer-readable instructions stored thereupon that, when executed by the processors, cause the processors to perform operations comprising:

providing a user interface (UI) by way of the remote computing resource system, the UI identifying a plurality of tenant resource modules provisioned in the remote computing resource system for a tenant of the remote computing resource system to provide resources for the tenant, wherein the tenant resource modules provisioned for the tenant of the remote computing resource system comprise one or more of a key vault, a virtual machine, an application service, an application programming interface, or a domain directory;

receiving a selection by way of the UI of one or more of the plurality of resource modules to be configured for intrusion detection;

responsive to receiving the selection by way of the UI, for the tenant resource modules selected in the UI,

allocating provisioned resources having corresponding access credentials,

deploying the corresponding access credentials in respective tenant resource modules, and

creating one or more data entries in a token mapping store, the data entries providing a mapping between the tenant, the corresponding access credentials, and the identified tenant resource modules in which the corresponding access credentials were deployed;

scanning one or more access logs for the remote computing resource system to detect one or more resource access attempts, each access attempt including an access credential for the access attempt; and

for each resource access attempt:

searching the token mapping store for a matching data entry where the access credential of the data entry matches the access credential for the access attempt, and

if the matching data entry is found, generating an alert that identifies the identified resource module of the matching data entry.

7. The system of claim 6 , wherein allocating at least one of the provisioned resources comprises generating a storage account and the corresponding access credential comprises a key to the storage account.

8. The system of claim 6 , wherein at least one of the provisioned resources comprises an unused resource allocated for the tenant.

9. The system of claim 8 , wherein the unused resource allocated for the tenant comprises one of a container with restricted access permissions and a fictitious user account in a domain corresponding to the tenant.

10. The system of claim 6 , wherein at least one of the corresponding access credentials for the provisioned resources comprises one of a connection string, an access key, a certificate, a service key, a management key, a storage key, or an access token.

11. The system of claim 6 , wherein the UI further comprises a UI control which, when selected, will cause threat intelligence data to be generated and sent to one or more entities.

12. One or more computer storage media having computer executable instructions stored thereon which, when executed by one or more processors, cause the processors to perform operations for creating and deploying honey tokens for intrusion detection in a remote computing resource system, the operations comprising:

providing a user interface (UI) by way of the remote computing resource system, the UI identifying a plurality of tenant resource modules provisioned in the remote computing resource system for a tenant of the remote computing resource system to provide resources for the tenant, wherein the tenant resource modules provisioned for the tenant of the remote computing resource system comprise one or more of a key vault, a virtual machine, an application service, an application programming interface, or a domain directory;

receiving a selection by way of the UI of one or more of the plurality of resource modules to be configured for intrusion detection;

responsive to receiving the selection by way of the UI, for the one or more tenant resource modules selected in the UI,

allocating provisioned resources having corresponding access credentials,

deploying the corresponding access credentials in respective tenant resource modules, and

creating one or more data entries in a token mapping store, the data entries providing a mapping between the tenant, the corresponding access credentials, and the identified resource modules in which the corresponding access credentials were deployed;

scanning one or more access logs for the remote computing resource system to detect one or more resource access attempts, each access attempt including an access credential for the access attempt; and

for each resource access attempt,

searching the token mapping store for a matching data entry where the access credential of the data entry matches the access credential for the access attempt, and

if the matching data entry is found, generating an alert that identifies the identified resource module of the matching data entry.

13. The one or more computer storage media of claim 12 , wherein allocating at least one of the provisioned resources comprises generating a storage account and the corresponding access credential comprises a key to the storage account.

14. The one or more computer storage media of claim 12 , wherein at least one of the provisioned resources comprises an unused resource allocated for the tenant.

15. The one or more computer storage media of claim 14 , wherein the unused resource allocated for the tenant comprises one of a container with restricted access permissions or a fictitious user account in a domain corresponding to the tenant.

16. The one or more computer storage media of claim 12 , wherein at least one of the corresponding access credentials for the provisioned resources comprises one of a connection string, an access key, a certificate, a service key, a management key, a storage key, or an access token.

17. The one or more computer storage media of claim 12 , wherein the UI further comprises a UI control which, when selected, will cause threat intelligence data to be generated and sent to one or more entities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2019
From: NEUVIRTH, HANI HANA; WEINBERGER, TOMER; ZOHAR, YANIV; NELSON, CRAIG A.; JOHNSON, ANDREW E.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 048496/0324 →
Continuity (1)
Related Publication 20200287915A1 · Sep 10, 2020
References Cited (151)
US 6185683B1 · Ginter · 2001 [cited by examiner]
US 7587611B2 · Johnson · 2009 [cited by examiner]
US 7788700B1 · Feezel · 2010 [cited by examiner]
US 7813759B2 · Virgile · 2010 [cited by examiner]
US 8479266B1 · Delker · 2013 [cited by examiner]
US 8554912B1 · Reeves · 2013 [cited by examiner]
US 8590004B2 · Comay · 2013 [cited by examiner]
US 8683560B1 · Brooker · 2014 [cited by examiner]
US 8793758B2 · Raleigh · 2014 [cited by examiner]
US 8875229B2 · Hoyos · 2014 [cited by examiner]
US 8880435B1 · Catlett · 2014 [cited by examiner]
US 8914406B1 · Haugsnes · 2014 [cited by examiner]
US 8966276B2 · Nanopoulos · 2015 [cited by examiner]
US 9021578B1 · Casaburi · 2015 [cited by examiner]
US 9129086B2 · Betz · 2015 [cited by examiner]
US 9177156B1 · Kaplan · 2015 [cited by examiner]
US 9202049B1 · Book · 2015 [cited by examiner]
US 9219744B2 · Baliga · 2015 [cited by examiner]
US 9299053B2 · Gazdzinski · 2016 [cited by examiner]
US 9398010B1 · Chickering · 2016 [cited by examiner]
US 9401925B1 · Guo · 2016 [cited by examiner]
US 9419942B1 · Buruganahalli · 2016 [cited by examiner]
US 9424413B2 · Hammad · 2016 [cited by examiner]
US 9547998B2 · Sadeh-Koniecpol · 2017 [cited by examiner]
US 9705919B1 · Jacobsen · 2017 [cited by examiner]
US 9742805B2 · Touboul · 2017 [cited by examiner]
US 9763086B2 · Benoit · 2017 [cited by examiner]
US 9836512B1 · Singh · 2017 [cited by examiner]
US 9838416B1 · Aziz · 2017 [cited by examiner]
US 9894099B1 · Jacobsen · 2018 [cited by examiner]
US 9900330B1 · Dargude · 2018 [cited by examiner]
US 9973517B2 · Hsiao · 2018 [cited by examiner]
US 10028147B1 · Coney · 2018 [cited by examiner]
US 10075384B2 · Shear · 2018 [cited by examiner]
US 10079842B1 · Brandwine · 2018 [cited by examiner]
US 10178122B1 · Shavell · 2019 [cited by examiner]
US 10182062B2 · Aabye · 2019 [cited by examiner]
US 10305920B2 · Balasubramanian · 2019 [cited by examiner]
US 10320784B1 · Talmor · 2019 [cited by examiner]
US 10320789B1 · Tribbensee · 2019 [cited by examiner]
US 10348767B1 · Lee · 2019 [cited by examiner]
US 10412097B1 · Banshats · 2019 [cited by examiner]
US 10454971B2 · Chalmers · 2019 [cited by examiner]
US 10484331B1 · Rossman · 2019 [cited by examiner]
US 10530578B2 · Keshava · 2020 [cited by examiner]
US 10541992B2 · Kong · 2020 [cited by examiner]
US 10558797B2 · Wright · 2020 [cited by examiner]
US 10574698B1 · Sharifi Mehr · 2020 [cited by examiner]
US 10601805B2 · Lerner · 2020 [cited by examiner]
US 10642988B2 · Quintanilla · 2020 [cited by examiner]
US 10652276B1 · Rambo · 2020 [cited by examiner]
US 10701094B2 · Kirti · 2020 [cited by examiner]
US 10728262B1 · Vaswani · 2020 [cited by examiner]
US 10826905B2 · Gujarathi · 2020 [cited by examiner]
US 10904277B1 · Sharifi Mehr · 2021 [cited by examiner]
US 10924481B2 · Haletky · 2021 [cited by examiner]
US 11044240B2 · Dowlatkhah · 2021 [cited by examiner]
US 20040068668A1 · Lor · 2004 [cited by examiner]
US 20040088551A1 · Dor · 2004 [cited by examiner]
US 20040107219A1 · Rosenberger · 2004 [cited by examiner]
US 20050071283A1 · Randle · 2005 [cited by examiner]
US 20050182950A1 · Son · 2005 [cited by examiner]
US 20050198534A1 · Matta · 2005 [cited by examiner]
US 20050222933A1 · Wesby · 2005 [cited by examiner]
US 20050235352A1 · Staats · 2005 [cited by examiner]
US 20050260973A1 · van de Groenendaal · 2005 [cited by examiner]
US 20060140134A1 · O'Brien · 2006 [cited by examiner]
US 20070156897A1 · Lim · 2007 [cited by examiner]
US 20080057913A1 · Sinha · 2008 [cited by examiner]
US 20080271122A1 · Nolan · 2008 [cited by examiner]
US 20090158032A1 · Costa · 2009 [cited by examiner]
US 20090199296A1 · Xie · 2009 [cited by examiner]
US 20090239468A1 · He · 2009 [cited by examiner]
US 20110055928A1 · Brindza · 2011 [cited by examiner]
US 20120116602A1 · Vaswani · 2012 [cited by examiner]
US 20120144201A1 · Anantha · 2012 [cited by examiner]
US 20120159579A1 · Pineau · 2012 [cited by examiner]
US 20120331545A1 · Baliga · 2012 [cited by examiner]
US 20130133072A1 · Kraitsman · 2013 [cited by examiner]
US 20130173913A1 · Kocsis · 2013 [cited by examiner]
US 20130179991A1 · White · 2013 [cited by examiner]
US 20140006347A1 · Qureshi · 2014 [cited by examiner]
US 20140020072A1 · Thomas · 2014 [cited by examiner]
US 20140248854A1 · Schell · 2014 [cited by examiner]
US 20140366118A1 · Yin · 2014 [cited by examiner]
US 20150013006A1 · Shulman · 2015 [cited by examiner]
US 20150135266A1 · Shulman · 2015 [cited by examiner]
US 20150172305A1 · Dixon · 2015 [cited by examiner]
US 20150180829A1 · Yu · 2015 [cited by examiner]
US 20150212843A1 · Turgeman · 2015 [cited by examiner]
US 20150256528A1 · Turgeman · 2015 [cited by examiner]
US 20150271162A1 · Dulkin · 2015 [cited by examiner]
US 20150326608A1 · Shabtai · 2015 [cited by examiner]
US 20160050205A1 · Heller · 2016 [cited by examiner]
US 20160080379A1 · Saboori · 2016 [cited by examiner]
US 20160125139A1 · Higgs · 2016 [cited by examiner]
US 20160255117A1 · Sinha · 2016 [cited by examiner]
US 20160277374A1 · Reid · 2016 [cited by examiner]
US 20160301712A1 · Shulman · 2016 [cited by examiner]
US 20160330230A1 · Reddy · 2016 [cited by examiner]
US 20160381023A1 · Dulce · 2016 [cited by examiner]
US 20170134405A1 · Ahmadzadeh · 2017 [cited by examiner]
US 20170134423A1 · Sysman · 2017 [cited by examiner]
US 20170163664A1 · Nagalla · 2017 [cited by examiner]
US 20170185773A1 · Lemay · 2017 [cited by examiner]
US 20170195346A1 · Be'ery · 2017 [cited by examiner]
US 20170214701A1 · Hasan · 2017 [cited by examiner]
US 20170235955A1 · Barkan · 2017 [cited by examiner]
US 20170237749A1 · Wood · 2017 [cited by examiner]
US 20170244672A1 · Shulman · 2017 [cited by examiner]
US 20170244729A1 · Fahrny · 2017 [cited by examiner]
US 20170324773A1 · Ohayon · 2017 [cited by examiner]
US 20170324774A1 · Ohayon · 2017 [cited by examiner]
US 20170339186A1 · Gurvich · 2017 [cited by examiner]
US 20170346804A1 · Beecham · 2017 [cited by examiner]
US 20170346851A1 · Drake · 2017 [cited by examiner]
US 20180063143A1 · Wilson · 2018 [cited by examiner]
US 20180101675A1 · Kubler · 2018 [cited by examiner]
US 20180198786A1 · Shah · 2018 [cited by examiner]
US 20180227128A1 · Church · 2018 [cited by examiner]
US 20180343283A1 · Goutal · 2018 [cited by examiner]
US 20190044950A1 · Chen · 2019 [cited by examiner]
US 20190095516A1 · Srinivasan · 2019 [cited by examiner]
US 20190124112A1 · Thomas · 2019 [cited by examiner]
US 20190132299A1 · Tucker · 2019 [cited by examiner]
US 20190207771A1 · Hecht · 2019 [cited by examiner]
US 20190207956A1 · Be'ery · 2019 [cited by examiner]
US 20190306138A1 · Carru · 2019 [cited by examiner]
US 20190349766A1 · Rhelimi · 2019 [cited by examiner]
US 20200021581A1 · Wu · 2020 [cited by examiner]
US 20200057850A1 · Kraus · 2020 [cited by examiner]
US 20200076849A1 · Watson · 2020 [cited by examiner]
US 20200137026A1 · Shulman · 2020 [cited by examiner]
US 20200153836A1 · Johnson · 2020 [cited by examiner]
US 20200264860A1 · Srinivasan · 2020 [cited by examiner]
US 20200267184A1 · Vera-Schockner · 2020 [cited by examiner]
US 20200287915A1 · Neuvirth · 2020 [cited by examiner]
WO WO2014160479A1 · 2014 [cited by examiner]
WO WO2017013589A1 · 2017 [cited by examiner]
El-Kosairy et al “A New Web Deception System Framework,” pp. 1-10, IEEE (Year: 2018). [cited by examiner]
Jogdand et al “Survey of Different IDS Using Honeytoken based Techniques to Mitigate Cyber Threats,” International Conference on Electrical, Electronics and Optimization Techniques (ICEEOT), pp. 802-807 (Year: 2016). [cited by examiner]
Amara et al “Cloud Computing Security Threats and Attacks with their Mitigation Techniques,” 2017 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery, pp. 244-251 (Year: 2017). [cited by examiner]
Mahajan et al “Deployment of Intrusion Detection in Cloud: A Performance-Based Study,” 2017 IEEE Trustcom/Big Data/ICESS, IEEE Computer Society, pp. 1103-1108. [cited by examiner]
Bercovitch et al “HoneyGen: An Automated Honeytokens Generator,” IEEE, pp. 131-136 (Year: 2011). [cited by examiner]
Fraunholz et al On the Detection and Handling of Security Incidents and Perimeter Breaches—A Modular and Flexible Honeytoken based Framework, IEEE, pp. 1-4 (Year: 2018). [cited by examiner]
Bourke, et al., “Breach Detection at Scale with AWS Honey Tokens”, Retrieved From: https://web.archive.org/web/20180828210840/https://www.blackhat.com/docs/asia-18/asia-18-bourke-grzelak-breach-detection-at-scale-with-a… [cited by applicant]
Sheridan, Kelly, “Hunting Cybercriminals with AWS Honey Tokens”, Retrieved From: https://www.darkreading.com/cloud/hunting-cybercriminals-with-aws-honey-tokens/d/d-id/1331342, Mar. 22, 2018, 7 Pages. [cited by applicant]
Bercovitch, et al., “HoneyGen: An Automated Honeytokens Generator”, In Proceedings of the IEEE International Conference on Intelligence and Security Informatics, Jul. 10, 2011, pp. 131-136. [cited by applicant]
Jay, et al., “Rethinking Security in the Era of Cloud Computing”, In Journal of IEEE Security and Privacy, vol. 15, Issue 3, Jun. 16, 2017, pp. 60-69. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US20/015515”, Mailed Date: Jul. 27, 2020, 12 Pages. [cited by applicant]
Communication pursuant to Article 94(3) Received in European Patent Application No. 20732339.5, mailed on Oct. 16, 2024, 5 pages. [cited by applicant]