IP Library Granted Patent US 11,057,428
Granted Patent B1
US 11,057,428 · App. 16/369,133 · Granted Jul 6, 2021

Honeytoken tracker

Inventor: Thomas Eugene Sellers (Georgetown, TX)
Assignee: Rapid7, Inc.
H04L63/1491G06F16/27H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,057,428
App. No.
16/369,133
Granted
Jul 6, 2021
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes for tracking honeytokens. A malicious attack from an attacker is received at a honeypot and a determination is made that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot. A unique credential pair that corresponds to the deceptive credential information sought by the attack event is generated and a honeytoken tracker state table is modified to include the unique credential pair and attack event metadata in association with the attack event. The unique credential pair is then transmitted to the attacker.

Claims (82)

1. A computer-implemented method, comprising:

receiving a malicious attack from an attacker at a honeypot;

determining that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot;

generating a unique credential pair that corresponds to the compromised deceptive credential information sought by the attack event;

generating a honeytoken tracker;

modifying a honeytoken tracker state table with the honeytoken tracker that comprises the unique credential pair and attack event metadata in association with the attack;

transmitting the unique credential pair to the attacker; and

tracking a subsequent malicious attack from the attacker with the honeytoken tracker without processing a hash value associated with the unique credential pair that is used by the attacker as part of the subsequent malicious attack.

2. The computer-implemented method of claim 1 , wherein

the malicious attack is intended for a protected host, and

the compromised deceptive credential information is associated with the protected host or one or more services provided by the protected host.

3. The computer-implemented method of claim 1 , further comprising:

synchronizing the honeytoken tracker state table with a honeypot management system.

4. The computer-implemented method of claim 3 , further comprising:

monitoring vertical or horizontal movement of the malicious attack as part of a next step of the malicious attack performed using the unique credential pair.

5. The computer-implemented method of claim 4 , further comprising:

updating the honeytoken tracker state table if the next step comprises vertical movement of the malicious attack, or

receiving confirmation that one or more other honeypots have updated the honeytoken tracker state table maintained by the honeypot management system if the next step comprises horizontal movement of the malicious attack.

6. The computer-implemented method of claim 5 , wherein

the deceptive credential information is required to access a service of one or more services provided by the protected host, and

the one or more services are mimicked by the honeypot or the one or more other honeypots.

7. The computer-implemented method of claim 3 , further comprising:

accessing the honeytoken tracker state table;

correlating the subsequent malicious attack to the attacker using a dynamically generated username without knowledge of the hash value that was used as part of the subsequent malicious attack;

accessing a honeypot personality state table maintained by the honeypot management system;

generating a present personality for the honeypot that comprises one or more mimicked services, banner information, an operating system, and protocol information of a past personality of the honeypot that existed during the malicious attack based on information in the honeypot personality state table; and

presenting the present personality for the honeypot to the attacker prior to an another attack event that is associated with the subsequent malicious attack.

8. A non-transitory computer readable storage medium comprising program instructions executable to:

receive a malicious attack from an attacker at a honeypot;

determine that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot;

generate a unique credential pair that corresponds to the compromised deceptive credential information sought by the attack event;

generate a honeytoken tracker;

modify a honeytoken tracker state table with the honeytoken tracker that comprises the unique credential pair and attack event metadata in association with the attack;

transmit the unique credential pair to the attacker; and

track a subsequent malicious attack from the attacker with the honeytoken tracker without processing a hash value associated with the unique credential pair that is used by the attacker as part of the subsequent malicious attack.

9. The non-transitory computer readable storage medium of claim 8 , wherein

the malicious attack is intended for a protected host, and

the compromised deceptive credential information is associated with the protected host or one or more services provided by the protected host.

10. The non-transitory computer readable storage medium of claim 8 , further comprising:

synchronizing the honeytoken tracker state table with a honeypot management system.

11. The non-transitory computer readable storage medium of claim 10 , further comprising:

monitoring vertical or horizontal movement of the malicious attack as part of a next step of the malicious attack performed using the unique credential pair.

12. The non-transitory computer readable storage medium of claim 11 , further comprising:

updating the honeytoken tracker state table if the next step comprises vertical movement of the malicious attack, or

receiving confirmation that one or more other honeypots have updated the honeytoken tracker state table maintained by the honeypot management system if the next step comprises horizontal movement of the malicious attack.

13. The non-transitory computer readable storage medium of claim 12 , wherein

the deceptive credential information is required to access a service of one or more services provided by the protected host, and

the one or more services are mimicked by the honeypot or the one or more other honeypots.

14. The non-transitory computer readable storage medium of claim 10 , further comprising:

accessing the honeytoken tracker state table;

correlating the subsequent malicious attack to the attacker using a dynamically generated username without knowledge of the hash value that was used as part of the subsequent malicious attack;

accessing a honeypot personality state table maintained by the honeypot management system;

generating a present personality for the honeypot that comprises one or more mimicked services, banner information, an operating system, and protocol information of a past personality of the honeypot that existed during the malicious attack based on information in the honeypot personality state table; and

presenting the present personality for the honeypot to the attacker prior to an another attack event that is associated with the subsequent malicious attack.

15. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

receive a malicious attack from an attacker at a honeypot;

determine that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot;

generate a unique credential pair that corresponds to the compromised deceptive credential information sought by the attack event;

generate a honeytoken tracker;

modify a honeytoken tracker state table with the honeytoken tracker that comprises the unique credential pair and attack event metadata in association with the attack;

transmit the unique credential pair to the attacker; and

track a subsequent malicious attack from the attacker with the honeytoken tracker without processing a hash value associated with the unique credential pair that is used by the attacker as part of the subsequent malicious attack.

16. The system of claim 15 , wherein

the malicious attack is intended for a protected host, and

the compromised deceptive credential information is associated with the protected host or one or more services provided by the protected host.

17. The system of claim 15 , further comprising:

synchronizing the honeytoken tracker state table with a honeypot management system.

18. The system of claim 17 , further comprising:

monitoring vertical or horizontal movement of the malicious attack as part of a next step of the malicious attack performed using the unique credential pair; and

updating the honeytoken tracker state table if the next step comprises vertical movement of the malicious attack, or

receiving confirmation that one or more other honeypots have updated the honeytoken tracker state table maintained by the honeypot management system if the next step comprises horizontal movement of the malicious attack.

19. The system of claim 18 , wherein

the deceptive credential information is required to access a service of one or more services provided by the protected host, and

the one or more services are mimicked by the honeypot or the one or more other honeypots.

20. The system of claim 17 , further comprising:

accessing the honeytoken tracker state table;

correlating the subsequent malicious attack to the attacker using a dynamically generated username without knowledge of the hash value that was used as part of the subsequent malicious attack;

accessing a honeypot personality state table maintained by the honeypot management system;

generating a present personality for the honeypot that comprises one or more mimicked services, banner information, an operating system, and protocol information of a past personality of the honeypot that existed during the malicious attack based on information in the honeypot personality state table; and

presenting the present personality for the honeypot to the attacker prior to an another attack event that is associated with the subsequent malicious attack.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2019
From: SELLERS, THOMAS EUGENE
To: RAPID7, INC.
Reel/Frame 049168/0287 →
Continuity (1)
Continuation In Part 16367502 · Mar 28, 2019
Cited By (5)
US 12,375,527 US 12,418,559 US 12,489,731 US 12,647,444 US 12,647,445