IP Library Granted Patent US 10,986,129
Granted Patent B1
US 10,986,129 · App. 16/435,742 · Granted Apr 20, 2021

Live deployment of deception systems

Inventor: Thomas Eugene Sellers (Georgetown, TX)
Assignee: Rapid7, Inc.
H04L63/1491H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,986,129
App. No.
16/435,742
Granted
Apr 20, 2021
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes to perform live deployment of deception computing systems. An imminent or ongoing malicious attack on a protected host in a network is detected. In response to detecting the imminent or ongoing malicious attack, personality characteristics of the protected host are cloned and a honeypot clone based on the personality characteristics is generated. The honeypot clone is then deployed in the network. A determination is made that the malicious attack includes an interactive session between an attacker associated with the malicious attack and the protected host, and a live state transition is performed between the protected host and the honeypot clone using agent data if the interactive session includes an encrypted protocol or using session state data if the interactive session does not include the encrypted protocol. Attacker data traffic associated with the malicious attack is redirected from the protected host to the honeypot clone and the interactive session is resumed if the redirection of the attacker traffic data transitions within a predetermined time period.

Claims (31)

1. A computer-implemented method, comprising:

detecting that a malicious attack on a protected host in a network is imminent or ongoing;

cloning a plurality of personality characteristics of the protected host in response to the detecting that the malicious attack is imminent or ongoing;

generating a honeypot clone based on the plurality of personality characteristics;

deploying the honeypot clone in the network;

determining that the malicious attack comprises an interactive session between an attacker associated with the malicious attack and the protected host; and

performing a live state transition between the protected host and the honeypot clone using agent data if the interactive session comprises an encrypted protocol or using session state data if the interactive session does not comprise the encrypted protocol.

2. The computer-implemented method of claim 1 , further comprising:

redirecting attacker data traffic associated with the malicious attack from the protected host to the honeypot clone;

disabling the protected host or access to the protected host; and

resuming the interactive session if the redirection of the attacker traffic data transitions within a predetermined time period.

3. A non-transitory computer readable storage medium comprising program instructions executable to:

detect that a malicious attack on a protected host in a network is imminent or ongoing;

clone a plurality of personality characteristics of the protected host in response to the detecting that the malicious attack is imminent or ongoing;

generate a honeypot clone based on the plurality of personality characteristics; and

deploy the honeypot clone in the network;

determine that the malicious attack comprises an interactive session between an attacker associated with the malicious attack and the protected host;

perform a live state transition between the protected host and the honeypot clone using agent data if the interactive session comprises an encrypted protocol or using session state data if the interactive session does not comprise the encrypted protocol;

redirecting attacker data traffic associated with the malicious attack from the protected host to the honeypot clone; and

resuming the interactive session if the redirection of the attacker traffic data transitions within a predetermined time period.

4. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

detect that a malicious attack on a protected host in a network is imminent or ongoing;

clone a plurality of personality characteristics of the protected host in response to the detecting that the malicious attack is imminent or ongoing;

generate a honeypot clone based on the plurality of personality characteristics;

deploy the honeypot clone in the network;

determine that the malicious attack comprises an interactive session between an attacker associated with the malicious attack and the protected host;

perform a live state transition between the protected host and the honeypot clone using agent data if the interactive session comprises an encrypted protocol or using session state data if the interactive session does not comprise the encrypted protocol;

redirecting attacker data traffic associated with the malicious attack from the protected host to the honeypot clone; and

resuming the interactive session if the redirection of the attacker traffic data transitions within a predetermined time period.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2019
From: SELLERS, THOMAS
To: RAPID7, INC.
Reel/Frame 049988/0925 →
Continuity (1)
Continuation 16367359 · Mar 28, 2019
Cited By (1)
US 12,683,982