IP Library Granted Patent US 10,986,130
Granted Patent B1
US 10,986,130 · App. 16/435,934 · Granted Apr 20, 2021

Honeypot opaque credential recovery

Inventors: Thomas Eugene Sellers (Georgetown, TX); Derek Abdine (Rancho Palos Verdes, CA)
Assignee: Rapid7, Inc.
H04L63/1491G06F21/45
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,986,130
App. No.
16/435,934
Granted
Apr 20, 2021
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes for recovering opaque credentials in deception systems. A plaintext credential is received at a honeypot and a plaintext lookup table is accessed. It is determined that the plaintext credential does not exist in the plaintext lookup table and the plaintext credential is added to the plaintext lookup table and a protocol specific plaintext lookup table. An opaque credential is generated for the plaintext credential and the opaque credential is added to a protocol specific opaque lookup table. Attack context metadata associated with the original attack event is generated and stored in the protocol specific opaque lookup table in association with the plaintext credential and the opaque credential. If the honeypot receives the opaque credential from a subsequent attacker who initiates a subsequent attack event, the protocol specific opaque lookup table is accessed and the plaintext credential associated with the opaque credential is recovered. The plaintext credential, the opaque credential, and the attack context metadata are then exchanged with a credential exchange manager.

Claims (41)

1. A computer-implemented method, comprising:

receiving a plaintext credential at a honeypot from an original attacker who initiates an original attack event;

accessing a plaintext lookup table to determine that the plaintext credential does not exist in the plaintext lookup table;

adding the plaintext credential to the plaintext lookup table and to a protocol specific plaintext lookup table;

associating the plaintext credential in the plaintext lookup table to a specific protocol used by the honeypot for hashed credential exchange;

adding an attack context in which the plaintext credential was presented to the honeypot to the protocol specific plaintext lookup table;

generating an opaque credential for the plaintext credential;

adding the opaque credential in association with the attack context and the specific protocol for the hashed credential exchange to a protocol specific opaque lookup table;

receiving the opaque credential at the honeypot from a subsequent attacker who initiates a subsequent attack event;

accessing the protocol specific opaque lookup table;

determining that the opaque credential received from the subsequent attacker as part of the subsequent attack event requires the specific protocol in the protocol specific opaque lookup table for the hashed credential exchange;

recovering the plaintext credential associated with the opaque credential; and

exchanging the plaintext credential, the opaque credential, and the attack context metadata with a credential exchange manager.

2. A non-transitory computer readable storage medium comprising program instructions executable to:

receive a plaintext credential at a honeypot from an original attacker who initiates an original attack event;

access a plaintext lookup table to determine that the plaintext credential does not exist in the plaintext lookup table;

add the plaintext credential to the plaintext lookup table and to a protocol specific plaintext lookup table;

associate the plaintext credential in the plaintext lookup table to a specific protocol used by the honeypot for hashed credential exchange;

add an attack context in which the plaintext credential was presented to the honeypot to the protocol specific plaintext lookup table;

generate an opaque credential for the plaintext credential;

add the opaque credential to a protocol specific opaque lookup table;

receive the opaque credential at the honeypot from a subsequent attacker who initiates a subsequent attack event;

access the protocol specific opaque lookup table;

determine that the opaque credential received from the subsequent attacker as part of the subsequent attack event requires the specific protocol in the protocol specific opaque lookup table for the hashed credential exchange;

recover the plaintext credential associated with the opaque credential; and

exchange the plaintext credential, the opaque credential, and the attack context metadata with a credential exchange manager.

3. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

receive a plaintext credential at a honeypot from an original attacker who initiates an original attack event;

access a plaintext lookup table to determine that the plaintext credential does not exist in the plaintext lookup table;

add the plaintext credential to the plaintext lookup table and to a protocol specific plaintext lookup table;

associate the plaintext credential in the plaintext lookup table to a specific protocol used by the honeypot for hashed credential exchange;

add an attack context in which the plaintext credential was presented to the honeypot to the protocol specific plaintext lookup table;

generate an opaque credential for the plaintext credential;

add the opaque credential to a protocol specific opaque lookup table;

receive the opaque credential at the honeypot from a subsequent attacker who initiates a subsequent attack event;

access the protocol specific opaque lookup table;

determine that the opaque credential received from the subsequent attacker as part of the subsequent attack event requires the specific protocol in the protocol specific opaque lookup table for the hashed credential exchange;

recover the plaintext credential associated with the opaque credential; and

exchange the plaintext credential, the opaque credential, and the attack context metadata with a credential exchange manager.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: SELLERS, THOMAS EUGENE; ABDINE, DEREK
To: RAPID7, INC.
Reel/Frame 053769/0429 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →