IP Library Granted Patent US 10,979,454
Granted Patent B1
US 10,979,454 · App. 16/546,663 · Granted Apr 13, 2021

Monitoring scan attempts in a network

Inventors: Roy Hodgman (Cambridge, MA); Jeffrey D. Myers (Cambridge, MA)
Assignee: Rapid7, Inc.
H04L63/1491H04L63/0281H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,979,454
App. No.
16/546,663
Granted
Apr 13, 2021
Kind
B1
Abstract

Methods and devices for monitoring scan attempts in a network. Various embodiments provide enhancements to existing honeypot devices. These enhancements may include at least one of: (1) a port access module configured to make at least one honeypot port appear to be closed; (2) a mobility module configured to change the address of the honeypot within the network; (3) an emulation module configured to discover a network neighbor's profile and further configured to emulate the network neighbor's profile.

Claims (22)

1. A method for operating a virtual security appliance, the method comprising:

deploying at least one virtual security appliance with a first plurality of ports in the network;

introducing the virtual security appliance as a honeypot device to at least one other device on the network so the device does not report scan attempts by the virtual security appliance;

scanning the device using the virtual security appliance to determine a first profile; and

selectively switching the first plurality of ports of the virtual security appliance between resembling the first profile and a honeypot profile.

2. The method of claim 1 further comprising scanning ports of the device in a predetermined order to introduce the virtual security appliance as a honeypot device.

3. The method of claim 1 wherein introducing the virtual security appliance as the honeypot device includes scanning the device at prescheduled intervals.

4. The method of claim 1 wherein introducing the virtual security appliance as the honeypot device includes authenticating the virtual security appliance via cryptographic secrets.

5. The method of claim 1 further comprising selecting at least one device to scan based on the at least one device's location.

6. The method of claim 5 wherein selecting the at least one device to scan based on the device's location includes selecting the device based on the device's IP address.

7. The method of claim 5 wherein selecting the at least one device to scan based on the device's location includes selecting the device based on the device being in the same CIDR block as the at least one virtual security appliance.

8. A virtual security appliance comprising:

a first plurality of ports; and an emulation module comprising a hardware processor configured to:

introduce the virtual security appliance as a honeypot device to at least one other device on a network so the device does not report scan attempts by the virtual security appliance,

scan the device to determine a first profile,

and selectively switch the first plurality of ports between resembling the first profile and the honeypot profile.

9. The virtual security appliance of claim 8 wherein the emulation module introduces the virtual security appliance as a honeypot device scanning ports of the device in a predetermined order.

10. The virtual security appliance of claim 8 wherein the emulation module introduces the virtual security appliance as a honeypot device by scanning the device at prescheduled intervals.

11. The virtual security appliance of claim 9 wherein the emulation module introduces the virtual security appliance as a honeypot device by authenticating the virtual security appliance via cryptographic secrets.

12. The virtual security appliance of claim 8 wherein the virtual security appliance selects at least one device to scan based on the at least one device's location.

13. The virtual security appliance of claim 12 wherein the virtual security appliance selects the at least one device based on the device's IP address.

14. The virtual security appliance of claim 12 wherein the virtual security appliance selects the at least one device based on the device being in the same CIDR block as the at least one virtual security appliance.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: HODGMAN, ROY; MYERS, JEFFREY
To: RAPID7, INC.
Reel/Frame 053768/0427 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
Cited By (1)
US 12,683,981