IP Library Granted Patent US 11,057,429
Granted Patent B1
US 11,057,429 · App. 16/717,154 · Granted Jul 6, 2021

Honeytoken tracker

Inventor: Thomas Eugene Sellers (Georgetown, TX)
Assignee: Rapid7, Inc.
H04L63/1491G06F16/27H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,057,429
App. No.
16/717,154
Granted
Jul 6, 2021
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes for tracking honeytokens. A malicious attack from an attacker is received at a honeypot and a determination is made that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot. A unique credential pair that corresponds to the deceptive credential information sought by the attack event is generated and a honeytoken tracker state table is modified to include the unique credential pair and attack event metadata in association with the attack event. The unique credential pair is then transmitted to the attacker and the honeytoken tracker state table is synchronized with a honeypot management system. Another malicious attack is detected, the honeytoken tracker state table is accessed, and the malicious attacker is correlated to the attacker. A honeypot personality state table maintained by the honeypot management system is accessed and a present personality for the honeypot that is substantially similar to a past personality of the honeypot that existed during the malicious attack based on information in the honeypot personality state table is generated.

Claims (38)

1. A computer-implemented method, comprising:

receiving a malicious attack from an attacker at a honeypot;

determining that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot;

generating a unique credential pair that corresponds to the deceptive credential information sought by the attack event;

modifying a honeytoken tracker state table to comprise the unique credential pair and attack event metadata in association with the attack event;

transmitting the unique credential pair to the attacker;

synchronizing the honeytoken tracker state table with a honeypot management system;

detecting another malicious attack from the attacker;

accessing the honeytoken tracker state table;

correlating the another malicious attack to the attacker using a hash uniquely generated for the attacker in the honeytoken tracker state table or a dynamically generated username;

accessing a honeypot personality state table maintained by the honeypot management system; and

generating a present personality for the honeypot that comprises one or more mimicked services, banner information, an operating system, and protocol information of a past personality of the honeypot that existed during the malicious attack based on information in the honeypot personality state table.

2. A non-transitory computer readable storage medium comprising program instructions executable to:

receive a malicious attack from an attacker at a honeypot;

determine that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot;

generate a unique credential pair that corresponds to the deceptive credential information sought by the attack event;

modify a honeytoken tracker state table to comprise the unique credential pair and attack event metadata in association with the attack event;

transmit the unique credential pair to the attacker;

synchronize the honeytoken tracker state table with a honeypot management system;

detect another malicious attack from the attacker;

access the honeytoken tracker state table;

correlate the another malicious attack to the attacker using a hash uniquely generated for the attacker in the honeytoken tracker state table or a dynamically generated username;

access a honeypot personality state table maintained by the honeypot management system; and

generate a present personality for the honeypot that comprises one or more mimicked services, banner information, an operating system, and protocol information of a past personality of the honeypot that existed during the malicious attack based on information in the honeypot personality state table.

3. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

receive a malicious attack from an attacker at a honeypot;

determine that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot;

generate a unique credential pair that corresponds to the deceptive credential information sought by the attack event;

modify a honeytoken tracker state table to comprise the unique credential pair and attack event metadata in association with the attack event;

transmit the unique credential pair to the attacker;

synchronize the honeytoken tracker state table with a honeypot management system;

detect another malicious attack from the attacker;

access the honeytoken tracker state table;

correlate the another malicious attack to the attacker using a hash uniquely generated for the attacker in the honeytoken tracker state table or a dynamically generated username;

access a honeypot personality state table maintained by the honeypot management system; and

generate a present personality for the honeypot that comprises one or more mimicked services, banner information, an operating system, and protocol information of a past personality of the honeypot that existed during the malicious attack based on information in the honeypot personality state table.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: SELLERS, THOMAS EUGENE
To: RAPID7, INC.
Reel/Frame 053769/0309 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
Continuity (1)
Continuation 16369133 · Mar 29, 2019
Cited By (4)
US 12,199,993 US 12,206,666 US 12,284,211 US 12,423,441