IP Library Granted Patent US 12,328,339
Granted Patent B2
US 12,328,339 · App. 16/983,583 · Granted Jun 10, 2025

Reactive and pre-emptive security system for the protection of computer networks and systems

Inventor: Craig Steven Wright (London, GB)
Assignee: NCHAIN LICENSING AG
H04L63/1491H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,328,339
App. No.
16/983,583
Granted
Jun 10, 2025
Kind
B2
Abstract

The invention provides mechanisms for enhancing the security and protection of a computer-based system or network. It relates, in part, to the use of a decoy (which may be termed “honeypot” or “honeynet”) for collecting attacker-related data, and/or diverting malicious behaviour away from legitimate resources. In one embodiment, the invention provides a method comprising the steps of receiving, processing and logging network traffic data of a plurality of users, where the network traffic is received from a plurality of participating users; determining an attacker profile from the network traffic data; determining a honeypot or honeynet configuration based on the attacker profile; and upon receipt of a valid information request from a user of the plurality of users, providing the determined attacker profile and configuration to the user. Additionally or alternatively, it may provide a computer-implemented method comprising the steps of receiving, processing and logging network traffic data; based on processed network traffic data: determining that network traffic originates from an attacker, determining a risk classification; and determining a decoy configuration based on the risk classification; upon receipt of a valid information request from a user, providing the determined risk classification and decoy configuration to the user.

Claims (55)

1. A computer-implemented security method comprising:

receiving, processing, and logging network traffic data received from a plurality of users;

determining an attacker profile from the network traffic data, wherein the attacker profile includes attack prevention information an attacker identity;

determining an attacker classification based on sophistication of the attacker with the attacker identity;

determining a configuration of a honeypot or honeynet using the network traffic data, the attacker profile, and the attacker classification; and

using a computer-based storage resource to store the attacker profile and the honeypot or honeynet configuration,

wherein the attacker profile and the honeypot or honeynet configuration are made available upon request to any of the plurality of users that are registered.

2. The method of claim 1 , further comprising using the computer-based storage resource to store:

the network traffic data; and/or

data relating to the users.

3. The method according to claim 1 , further comprising:

directing network traffic to the honeypot or honeynet generated in accordance with, or using, the determined configuration.

4. The method according to claim 1 , wherein the plurality of users comprises users who are designated as authorised users.

5. The method according to claim 1 , further comprising:

receiving a request from a user; and

determining whether the request is from an authorised user or an attacker.

6. The method according to claim 1 , further comprising: determining a profile for one or more of the users from the plurality of users.

7. A computer-implemented security system comprising:

a computer-based storage resource is arranged to receive, process, and log network traffic data received from a plurality of users; and

one or more processors and memory, the memory storing instructions that, when executed by the one or more processors of a computer system, cause the computer-implemented security system to:

determine an attacker profile from the network traffic data, wherein the attacker profile includes attack prevention information associated with an attacker identity;

determine an attacker classification based on sophistication of the attacker with the attacker identity;

determine a configuration of a honeypot or a honeynet using the network traffic data, the attacker profile, and the attacker classification;

use the computer-based storage resource to store an attacker profile and a honeypot or honeynet configuration,

wherein the attacker profile and the honeypot or honeynet configuration are made available upon request to any of the plurality of users that are registered.

8. The computer-implemented security system according to claim 7 , wherein the computer-based storage resource is also arranged to store:

profile(s) relating to one or more of the plurality of users;

profile(s) relating to one or more attackers or groups or types of attackers; and/or

honeypot/honeynet configuration parameters.

9. A computer-implemented method comprising:

using a computer-based storage resource to store an attacker profile and a computer decoy, wherein the attacker profile and the computer decoy are made available upon request to a plurality of registered users;

receiving attacker profile information;

monitoring traffic to a network address;

comparing the monitored traffic to the attacker profile information;

determining an attacker classification based on sophistication of the attacker with an attacker identity, wherein the sophistication is determined based at least in part on behavior indicating skillfulness of an attack;

upon determining that the monitored traffic is associated with an attacker, retrieving configuration information to configure the computer decoy; and

configuring the computer decoy based on the retrieved configuration information and the attacker classification using a machine learning model.

10. The method of claim 9 , further comprising directing traffic to the computer decoy.

11. The method of claim 9 , further comprising storing the monitored traffic in the computer-based storage resource.

12. The method according to claim 9 , wherein the attacker profile information is generated using network traffic data provided by a plurality of users.

13. A system comprising:

one or more processors; and

memory storing instructions executable by the one or more processors to cause the system to:

determine an attacker profile based on network traffic data;

determine an attacker classification based on sophistication of the attacker with an attacker identity, wherein the sophistication is based at least in part on a behavior of the attacker,

determine a configuration of a honeypot or honeynet using the network traffic data, the attacker profile, and the attacker classification;

configure the honeypot or honeynet according to the determined configuration, wherein the instructions cause the system to determine the configuration of the honeypot or honeynet using a machine learning model;

use a computer-based storage resource to store the attacker profile and the honeypot or honeynet configuration,

wherein the attacker profile and the honeypot or honeynet configuration are made available upon request to any of the plurality of users that are registered.

14. The system according to claim 13 , wherein the instructions further cause the system to generate a database for the honeypot or honeynet.

15. The system according to claim 14 , wherein the database is an altered or false database.

16. The system according to claim 15 , wherein the database lacks data that is commercially or confidentially sensitive.

17. The system according to claim 13 , wherein the instructions further cause the system to configure different honeypots or honeynets for different attacker profiles.

18. The system according to claim 13 , wherein the machine learning model is a neural network.

19. The system according to claim 13 , wherein the attacker profile comprises information usable at least in part to identify the attacker.

Assignments (3)
CHANGE OF NAME Recorded Feb 3, 2025
From: NCHAIN HOLDINGS AG
To: NCHAIN LICENSING AG
Reel/Frame 070096/0502 →
CHANGE OF NAME Recorded Mar 19, 2023
From: NCHAIN HOLDINGS LTD
To: NCHAIN LICENSING AG
Reel/Frame 063117/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2020
From: WRIGHT, CRAIG; SAVANAH, STEPHANE
To: NCHAIN HOLDINGS LTD
Reel/Frame 053385/0500 →
Priority Claims (1)
GB 1603118 · Feb 23, 2016 · national
Continuity (2)
Division 16079076
Related Publication 20200366714A1 · Nov 19, 2020
References Cited (80)
US 8661102B1 · Steiner et al. · 2014 [cited by applicant]
US 8682812B1 · Ranjan · 2014 [cited by applicant]
US 9716727B1 · Seger · 2017 [cited by examiner]
US 10050779B2 · Alness et al. · 2018 [cited by applicant]
US 20020133603A1 · Mitomo et al. · 2002 [cited by applicant]
US 20030217283A1 · Hrastar et al. · 2003 [cited by applicant]
US 20040128543A1 · Blake · 2004 [cited by examiner]
US 20040177110A1 · Rounthwaite · 2004 [cited by examiner]
US 20050166072A1 · Converse et al. · 2005 [cited by applicant]
US 20060016198A1 · Stuttaford et al. · 2006 [cited by applicant]
US 20060101515A1 · Amoroso et al. · 2006 [cited by applicant]
US 20060161982A1 · Chari · 2006 [cited by examiner]
US 20060212942A1 · Barford et al. · 2006 [cited by applicant]
US 20060242701A1 · Black · 2006 [cited by examiner]
US 20070067841A1 · Yegneswaran et al. · 2007 [cited by applicant]
US 20070094722A1 · Riordan · 2007 [cited by applicant]
US 20070094728A1 · Julisch et al. · 2007 [cited by applicant]
US 20070192863A1 · Kapoor et al. · 2007 [cited by applicant]
US 20070271614A1 · Capalik · 2007 [cited by applicant]
US 20080016570A1 · Capalik · 2008 [cited by applicant]
US 20080301809A1 · Choi · 2008 [cited by applicant]
US 20090241173A1 · Troyansky · 2009 [cited by applicant]
US 20100071054A1 · Hart · 2010 [cited by applicant]
US 20100077483A1 · Stolfo · 2010 [cited by examiner]
US 20100122342A1 · El-Moussa · 2010 [cited by examiner]
US 20100269175A1 · Stolfo et al. · 2010 [cited by applicant]
US 20100274892A1 · Legrand · 2010 [cited by examiner]
US 20110214182A1 · Adams · 2011 [cited by examiner]
US 20120167208A1 · Buford · 2012 [cited by examiner]
US 20130145465A1 · Wang · 2013 [cited by examiner]
US 20130152199A1 · Capalik · 2013 [cited by applicant]
US 20130305357A1 · Ayyagari · 2013 [cited by examiner]
US 20140298469A1 · Marion · 2014 [cited by examiner]
US 20150033340A1 · Giokas · 2015 [cited by examiner]
US 20150106889A1 · Sharabani et al. · 2015 [cited by applicant]
US 20150229656A1 · Shieh · 2015 [cited by applicant]
US 20160044054A1 · Stiansen et al. · 2016 [cited by applicant]
US 20160065614A1 · Stolfo et al. · 2016 [cited by applicant]
US 20160080414A1 · Kolton et al. · 2016 [cited by applicant]
US 20160164886A1 · Thrash · 2016 [cited by examiner]
US 20160197943A1 · Momot · 2016 [cited by examiner]
US 20160218933A1 · Porras · 2016 [cited by examiner]
US 20170134405A1 · Ahmadzadeh · 2017 [cited by examiner]
US 20170324773A1 · Ohayon · 2017 [cited by examiner]
CN 101087196A · 2007 [cited by examiner]
CN 102254111A · 2011 [cited by applicant]
CN 102546621A · 2012 [cited by examiner]
CN 103607399A · 2014 [cited by applicant]
EP 2657880A1 · 2013 [cited by examiner]
EP 2942919A1 · 2015 [cited by applicant]
JP 2005004617A · 2005 [cited by applicant]
KR 20050082681A · 2005 [cited by examiner]
KR 20050082681A1 · 2005 [cited by examiner]
WO 0223805A2 · 2002 [cited by applicant]
WO 2012011070A1 · 2012 [cited by applicant]
WO 2016005273A1 · 2016 [cited by applicant]
WO WO2017145001A1 · 2017 [cited by examiner]
Tian et al., “A Study of Intrusion Signature Based on Honeypot”, IEEE, doi: 10.1109/PDCAT.2005.51, 2005, pp. 125-129. (Year: 2005). [cited by examiner]
Dagdee et al., “Intrusion Attack Pattern Analysis and Signature Extraction for Web Services Using Honeypots”, IEEE, doi: 10.1109/ICETET.2008.192, 2008, pp. 1232-1237. (Year: 2008). [cited by examiner]
Kuwatly et al., “A dynamic honeypot design for intrusion detection”, IEEE, doi: 10.1109/PERSER.2004.1356776, 2004, pp. 95-104. (Year: 2004). [cited by examiner]
Wagener et al., “Adaptive and self-configurable honeypots”, IEEE, doi: 10.1109/INM.2011.5990710, 2011, pp. 345-352. (Year: 2011). [cited by examiner]
Alese et al., “Improving deception in honeynet: Through data manipulation,” The 9th International Conference for Internet Technology and Secured Transactions (ICITST-2014), 2014, pp. 198-204, doi: 10.1109/ICITST.2014.70… [cited by examiner]
O'Leary et al., “Development of a Honeynet Laboratory: a Case Study,” Seventh ACIS International Conference on Software Engineering, Artificial Intelligence, Networking, and Parallel/Distributed Computing (SNPD'06), 200… [cited by examiner]
Capalik, “Next-Generation Honeynet Technology with Real-Time Forensics for U.S. Defense,” MILCOM 2007—IEEE Military Communications Conference, 2007, pp. 1-7, doi: 10.1109/MILCOM.2007.4455171. (Year: 2007). [cited by examiner]
Tian et al., “A Study of Intrusion Signature Based on Honeypot,” Dalian, China, 2005, pp. 125-129, doi: 10.1109/PDCAT.2005.51. (Year: 2005). [cited by examiner]
Dagdee et al., “Intrusion Attack Pattern Analysis and Signature Extraction for Web Services Using Honeypots,” India, 2008, pp. 1232-1237, doi: 10.1109/ICETET.2008.192. (Year: 2008). [cited by examiner]
Fan et al., “Taxonomy of honeynet solutions,” 2015 SAI Intelligent Systems Conference (IntelliSys), London, UK, 2015, pp. 1002-1009, doi: 10.1109/IntelliSys.2015.7361266. (Year: 2015). [cited by examiner]
Hassan et al., “A Probabilistic Study on the Relationship of Deceptions and Attacker Skills,” 2017 IEEE 15th Intl Conf on Dependable, Autonomic and Secure Computing, 15th Intl Conf on Pervasive Intelligence and Computin… [cited by examiner]
Salles-Loustau et al., “Characterizing Attackers and Attacks: An Empirical Study,” 2011 IEEE 17th Pacific Rim International Symposium on Dependable Computing, Pasadena, CA, USA, 2011, pp. 174-183, doi: 10.1109/PRDC.2011… [cited by examiner]
Wagener et al., “Adaptive and self-configurable honeypots,” 12th IFIP/IEEE International Symposium on Integrated Network Management (IM 2011) and Workshops, Dublin, Ireland, 2011, pp. 345-352, doi: 10.1109/INM.2011.5990… [cited by examiner]
Fraunholz et al, “An Adaptive Honeypot Configuration, Deployment and Maintenance Strategy,” arXiv:2111.03884v1, Nov. 6, 2021. (Year: 2021). [cited by examiner]
Zhang et al., “An Adaptive Honeypot Deployment Algorithm Based on Learning Automata,” 2017 IEEE Second International Conference on Data Science in Cyberspace (DSC), Shenzhen, China, 2017, pp. 521-527, doi: 10.1109/DSC.2… [cited by examiner]
Hassan et al., “A Probabilistic Study on the Relationship of Deceptions and Attacker Skills,” Orlando, FL, USA, 2017, pp. 693-698, doi: 10.1109/DASC-PICom-DataCom-CyberSciTec.2017.121. (Year: 2017). [cited by examiner]
Yang et al., “Evaluating Threat Assessment for Multi-Stage Cyber Attacks,” MILCOM 2006—2006 IEEE Military Communications conference, Washington, DC, USA, 2006, pp. 1-7, doi: 10.1109/MILCOM.2006.302216. (Year: 2006). [cited by examiner]
Paulauskas et al., “Attacker Skill Level distribution estimation in the system mean time-to-compromise,” 2008 1st International Conference on Information Technology, Gdansk, Poland, 2008, pp. 1-4, doi: 10.1109/INFTECH.2… [cited by examiner]
Mézešová et al., “Evaluation of Attacker Skill Level for Multi-stage Attacks,” 2019 11th International Conference on Electronics, Computers and Artificial Intelligence (ECAI), Pitesti, Romania, 2019, pp. 1-6, doi: 10.11… [cited by examiner]
International Search Report and Written Opinion mailed May 12, 2017, Patent Application No. PCT/IB2017/050811, filed Feb. 14, 2017, 9 pages. [cited by applicant]
UK Commercial Search Report mailed Apr. 11, 2016, Patent Application No. 1603118.9, filed Feb. 23, 2016, 3 pages. [cited by applicant]
UK Commercial Search Report with Expanded Report mailed Jun. 29, 2016, Patent Application No. 1603118.9, filed Feb. 23, 2016, 5 pages. [cited by applicant]
UK IPO Search Report mailed Oct. 4, 2016, Patent Application No. 1603118.9, filed Feb. 23, 2016, 4 pages. [cited by applicant]