IP Library › Granted Patent US 11,237,884
Granted Patent B2
US 11,237,884 · App. 17/084,203 · Granted Feb 1, 2022

Automated honeypot creation within a network

Inventors: Austin Walters (McLean, VA); Jeremy Goodsitt (McLean, VA); Vincent Pham (McLean, VA); Kate Key (McLean, VA)
Assignee: Capital One Services, LLC
G06F9/541G06F8/71G06F9/54G06F9/547G06F11/3608G06F11/3628G06F11/3636G06F16/2237G06F16/2264G06F16/248G06F16/2423G06F16/24568G06F16/254G06F16/258G06F16/283G06F16/285G06F16/288G06F16/335G06F16/906G06F16/9038G06F16/90332G06F16/90335G06F16/93G06F17/15G06F17/16G06F17/18G06F21/552G06F21/60G06F21/6245G06F21/6254G06F30/20G06F40/117G06F40/166G06F40/20G06K9/036G06K9/6215G06K9/6218G06K9/6231G06K9/6232G06K9/6253G06K9/6256G06K9/6257G06K9/6262G06K9/6265G06K9/6267G06K9/6269G06K9/6277G06K9/66G06K9/6885G06K9/72G06N3/04G06N3/0445G06N3/0454G06N3/08G06N3/088G06N5/00G06N5/02G06N5/04G06N7/00G06N7/005G06N20/00G06Q10/04G06T7/194G06T7/246G06T7/248G06T7/254G06T11/001H04L63/1416H04L63/1491H04L67/306H04L67/34H04N21/23412H04N21/8153
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,237,884
App. No.
17/084,203
Granted
Feb 1, 2022
Kind
B2
Abstract

Systems and methods for managing Application Programming Interfaces (APIs) are disclosed. Systems may involve automatically generating a honeypot. For example, the system may include one or more memory units storing instructions and one or more processors configured to execute the instructions to perform operations. The operations may include receiving, from a client device, a call to an API node and classifying the call as unauthorized. The operation may include sending the call to a node-imitating model associated with the API node and receiving, from the node-imitating model, synthetic node output data. The operations may include sending a notification based on the synthetic node output data to the client device.

Claims (88)

1. A system comprising:

one or more memory units storing instructions; and

one or more processors that execute the instructions to perform operations comprising:

receiving a call from a client device;

classifying the call as unauthorized based on call data associated with the call;

obtaining, from a routing model, routing data for the call based on the call data associated with the call; and

sending, based on the classifying and the routing data, the call to a node-imitating model of a plurality of node-imitating models such that (i) the call is sent to a first node-imitating model in response to the call data being first call data and (ii) the call is sent to a second node-imitating model in response to the call data being other call data different from the first call data,

wherein (i) the first node-imitating model is trained based on a first set of training data related to a first set of prior calls that is provided to the first node-imitating model and (ii) the second node-imitating model is trained based on a second set of training data related to a second set of prior calls that is provided to the second node-imitating model,

wherein the first and second node-imitating models have different configurations for processing the call as a result of the training of the first and second node-imitating models.

2. The system of claim 1 , wherein the operations further comprise:

providing training call data to the routing model to train the routing model to route calls to one or more of the plurality of node-imitating models.

3. The system of claim 2 , wherein the operations further comprise:

receiving, from the first node-imitating model, synthetic node output data based on the call;

providing the synthetic node output data to the client device;

receiving a second call and classifying the second call as unauthorized based on second call data associated with the second call; and

sending the second call to the second node-imitating model based on the classifying of the second call, the second call data, and the trained routing model.

4. The system of claim 3 , wherein the operations further comprise:

sending a notification to the client device based on the synthetic node output data, the notification comprising a data marker;

searching a remote computing resource for the data marker;

receiving search results from the remote computing resource;

identifying a location of the data marker based on the search results; and

storing the location.

5. The system of claim 4 , wherein the location comprises at least one of an IP address, a MAC address, or a uniform resource locator (URL).

6. The system of claim 1 , wherein the first node-imitating model comprises a first machine-learning model.

7. The system of claim 6 , wherein the operations further comprise:

receiving a collection of call data based on a plurality of calls;

receiving synthetic node output data based on the plurality of calls; and

training the first node-imitating model using the collection of call data and the synthetic node output data.

8. The system of claim 7 , wherein:

the synthetic node output data is first synthetic node output data; and

training the first node-imitating model comprises iteratively training by:

generating, based on the call data, second synthetic node output data using the first node-imitating model;

determining a first similarity metric value between the second synthetic node output data and the synthetic node output data; and

performing, based on the first similarity metric value, one of:

updating a parameter of the first node-imitating model; or

terminating training of the first node-imitating model.

9. The system of claim 1 , wherein classifying the call as unauthorized comprises classifying the call as unauthorized based on at least one of a log, a failed authentication attempt, a packet-sniffing event, a rate of pinging, an account, an Internet Protocol (IP) address, or a media access control (MAC) address.

10. The system of claim 1 , the operations further comprising:

identifying a location associated with the client device, the location comprising at least one of an IP address or a MAC address; and

blocking the location from accessing an API node associated with any of the plurality of node-imitating models.

11. A method, comprising:

receiving a call from a client device;

classifying the call as unauthorized based on call data associated with the call;

obtaining, from a routing model, routing data for the call based on the call data associated with the call; and

sending, based on the classifying and the routing data, the call to a node-imitating model of a plurality of node-imitating models such that (i) the call is sent to a first node-imitating model in response to the call data being first call data and (ii) the call is sent to a second node-imitating model in response to the call data being other call data different from the first call data,

wherein (i) the first node-imitating model is trained based on a first set of training data related to a first set of prior calls that is provided to the first node-imitating model and (ii) the second node-imitating model is trained based on a second set of training data related to a second set of prior calls that is provided to the second node-imitating model, and

wherein the first and second node-imitating models have different configurations as a result of the training of the first and second node-imitating models.

12. The method of claim 11 , further comprising:

providing training call data to the routing model to train the routing model to route calls to one or more of the plurality of node-imitating models.

13. The method of claim 12 , further comprising:

receiving, from the first node-imitating model, synthetic node output data based on the call;

providing the synthetic node output data to the client device;

receiving a second call and classifying the second call as unauthorized based on second call data associated with the second call; and

sending the second call to the second node-imitating model based on the classifying of the second call, the second call data, and the trained routing model.

14. The method of claim 13 , further comprising:

sending a notification to the client device based on the synthetic node output data, the notification comprising a data marker;

searching a remote computing resource for the data marker;

receiving search results from the remote computing resource;

identifying a location of the data marker based on the search results; and

storing the location.

15. The method of claim 11 , wherein the first node-imitating model comprises a first machine-learning model.

16. The method of claim 15 , wherein the method further comprises:

receiving a collection of call data based on a plurality of calls;

receiving synthetic node output data based on the plurality of calls; and

training the first node-imitating model using the collection of call data and the synthetic node output data.

17. The method of claim 16 , wherein:

the synthetic node output data is first synthetic node output data; and

training the first node-imitating model comprises iteratively training by:

generating, based on the call data, second synthetic node output data using the first node-imitating model;

determining a first similarity metric value between the second synthetic node output data and the synthetic node output data; and

performing, based on the first similarity metric value, one of:

updating a parameter of the first node-imitating model; or

terminating training of the first node-imitating model.

18. The method of claim 11 , wherein classifying the call as unauthorized comprises classifying the call as unauthorized based on at least one of a log, a failed authentication attempt, a packet-sniffing event, a rate of pinging, an account, an Internet Protocol (IP) address, or a media access control (MAC) address; and

wherein the method further comprises:

identifying a location associated with the client device, the location comprising at least one of the IP address or the MAC address; and

blocking the location from accessing an API node associated with any of the plurality of node-imitating models.

19. A non-transitory computer readable medium comprising instructions that, when executed by one or more processors, perform operations comprising:

receiving a call from a client device;

classifying the call as unauthorized based on call data associated with the call;

obtaining, from a routing model, routing data for the call based on the call data associated with the call; and

sending, based on the classifying and the routing data, the call to a node-imitating model of a plurality of node-imitating models such that (i) the call is sent to a first node-imitating model in response to the call data being first call data and (ii) the call is sent to a second node-imitating model in response to the call data being other call data different from the first call data,

wherein (i) the first node-imitating model is trained based on a first set of training data related to a first set of prior calls that is provided to the first node-imitating model and (ii) the second node-imitating model is trained based on a second set of training data related to a second set of prior calls that is provided to the second node-imitating model, and

wherein the first and second node-imitating models have different configurations as a result of the training of the first and second node-imitating models.

20. The medium of claim 19 , the operations further comprising:

receiving a collection of call data based on a plurality of calls;

receiving synthetic node output data based on the plurality of calls; and

training the first node-imitating model using the collection of call data and the synthetic node output data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2020
From: WALTERS, AUSTIN; GOODSITT, JEREMY; PHAM, VINCENT; KEY, KATE
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 054214/0989 →
Continuity (3)
Continuation 16362537 · Mar 22, 2019
Provisional Application 62694968 · Jul 6, 2018
Related Publication 20210049054A1 · Feb 18, 2021
Cited By (1)
US 12,699,679