IP Library Granted Patent US 11,575,709
Granted Patent B2
US 11,575,709 · App. 17/201,353 · Granted Feb 7, 2023

Monitoring and reporting connection attempts in a network

Inventors: Roy Hodgman (Cambridge, MA); Jeffrey D. Myers (Cambridge, MA)
Assignee: Rapid7, Inc.
H04L63/1491H04L63/0281H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,575,709
App. No.
17/201,353
Granted
Feb 7, 2023
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes for monitoring scan attempts in a network. A virtual security appliance with multiple ports is deployed in a network. One or more ports are obfuscated via the virtual security appliance to make the various ports appear to be closed. An address of the virtual security appliance within the network is modified, the several ports are adjusted to assume a predetermined profile, a network neighbor's profile is discovered and emulated, and a received connection attempt intended for the virtual security appliance is monitored.

Claims (35)

1. A computer-implemented method, comprising:

deploying a virtual security appliance in a network, wherein

the virtual security appliance comprises a plurality of ports;

obfuscating, via the virtual security appliance, a port of the plurality of ports to make the port of the plurality of ports appear to be closed;

modifying an address of the virtual security appliance within the network;

adjusting the plurality of ports to assume a predetermined profile;

discovering a network neighbor's profile;

emulating the network neighbor's profile;

monitoring a received connection attempt intended for the virtual security appliance;

identifying, using one or more credentials, the virtual security appliance as a honeypot device to a device on the network in communication with the virtual security appliance as part of the received connection attempt by scanning one or more ports of the device in a predetermined order to identify the virtual security appliance as the honeypot device; and

reporting the received connection attempt.

2. A non-transitory computer readable storage medium comprising program instructions executable to:

deploy a virtual security appliance in a network, wherein

the virtual security appliance comprises a plurality of ports;

obfuscate, via the virtual security appliance, a port of the plurality of ports to make the port of the plurality of ports appear to be closed;

modify an address of the virtual security appliance within the network;

adjust the plurality of ports to assume a predetermined profile;

discover a network neighbor's profile;

emulate the network neighbor's profile;

monitor a received connection attempt intended for the virtual security appliance;

identifying, using one or more credentials, the virtual security appliance as a honeypot device to a device on the network in communication with the virtual security appliance as part of the received connection attempt by scanning one or more ports of the device in a predetermined order to identify the virtual security appliance as the honeypot device; and

reporting the received connection attempt.

3. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

deploy a virtual security appliance in a network, wherein

the virtual security appliance comprises a plurality of ports;

obfuscate, via the virtual security appliance, a port of the plurality of ports to make the port of the plurality of ports appear to be closed;

modify an address of the virtual security appliance within the network;

adjust the plurality of ports to assume a predetermined profile;

discover a network neighbor's profile;

emulate the network neighbor's profile;

monitor a received connection attempt intended for the virtual security appliance;

identifying, using one or more credentials, the virtual security appliance as a honeypot device to a device on the network in communication with the virtual security appliance as part of the received connection attempt by scanning one or more ports of the device in a predetermined order to identify the virtual security appliance as the honeypot device; and

reporting the received connection attempt.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2021
From: HODGMAN, ROY; MYERS, JEFFREY
To: RAPID7, INC.
Reel/Frame 055591/0556 →
Continuity (2)
Continuation 16546663 · Aug 21, 2019
Related Publication 20210288998A1 · Sep 16, 2021