IP Library Granted Patent US 11,496,515
Granted Patent B2
US 11,496,515 · App. 17/203,823 · Granted Nov 8, 2022

Honeypot deployment based on lifecycle of protected hosts

Inventor: Thomas Eugene Sellers (Georgetown, TX)
Assignee: Rapid7, Inc.
H04L63/1491H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,515
App. No.
17/203,823
Granted
Nov 8, 2022
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes for dynamically deploying deception computing systems based on network environment lifecycle. Lifecycle metadata associated with protected hosts in a network is retrieved. A configurable ratio of honeypots to the protected hosts is accessed. One or more honeypots are deployed based on: the configurable ratio if the lifecycle metadata can be retrieved or determined, or on a schedule if the lifecycle metadata cannot be retrieved or determined, but can be estimated.

Claims (49)

1. A computer-implemented method, comprising:

retrieving lifecycle metadata associated with a plurality of protected hosts in a network;

accessing a configurable ratio of a plurality of honeypots to the plurality of protected hosts; and

deploying in or discharging from, the network, one or more honeypots of the plurality of honeypots based on:

the configurable ratio if the lifecycle metadata can be retrieved or determined, or

a schedule if the lifecycle metadata cannot be retrieved or determined, but can be estimated.

2. The computer-implemented method of claim 1 , further comprising:

determining that the plurality of honeypots and the plurality of protected hosts do not share a Layer 2 (L 2 ) network segment; and

modifying a network route in the network to direct attacker traffic to a network location of the plurality of honeypots.

3. The computer-implemented method of claim 1 , further comprising:

determining that a protected host of the plurality of protected hosts is no longer part of the network; and

performing a host replacement operation to replace the protected host with a honeypot that is an explicit personality clone of the protected host.

4. The computer-implemented method of claim 1 , wherein

the lifecycle metadata comprises Dynamic Host Configuration Protocol (DHCP) log data, data collected by an agent-based computing system, network infrastructure log data, or protected host data generated by direct monitoring.

5. The computer-implemented method of claim 2 , wherein

the host replacement operation is performed based on one or more deployment criteria.

6. A non-transitory computer readable storage medium comprising program instructions executable to:

retrieve lifecycle metadata associated with a plurality of protected hosts in a network;

access a configurable ratio of a plurality of honeypots to the plurality of protected hosts; and

deploy in or discharge from, the network, one or more honeypots of the plurality of honeypots based on:

the configurable ratio if the lifecycle metadata can be retrieved or determined, or

a schedule if the lifecycle metadata cannot be retrieved or determined, but can be estimated.

7. The non-transitory computer readable storage medium of claim 6 , further comprising:

determining that the plurality of honeypots and the plurality of protected hosts do not share a Layer 2 (L 2 ) network segment; and

modifying a network route in the network to direct attacker traffic to a network location of the plurality of honeypots.

8. The non-transitory computer readable storage medium of claim 6 , further comprising:

determining that a protected host of the plurality of protected hosts is no longer part of the network; and

performing a host replacement operation to replace the protected host with a honeypot that is an explicit personality clone of the protected host.

9. The non-transitory computer readable storage medium of claim 6 , wherein

the lifecycle metadata comprises Dynamic Host Configuration Protocol (DHCP) log data, data collected by an agent-based computing system, network infrastructure log data, or protected host data generated by direct monitoring.

10. The non-transitory computer readable storage medium of claim 7 , wherein

the host replacement operation is performed based on one or more deployment criteria.

11. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

retrieve lifecycle metadata associated with a plurality of protected hosts in a network;

access a configurable ratio of a plurality of honeypots to the plurality of protected hosts; and

deploy in or discharge from, the network, one or more honeypots of the plurality of honeypots based on:

the configurable ratio if the lifecycle metadata can be retrieved or determined, or

a schedule if the lifecycle metadata cannot be retrieved or determined, but can be estimated.

12. The system of claim 11 , further comprising:

determining that the plurality of honeypots and the plurality of protected hosts do not share a Layer 2 (L 2 ) network segment; and

modifying a network route in the network to direct attacker traffic to a network location of the plurality of honeypots.

13. The system of claim 11 , further comprising:

determining that a protected host of the plurality of protected hosts is no longer part of the network; and

performing a host replacement operation to replace the protected host with a honeypot that is an explicit personality clone of the protected host.

14. The system of claim 13 , wherein

the lifecycle metadata comprises Dynamic Host Configuration Protocol (DHCP) log data, data collected by an agent-based computing system, network infrastructure log data, or protected host data generated by direct monitoring, and

the host replacement operation is performed based on one or more deployment criteria.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2021
From: SELLERS, THOMAS EUGENE
To: RAPID7, INC.
Reel/Frame 055622/0373 →
Continuity (2)
Continuation 16367354 · Mar 28, 2019
Related Publication 20210211465A1 · Jul 8, 2021