IP Library Granted Patent US 11,411,993
Granted Patent B2
US 11,411,993 · App. 17/204,157 · Granted Aug 9, 2022

Ratio-based management of honeypot fleets

Inventor: Thomas Eugene Sellers (Georgetown, TX)
Assignee: Rapid7, Inc.
H04L63/1491H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,993
App. No.
17/204,157
Granted
Aug 9, 2022
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes for dynamically deploying deception computing systems based on network environment lifecycle. Based on available lifecycle metadata associated with honeypots, a determination is made as to whether honeypot deployment criteria require maintaining a likelihood that a malicious attacker will target a given honeypot and/or preventing the malicious attacker from determining if a target is a protected host or the given honeypot. If a honeypot deployment criteria requires maintaining a likelihood that the malicious attacker will target the given honeypot, a ratio management operation is performed. In addition, if another honeypot deployment criteria requires preventing the malicious attacker from determining if the target is the protected host or the given honeypot, a host replacement operation is performed.

Claims (29)

1. A computer-implemented method, comprising:

retrieving lifecycle metadata associated with a plurality of protected hosts in a network;

accessing information comprising one or more honeypot deployment criteria;

determining that at least one criteria of the one or more honeypot deployment criteria requires maintaining a likelihood that a malicious attacker will target at least one honeypot of a plurality of honeypots deployed in the network instead of at least one protected host of the plurality of protected hosts;

accessing a configurable ratio of the plurality of honeypots to the plurality of protected hosts; and

deploying one or more new honeypots in addition to the plurality of honeypots as one or more new protected hosts in addition to the plurality of protected hosts come online in the network or discharging one or more existing honeypots from the plurality of honeypots as one or more existing hosts that make up the plurality of protected hosts go offline from the network, to maintain the configurable ratio.

2. The computer-implemented method of claim 1 , further comprising:

determining that at least one other criteria of the one or more honeypot deployment criteria requires preventing the malicious attacker from being able to determine whether a target is the at least one honeypot or the at least one protected host; and

performing a host replacement operation using one or more explicit personality clones based on ingress of the one or more new protected hosts to the network and egress of the one or more existing honeypots from the network.

3. A non-transitory computer readable storage medium comprising program instructions executable to:

retrieve lifecycle metadata associated with a plurality of protected hosts in a network;

access information comprising one or more honeypot deployment criteria;

determine that at least one criteria of the one or more honeypot deployment criteria requires maintaining a likelihood that a malicious attacker will target at least one honeypot of a plurality of honeypots deployed in the network instead of at least one protected host of the plurality of protected hosts;

access a configurable ratio of the plurality of honeypots to the plurality of protected hosts; and

deploy one or more new honeypots in addition to the plurality of honeypots as one or more new protected hosts in addition to the plurality of protected hosts come online in the network or discharge one or more existing honeypots from the plurality of honeypots as one or more existing hosts that make up the plurality of protected hosts go offline from the network, to maintain the configurable ratio.

4. The non-transitory computer readable storage medium of claim 3 , further comprising:

determining that at least one other criteria of the one or more honeypot deployment criteria requires preventing the malicious attacker from being able to determine whether a target is the at least one honeypot or the at least one protected host; and

performing a host replacement operation using one or more explicit personality clones based on ingress of the one or more new protected hosts to the network and egress of the one or more existing honeypots from the network.

5. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

retrieve lifecycle metadata associated with a plurality of protected hosts in a network;

access information comprising one or more honeypot deployment criteria;

determine that at least one criteria of the one or more honeypot deployment criteria requires maintaining a likelihood that a malicious attacker will target at least one honeypot of a plurality of honeypots deployed in the network instead of at least one protected host of the plurality of protected hosts;

access a configurable ratio of the plurality of honeypots to the plurality of protected hosts; and

deploy one or more new honeypots in addition to the plurality of honeypots as one or more new protected hosts in addition to the plurality of protected hosts come online in the network or discharge one or more existing honeypots from the plurality of honeypots as one or more existing hosts that make up the plurality of protected hosts go offline from the network, to maintain the configurable ratio.

6. The system of claim 5 , further comprising:

determining that at least one other criteria of the one or more honeypot deployment criteria requires preventing the malicious attacker from being able to determine whether a target is the at least one honeypot or the at least one protected host; and

performing a host replacement operation using one or more explicit personality clones based on ingress of the one or more new protected hosts to the network and egress of the one or more existing honeypots from the network.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2021
From: SELLERS, THOMAS EUGENE
To: RAPID7, INC.
Reel/Frame 055622/0373 →
Continuity (2)
Continuation 16367354 · Mar 28, 2019
Related Publication 20210203696A1 · Jul 1, 2021