IP Library Granted Patent US 11,522,912
Granted Patent B2
US 11,522,912 · App. 17/205,134 · Granted Dec 6, 2022

Honeypot opaque credential recovery

Inventors: Thomas Eugene Sellers (Georgetown, TX); Derek Abdine (Rancho Palos Verdes, CA)
Assignee: Rapid7, Inc.
H04L63/1491G06F21/45
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,522,912
App. No.
17/205,134
Granted
Dec 6, 2022
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes for recovering opaque credentials in deception systems. A plaintext credential is received at a honeypot and a plaintext lookup table is accessed. It is determined that the plaintext credential does not exist in the plaintext lookup table and the plaintext credential is added to the plaintext lookup table and a protocol specific plaintext lookup table. An opaque credential is generated for the plaintext credential and the opaque credential is added to a protocol specific opaque lookup table.

Claims (86)

1. A computer-implemented method, comprising:

receiving, at a honeypot, a plaintext credential from an original attacker as part of an original attack event;

determining that the plaintext credential does not exist in a plaintext lookup table;

adding the plaintext credential to the plaintext lookup table;

adding the plaintext credential to a protocol specific plaintext lookup table to associate the plaintext credential previously added to the plaintext lookup table with a protocol used by the honeypot to perform credential exchange;

generating an opaque credential for the plaintext credential;

adding the opaque credential to a protocol specific opaque lookup table;

generating attack context metadata associated with the original attack event;

adding the attack context metadata to the protocol specific plaintext lookup table;

storing the attack context metadata associated with the original attack event in the protocol specific opaque lookup table;

receiving, at the honeypot, from the original attacker as part the original attack event or from a subsequent attacker as part of a subsequent attack event, an opaque credential for the protocol used by the honeypot to perform the credential exchange;

accessing the protocol specific opaque lookup table; and

recovering the plaintext credential associated with the opaque credential.

2. The computer-implemented method of claim 1 , wherein

the attack context metadata comprises one or more attack vectors, one or more exploits used, or one or more vulnerabilities targeted by the original attacker as part of the original attack event.

3. The computer-implemented method of claim 1 , further comprising:

modifying one or more logs generated for the original attack event or for the subsequent attack event to comprise the recovered plaintext credential;

configuring the honeypot to consider the recovered plaintext credential as valid;

updating the plaintext lookup table with the recovered plaintext credential; and

sending the updated plaintext lookup table, the protocol specific plaintext lookup table, and the attack context metadata to a honeypot management server for performance of the credential exchange.

4. The computer-implemented method of claim 3 , further comprising:

receiving, at the honeypot, a new plaintext credential;

sending the new plaintext credential to the honeypot management server;

receiving a global opaque lookup table from the honeypot management server;

receiving a new opaque credential;

sending the new opaque credential to the honeypot management server;

receiving a newly-recovered plaintext credential for the new opaque credential from the honeypot management server; and

receiving confirmation from the honeypot management server that the updated plaintext lookup table further updated with the newly-recovered plaintext credential has been sent to one or more other honeypots.

5. A non-transitory computer readable storage medium comprising program instructions executable to:

receive, at a honeypot, a plaintext credential from an original attacker as part of an original attack event;

determine that the plaintext credential does not exist in a plaintext lookup table;

add the plaintext credential to the plaintext lookup table;

add the plaintext credential to a protocol specific plaintext lookup table to associate the plaintext credential previously added to the plaintext lookup table with a protocol used by the honeypot to perform credential exchange;

generate an opaque credential for the plaintext credential;

add the opaque credential to a protocol specific opaque lookup table;

generate attack context metadata associated with the original attack event;

add the attack context metadata to the protocol specific plaintext lookup table;

store the attack context metadata associated with the original attack event in the protocol specific opaque lookup table;

receive, at the honeypot, from the original attacker as part the original attack event or from a subsequent attacker as part of a subsequent attack event, an opaque credential for the protocol used by the honeypot to perform the credential exchange;

access the protocol specific opaque lookup table; and

recover the plaintext credential associated with the opaque credential.

6. The non-transitory computer readable storage medium of claim 5 , wherein

the attack context metadata comprises one or more attack vectors, one or more exploits used, or one or more vulnerabilities targeted by the original attacker as part of the original attack event.

7. The non-transitory computer readable storage medium of claim 5 , further comprising:

modifying one or more logs generated for the original attack event or for the subsequent attack event to comprise the recovered plaintext credential;

configuring the honeypot to consider the recovered plaintext credential as valid;

updating the plaintext lookup table with the recovered plaintext credential; and

sending the updated plaintext lookup table, the protocol specific plaintext lookup table, and the attack context metadata to a honeypot management server for performance of the credential exchange.

8. The non-transitory computer readable storage medium of claim 7 , further comprising:

receiving, at the honeypot, a new plaintext credential;

sending the new plaintext credential to the honeypot management server;

receiving a global opaque lookup table from the honeypot management server;

receiving a new opaque credential;

sending the new opaque credential to the honeypot management server;

receiving a newly-recovered plaintext credential for the new opaque credential from the honeypot management server; and

receiving confirmation from the honeypot management server that the updated plaintext lookup table further updated with the newly-recovered plaintext credential has been sent to one or more other honeypots.

9. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

receive, at a honeypot, a plaintext credential from an original attacker as part of an original attack event;

determine that the plaintext credential does not exist in a plaintext lookup table;

add the plaintext credential to the plaintext lookup table;

add the plaintext credential to a protocol specific plaintext lookup table to associate the plaintext credential previously added to the plaintext lookup table with a protocol used by the honeypot to perform credential exchange;

generate an opaque credential for the plaintext credential;

add the opaque credential to a protocol specific opaque lookup table;

generate attack context metadata associated with the original attack event;

add the attack context metadata to the protocol specific plaintext lookup table;

store the attack context metadata associated with the original attack event in the protocol specific opaque lookup table;

receive, at the honeypot, from the original attacker as part the original attack event or from a subsequent attacker as part of a subsequent attack event, an opaque credential for the protocol used by the honeypot to perform the credential exchange;

access the protocol specific opaque lookup table; and

recover the plaintext credential associated with the opaque credential.

10. The system of claim 9 , wherein

the attack context metadata comprises one or more attack vectors, one or more exploits used, or one or more vulnerabilities targeted by the original attacker as part of the original attack event.

11. The system of claim 9 , further comprising:

modifying one or more logs generated for the original attack event or for the subsequent attack event to comprise the recovered plaintext credential;

configuring the honeypot to consider the recovered plaintext credential as valid;

updating the plaintext lookup table with the recovered plaintext credential; and

sending the updated plaintext lookup table, the protocol specific plaintext lookup table, and the attack context metadata to a honeypot management server for performance of the credential exchange.

12. The system of claim 11 , further comprising:

receiving, at the honeypot, a new plaintext credential;

sending the new plaintext credential to the honeypot management server;

receiving a global opaque lookup table from the honeypot management server;

receiving a new opaque credential;

sending the new opaque credential to the honeypot management server;

receiving a newly-recovered plaintext credential for the new opaque credential from the honeypot management server; and

receiving confirmation from the honeypot management server that the updated plaintext lookup table further updated with the newly-recovered plaintext credential has been sent to one or more other honeypots.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2021
From: SELLERS, THOMAS EUGENE; ABDINE, DEREK
To: RAPID7, INC.
Reel/Frame 055635/0187 →
Continuity (2)
Continuation 16369253 · Mar 29, 2019
Related Publication 20210226992A1 · Jul 22, 2021