IP Library Granted Patent US 11,489,870
Granted Patent B2
US 11,489,870 · App. 17/210,671 · Granted Nov 1, 2022

Behavior management of deception system fleets

Inventor: Thomas Eugene Sellers (Georgetown, TX)
Assignee: Rapid7, Inc.
H04L63/1491H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,870
App. No.
17/210,671
Granted
Nov 1, 2022
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes for managing and controlling the collective behavior of deception computing system fleets. A malicious attack initiated by a malicious attacker received by a honeypot that is part of a network along with other honeypots is detected. Information associated with the malicious attack is received from the honeypot. Based on the received information, a subset of honeypots other than the honeypot are configured to entice the attacker to engage with the subset of honeypots or avoid the subset of honeypots.

Claims (69)

1. A computer-implemented method, comprising:

receiving attack data of a malicious attack directed at a target honeypot in a network;

accessing a fleet state table to identify a profile of one or more additional target honeypots sought or expected by the malicious attack;

determining whether one or more security goals of the network require attacker engagement or attacker avoidance; and

if the one or more security goals of the network require attacker engagement,

changing a personality of a subset of honeypots in a honeypot fleet identified for provisioning using a personality state table to match the profile of the target honeypot, or

if the one or more security goals of the network require attacker avoidance,

changing the personality of the subset of honeypots in the honeypot fleet identified for the provisioning using the personality state table to differ from the profile of the target honeypot.

2. The computer-implemented method of claim 1 , further comprising:

updating the fleet state table based on whether the personality of the subset of honeypots is changed for attacker engagement or attacker avoidance.

3. The computer-implemented method of claim 2 , further comprising:

transmitting a flocking instruction to the subset of honeypots to perform a scaled flocking operation.

4. The computer-implemented method of claim 3 , wherein

performing the scaled flocking operation comprises:

scaling the subset of honeypots up based on the personality if the personality change is for attacker engagement or

scaling the subset of honeypots down based on the personality if the personality change is for attacker avoidance.

5. The computer-implemented method of claim 1 , further comprising:

configuring the subset of honeypots to be vulnerable to the malicious attack directed at the target honeypot.

6. The computer-implemented method of claim 5 , wherein

the configuring is performed based on at least an attacker location, a vulnerability age, or an unknown vulnerability that are part of the attack data.

7. The computer-implemented method of claim 1 , further comprising:

changing a personality of a first subset of honeypots in the honeypot fleet to match the profile of the target honeypot if the one or more security goals of the network require attacker engagement; and

changing a personality of a second subset of honeypots in the honeypot fleet to differ from the profile of the target honeypot if the one or more security goals of the network require attacker avoidance.

8. A non-transitory computer readable storage medium comprising program instructions executable to:

receive attack data of a malicious attack directed at a target honeypot in a network;

access a fleet state table to identify a profile of one or more additional target honeypots sought or expected by the malicious attack;

determine whether one or more security goals of the network require attacker engagement or attacker avoidance; and

if the one or more security goals of the network require attacker engagement,

change a personality of a subset of honeypots in a honeypot fleet identified for provisioning using a personality state table to match the profile of the target honeypot, or

if the one or more security goals of the network require attacker avoidance,

change the personality of the subset of honeypots in the honeypot fleet identified for the provisioning using the personality state table to differ from the profile of the target honeypot.

9. The non-transitory computer readable storage medium of claim 8 , further comprising:

updating the fleet state table based on whether the personality of the subset of honeypots is changed for attacker engagement or attacker avoidance.

10. The non-transitory computer readable storage medium of claim 9 , further comprising:

transmitting a flocking instruction to the subset of honeypots to perform a scaled flocking operation.

11. The non-transitory computer readable storage medium of claim 10 , wherein

performing the scaled flocking operation comprises:

scaling the subset of honeypots up based on the personality if the personality change is for attacker engagement or

scaling the subset of honeypots down based on the personality if the personality change is for attacker avoidance.

12. The non-transitory computer readable storage medium of claim 8 , further comprising:

configuring the subset of honeypots to be vulnerable to the malicious attack directed at the target honeypot.

13. The non-transitory computer readable storage medium of claim 12 , wherein

the configuring is performed based on at least an attacker location, a vulnerability age, or an unknown vulnerability that are part of the attack data.

14. The non-transitory computer readable storage medium of claim 8 , further comprising:

changing a personality of a first subset of honeypots in the honeypot fleet to match the profile of the target honeypot if the one or more security goals of the network require attacker engagement; and

changing a personality of a second subset of honeypots in the honeypot fleet to differ from the profile of the target honeypot if the one or more security goals of the network require attacker avoidance.

15. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

receive attack data of a malicious attack directed at a target honeypot in a network;

access a fleet state table to identify a profile of one or more additional target honeypots sought or expected by the malicious attack;

determine whether one or more security goals of the network require attacker engagement or attacker avoidance; and

if the one or more security goals of the network require attacker engagement,

change a personality of a subset of honeypots in a honeypot fleet identified for provisioning using a personality state table to match the profile of the target honeypot, or

if the one or more security goals of the network require attacker avoidance,

change the personality of the subset of honeypots in the honeypot fleet identified for the provisioning using the personality state table to differ from the profile of the target honeypot.

16. The system of claim 15 , further comprising:

updating the fleet state table based on whether the personality of the subset of honeypots is changed for attacker engagement or attacker avoidance.

17. The system of claim 16 , further comprising:

transmitting a flocking instruction to the subset of honeypots to perform a scaled flocking operation.

18. The system of claim 17 , wherein

performing the scaled flocking operation comprises:

scaling the subset of honeypots up based on the personality if the personality change is for attacker engagement or

scaling the subset of honeypots down based on the personality if the personality change is for attacker avoidance.

19. The system of claim 15 , further comprising:

configuring the subset of honeypots to be vulnerable to the malicious attack directed at the target honeypot based on at least an attacker location, a vulnerability age, or an unknown vulnerability that are part of the attack data.

20. The system of claim 15 , further comprising:

changing a personality of a first subset of honeypots in the honeypot fleet to match the profile of the target honeypot if the one or more security goals of the network require attacker engagement; and

changing a personality of a second subset of honeypots in the honeypot fleet to differ from the profile of the target honeypot if the one or more security goals of the network require attacker avoidance.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2021
From: SELLERS, THOMAS EUGENE
To: RAPID7, INC.
Reel/Frame 055696/0666 →
Continuity (3)
Continuation 16367897 · Mar 28, 2019
Continuation In Part 16367502 · Mar 28, 2019
Related Publication 20210211466A1 · Jul 8, 2021