IP Library Granted Patent US 12,732,539
Granted Patent B2
US 12,732,539 · App. 18/360,124 · Granted Sep 8, 2026

AI-based honeypot to mitigate social engineering cyberattack

Inventors: M. David Hanes (Lewisville, NC); Amanda L. Holst (Campbell, CA); Sudha Katgeri (Allen, TX); Ana M Montenegro (Mexico City, MX); Ishita Maheshkumar Thanki (San Jose, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/1491H04L63/1416H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,539
App. No.
18/360,124
Granted
Sep 8, 2026
Kind
B2
Abstract

A method includes creating, via a server, a plurality of virtualized human personalities associated with respective human users; receiving, via the server, a cyberattack message; determining, via the server, the cyberattack message targets a human user of the respective human users; selecting, via the server, a virtualized human personality of the plurality of virtualized human personalities based on the virtualized human personality being associated with the human user targeted by the cyberattack message; and responding, via the server, to the cyberattack message using the virtualized human personality selected from the plurality of virtualized human personalities.

Claims (58)

1 . A method comprising:

creating, via a server, a plurality of virtualized human personalities associated with respective human users;

receiving, via the server, a cyberattack message;

determining, via the server, the cyberattack message does not target any of the respective human users;

selecting, via the server, an additional virtualized human personality that is not associated with the respective human users in response to determining the cyberattack message does not target any of the respective human users; and

responding, via the server, to the cyberattack message using the additional virtualized human personality.

2 . The method of claim 1 , wherein responding, via the server, to the cyberattack message using the additional virtualized human personality comprises:

generating, via the server, a response using the additional virtualized human personality; and

sending, via the server, the response.

3 . The method of claim 2 , wherein the response is generated using the additional virtualized human personality and a plurality of large language models.

4 . The method of claim 2 , further comprising generating, via the server, a honeypot profile, wherein the response is sent via the honeypot profile.

5 . The method of claim 1 , further comprising determining, via the server, user information associated with the respective human users from social media profiles related to the respective human users, wherein the plurality of virtualized human personalities is created based on the user information determined from the social media profiles.

6 . The method of claim 1 , wherein responding to the cyberattack message using the additional virtualized human personality comprises transmitting, via the server, a response that incorporates user information.

7 . The method of claim 1 , further comprising:

generating the additional virtualized human personality by compiling information related to other human users.

8 . The method of claim 1 , wherein responding to the cyberattack message using the additional virtualized human personality comprises transmitting, via the server, a response that does not incorporate any user information.

9 . The method of claim 1 , wherein the additional virtualized human personality is randomly selected.

10 . A non-transitory computer readable medium comprising instructions that, when executed by one or more processors, are configured to cause the one or more processors to perform operations comprising:

creating a generic virtualized human personality that is not associated with any human user;

creating a specific virtualized human personality associated with a human user;

receiving a first cyberattack message;

determining whether the first cyberattack message is targeted to any human user;

responding to the first cyberattack message with a first response message generated using the generic virtualized human personality in response to determining the first cyberattack message is not targeted to any human user;

receiving a second cyberattack message;

determining whether the second cyberattack message is targeted to any human user; and

responding to the second cyberattack message with a second response message generated using the specific virtualized human personality in response to determining the second cyberattack message is targeted to the human user.

11 . The non-transitory computer readable medium of claim 10 , wherein the instructions, when executed by the one or more processors, are configured to cause the one or more processors to perform operations comprising:

identifying information related to the human user from a social media platform; and

creating the specific virtualized human personality based on the information.

12 . The non-transitory computer readable medium of claim 11 , wherein the instructions, when executed by the one or more processors, are configured to cause the one or more processors to respond to the second cyberattack message using the specific virtualized human personality by sending a response message containing the information related to the human user.

13 . The non-transitory computer readable medium of claim 10 , wherein the instructions, when executed by the one or more processors, are configured to cause the one or more processors to perform operations comprising:

determining information related to the human user is unavailable; and

creating the specific virtualized human personality based on default information.

14 . The non-transitory computer readable medium of claim 10 , wherein the instructions, when executed by the one or more processors, are configured to cause the one or more processors to respond to the second cyberattack message using the specific virtualized human personality by generating the second response message using a plurality of large language models (LLMs) and outputting the second response message.

15 . The non-transitory computer readable medium of claim 14 , wherein the instructions, when executed by the one or more processors, are configured to cause the one or more processors to perform operations comprising:

determining an additional cyberattack message is not received within a threshold duration of time since output of the second response message; and

adjusting generation of a subsequent response message using the plurality of LLMs in response to determining the additional cyberattack message is not received within the threshold duration of time since the output of the second response message.

16 . The non-transitory computer readable medium of claim 10 , wherein the instructions, when executed by the one or more processors, are configured to cause the one or more processors to perform operations comprising:

selecting a mood as a basis for generating response messages; and

generating the first response message and/or the second response message in accordance with the mood.

17 . The non-transitory computer readable medium of claim 10 , wherein the first response message and/or the second response message contain a company status.

18 . An apparatus comprising:

a memory configured to store instructions; and

a processor configured to execute the instructions stored on the memory to perform operations comprising:

generating a specific virtualized human personality associated with a human user;

generating a generic virtualized human personality that is not associated with any human user;

receiving an initial cyberattack message from a source;

determining the initial cyberattack message is not targeted to any human user;

generating an initial response message using the generic virtualized human personality in response to determining the initial cyberattack message is not targeted to any human user;

sending the initial response message to the source;

receiving a cyberattack message from the source;

determining the cyberattack message is targeted to the human user;

generating a response message using the specific virtualized human personality associated with the human user to contain a company status associated with the human user in response to determining the cyberattack message is targeted to the human user; and

sending the response message to the source.

19 . The apparatus of claim 18 , wherein the processor is configured to execute the instructions stored on the memory to perform operations comprising:

determining the company status associated with the human user; and

generating the specific virtualized human personality associated with the human user based on the company status.

20 . The apparatus of claim 19 , wherein the processor is configured to execute the instructions stored on the memory to perform operations comprising determining the company status associated with the human user via publicly available information, a user input, or both.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: HANES, M. DAVID; HOLST, AMANDA L.; KATGERI, SUDHA; MONTENEGRO, ANA M; THANKI, ISHITA MAHESHKUMAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064404/0178 →
Continuity (1)
Related Publication 20250039235A1 · Jan 30, 2025
References Cited (28)
US 10381006B1 · Eriksson · 2019 [cited by examiner]
US 10645225B1 · Stoops · 2020 [cited by examiner]
US 11102244B1 · Jakobsson · 2021 [cited by examiner]
US 11481735B1 · Schemers · 2022 [cited by examiner]
US 11818172B1 · Miretsky · 2023 [cited by examiner]
US 20140259172A1 · Wang et al. · 2014 [cited by applicant]
US 20150326608A1 · Shabtai et al. · 2015 [cited by applicant]
US 20160036801A1 · Caldwell · 2016 [cited by examiner]
US 20160308897A1 · Chapman · 2016 [cited by examiner]
US 20190140986A1 · Anderson · 2019 [cited by examiner]
US 20200143247A1 · Jonnalagadda · 2020 [cited by examiner]
US 20200153763A1 · Baudart et al. · 2020 [cited by applicant]
US 20200252365A1 · Peltier · 2020 [cited by examiner]
US 20210240836A1 · Hazony · 2021 [cited by examiner]
US 20240144192A1 · Weissenberger · 2024 [cited by examiner]
US 20240428008A1 · Abraham · 2024 [cited by examiner]
US 20250315148A1 · Bennett · 2025 [cited by examiner]
Bres J.B., “ChatGPT and the Future of CyberSecurity”, Linkedin, Feb. 20, 2023, 10 pages. [cited by applicant]
Cambiaso E., et al., “Scamming the Scammers: Using ChatGPT to Reply Mails for Wasting Time and Resources”, arXiv:2303.13521v1 [cs.CR], Feb. 10, 2023, 10 pages. [cited by applicant]
Francis R., et al., “Honeypot Catches Social Engineering Scams on Social Media”, CSO Online, Mar. 7, 2017, 8 pages. [cited by applicant]
Gonzalez B., “How to Set up a Phishing Attack with the Social-Engineer Toolkit”, Infosec, Mar. 6, 2023, 7 pages. [cited by applicant]
Technology Solutions, “How can you use AI to Detect and Prevent Social Engineering Attacks?”, Linkedin, Apr. 27, 2023, 3 pages. [cited by applicant]
Kirchner J.A., et al., “New AI Classifier for Indicating AI-Written Text”, OpenAI, Jan. 31, 2023, 10 pages. [cited by applicant]
Maruccia A., et al., “Reliable Detection of AI-Generated Text is Impossible, a New Study Says”, Techspot, Mar. 22, 2023, 7 pages. [cited by applicant]
Mckee F., et al., “Chatbots in a Honeypot World”, arXiv, Jan. 9, 2023, 24 Pages. [cited by applicant]
Paradise A., et al., “Creation and Management of Social Network Honeypots for Detecting Targeted Cyber Attacks”, IEEE Transactions on Computational Social Systems, vol. 4, No. 3, Sep. 2017, pp. 65-79. [cited by applicant]
Sun C., et al., “Application of Artificial Intelligence Technology in Honeypot Technology”, 2021 International Conference on Advanced Computing and Endogenous Security, Apr. 2022, 9 Pages, DOI: 10.1109/IEEECONF52377.202… [cited by applicant]
Zakaria W.Z.A., et al., “A Review on Artificial Intelligence Techniques for Developing Intelligent Honeypot”, IEEE, Apr. 2012, pp. 696-701. [cited by applicant]