IP Library Patent Application 18361835
Patent Application
App. No. 18/361,835

NETWORK ACTION CLASSIFICATION AND ANALYSIS USING WIDELY DISTRIBUTED HONEYPOT SENSOR NODES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/361,835
Abstract

A system and methods for network action classification and analysis using widely distributed lightweight honeypot sensor nodes, comprising a plurality of network traffic sensors each configured to monitor visible network traffic, analyze monitored traffic to identify patterns, communicate with other network sensors to correlate their respective traffic data, and produce a threat landscape based on the correlated traffic data. The system and method may comprise an emulation engine configured to simulate limited services or functionalities, emulating vulnerabilities or weak points in systems. Emulation engine may comprise one or more modules configured to provide use-case specific emulation capabilities. Emulation engine may receive network traffic data from network sensors, route the network traffic to an appropriate simulated destination service associated with the network traffic, and monitor the interactions between an attacker and the simulated destination. Logged interactions may be used as an input to generate the threat landscape.

Claims (57)

1 . A system for deception-based cybersecurity using distributed sensor nodes, comprising:

a plurality of network traffic sensors each comprising a plurality of programming instructions stored in a memory of, and operating on a processor of, a respective computing device, wherein each plurality of programmable instructions, when operating on the processor, cause the respective computing device to:

monitor visible network traffic;

analyze the traffic to identify a plurality of patterns, wherein the analysis comprises analysis of a plurality of network interactions, commands executed, and attempted exploits;

communicate with at least one other of the plurality of network traffic sensors to correlate the identified plurality of patterns with the respective identified patterns of the at least one other network traffic sensor;

produce a threat landscape, wherein the threat landscape comprises a plurality of identified traffic patterns;

identify a plurality of potential cybersecurity threats based on the threat landscape; and

export the analyzed traffic data and the threat landscape for use by external systems.

2 . The system of claim 1 , further comprising a network module comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the respective computing device, wherein the second plurality of programmable instructions, when operating on the processor, cause the respective computing device to:

receive the traffic, the traffic being associated with a network service;

analyze the traffic to determine a destination network service associated with the traffic;

emulate the destination network service and forward the traffic to the emulated destination network service; and

monitor and log the network interactions.

3 . The system of claim 1 , further comprising a web module comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the respective computing device, wherein the third plurality of programmable instructions, when operating on the processor, cause the respective computing device to:

receive the traffic, the traffic being associated with a web service;

analyze the traffic to determine a destination web service associated with the traffic;

emulate the destination web service and forward the traffic to the emulated destination web service; and

monitor and log web interaction data.

4 . The system of claim 1 , further comprising an internet-of-things module comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the respective computing device, wherein the fourth plurality of programmable instructions, when operating on the processor, cause the respective computing device to:

connect to an Internet-of-Things (IoT) device;

determine an IoT protocol or service associated with the IoT device;

emulate the IoT protocol or service; and

monitor and log commands executed and exploits attempted within the emulation.

5 . The system of claim 1 , further comprising a vulnerability module comprising a fifth plurality of programming instructions stored in the memory of, and operating on the processor of, the respective computing device, wherein the fifth plurality of programmable instructions, when operating on the processor, cause the respective computing device to:

simulate a known vulnerability or weakness to attract an attacker;

receive the traffic, the traffic being associated with the attacker; and

monitor and log commands executed exploits attempted by the attacker as the attacker interacts with simulated vulnerability or weakness.

6 . The system of claim 1 , wherein the plurality of network interactions, commands executed, and attempted exploits are received from an emulation engine, the emulation engine comprising one or more modules configured to operate as a lightweight honeypot.

7 . The system of claim 6 , wherein the plurality of network interactions, commands executed, and attempted exploits are logged during monitored interactions between an attacker and an emulated service or emulated application.

8 . A method for deception-based cybersecurity using distributed sensor nodes, comprising the steps of:

monitoring, at a network traffic sensor, visible network traffic;

analyzing the traffic to identify a plurality of patterns, wherein the analysis comprises analysis of a plurality of network interactions, commands executed, and attempted exploits;

communicating with at least one other of the plurality of network traffic sensors to correlate the identified plurality of patterns with the respective identified patterns of the at least one other network traffic sensor;

producing a threat landscape, wherein the threat landscape comprises a plurality of identified traffic patterns;

identifying a plurality of potential cybersecurity threats based on the threat landscape; and

exporting the analyzed traffic data and the threat landscape for use by external systems.

9 . The method of claim 8 , further comprising the steps of:

receiving, at a network module operating on the network traffic sensor, the traffic, the traffic being associated with a network service;

analyzing the traffic to determine a destination network service associated with the traffic;

emulating the destination network service and forwarding the traffic to the emulated destination network service; and

monitoring and logging the network interactions.

10 . The method of claim 8 , further comprising the steps of:

receiving, at a web module operating on the network traffic sensor, the traffic, the traffic being associated with a web service;

analyzing the traffic to determine a destination web service associated with the traffic;

emulating the destination web service and forwarding the traffic to the emulated destination web service; and

monitoring and logging web interaction data.

11 . The method of claim 8 , further comprising the steps of:

connecting, using an Internet-of-Things (IoT) module operating on the network traffic sensor, to an IoT device;

determining an IoT protocol or service associated with the IoT device;

emulating the IoT protocol or service; and

monitoring and logging commands executed and exploits attempted within the emulation.

12 . The method of claim 8 , further comprising the steps of:

simulating, using a vulnerability module operating on the network traffic sensor, a known vulnerability or weakness to attract an attacker;

receiving the traffic, the traffic being associated with the attacker; and

monitoring and logging commands executed and exploits attempted by the attacker as the attacker interacts with simulated vulnerability or weakness.

13 . The method of claim 8 , wherein the plurality of network interactions, commands executed, and attempted exploits are received from an emulation engine, the emulation engine comprising one or more modules configured to operate as a lightweight honeypot.

14 . The method of claim 13 , wherein the plurality of network interactions, commands executed, and attempted exploits are logged during monitored interactions between an attacker and an emulated service or emulated application.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE SECOND INVENTOR LAST NAME PREVIOUSLY RECORDED AT REEL: 64428 FRAME: 867. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 19, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 066762/0087 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064428/0866 →