IP Library › Granted Patent US 10,686,836
Granted Patent B1
US 10,686,836 · App. 16/174,417 · Granted Jun 16, 2020

Host-based deception security technology

Inventor: Salvatore J Stolfo (New York, NY)
Assignee: Allure Security Technology Inc.
H04L63/1491H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,686,836
App. No.
16/174,417
Granted
Jun 16, 2020
Kind
B1
Abstract

Systems and methods for generating and deploying decoy files and decoy applications that appear to be authentic files and applications. The content of the decoy files may be configurable, and the decoy files may be beaconized. The extent to which decoy files are and decoy applications are deployed may depend on the authentication level or change in authentication level of a user.

Claims (35)

1. A method of operating a host-based security system comprising:

generating a set of decoy files from a first set of documents by, in each document of the set, replacing a first information with second information;

determining a first authentication level for a user;

displaying a first quantity of decoy files corresponding to the authentication level;

determining a second authentication level for the user; and

upon determining the second authentication level, displaying a second quantity of decoy files.

2. The method of claim 1 , wherein the first quantity of decoy files is zero and the second quantity of decoy files is greater than zero.

3. The method of claim 1 , wherein the first quantity of decoy files is greater than zero.

4. The method of claim 3 , wherein the second quantity of decoy files is greater than the first quantity of decoy files.

5. The method of claim 3 , wherein the second quantity of decoy files is less than the first quantity of decoy files.

6. The method of claim 3 , wherein the set of decoy files includes a decoy file having an embedded beacon.

7. The method of claim 1 , wherein the second authentication level is determined based on a failed login attempt by the user.

8. The method of claim 1 , wherein the second authentication level is determined based on a signal received from a host application.

9. A method of operating a host-based security system comprising:

generating a set of decoy files from a first set of documents, in each document of the set, embedding a beacon;

determining a first authentication level for a user;

displaying a first quantity of decoy files corresponding to the authentication level;

determining a second authentication level for the user; and

upon determining the second authentication level, displaying a second quantity of decoy files.

10. The method of claim 9 , wherein the first quantity of decoy files is zero and the second quantity of decoy files is greater than zero.

11. The method of claim 9 , wherein the first quantity of decoy files is greater than zero.

12. The method of claim 11 , wherein the second quantity of decoy files is greater than the first quantity of decoy files.

13. The method of claim 11 , wherein the second quantity of decoy files is less than the first quantity of decoy files.

14. The method of claim 9 , wherein the second authentication level is determined based on a failed login attempt by the user.

15. The method of claim 9 , wherein the second authentication level is determined based on a signal received from a host application.

16. A method of operating a host-based security system comprising:

generating a set of decoy files;

determining a first authentication level for a user;

displaying a first quantity of decoy files corresponding to the authentication level;

determining a second authentication level for the user; and

upon determining the second authentication level, displaying a second quantity of decoy files;

wherein the second quantity of decoy files is less than the first quantity of decoy files.

17. The method of claim 16 , wherein the set of decoy files includes a decoy file having an embedded beacon.

18. The method of claim 16 , wherein the second authentication level is determined based on a failed login attempt by the user.

19. The method of claim 16 , wherein the second authentication level is determined based on a signal received from a host application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: STOLFO, SALVATORE J.
To: ALLURE SECURITY TECHNOLOGY INC.
Reel/Frame 052560/0467 →
Continuity (1)
Provisional Application 62578898 · Oct 30, 2017
Cited By (3)
US 12,301,707 US 12,368,755 US 12,519,832