IP Library › Granted Patent US 11,689,569
Granted Patent B2
US 11,689,569 · App. 17/352,251 · Granted Jun 27, 2023

Methods and systems for honeyfile creation, deployment and management

Inventors: Ben Whitham (Campbell, AU); David Liebowitz (Bruce, AU)
Assignee: Penten Pty Ltd
H04L63/1491G06F21/565G06F21/566G06F21/6218G06F2221/034G06Q10/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,569
App. No.
17/352,251
Filed
Jun 18, 2021
Granted
Jun 27, 2023
Kind
B2
Art Unit
2491
USPC
726/23
Abstract

A method for automatically creating a honeyfile for a file system, includes the steps of: surveying a file set of the file system to identify tokenisable data in the file set, tokenising the identified tokenisable data to form a plurality of token sequences, and either selecting one of the plurality of token sequences or generating a token sequence to operate as an exemplar token sequence; applying a substitution method to substitute the tokens of the exemplar token sequence with replacement tokenisable data; and packaging the replacement tokenisable data into a honeyfile.

Claims (33)

1. A method for automatically creating a honeyfile for a file system, including the steps of:

surveying a file set of the file system to identify metadata in the file set;

extracting the file set metadata;

analyzing the file set metadata to resolve one or more parameters of metadata applicable to the file set;

generating honeyfile metadata based on the resolved parameters; and

packaging the honeyfile metadata into a honeyfile, wherein a frequency of extracted metadata parameters is calculated, and incidence is normalized to create occurrence probabilities.

2. The method according to claim 1 , wherein the honeyfile metadata occurs with substantially the same relative frequency as the extracted metadata.

3. The method according to claim 1 , wherein generating honeyfile data includes creating a distribution of metadata parameter information and sampling proportional to probability.

4. The method according to claim 1 , wherein the honeyfile has a lifecycle term based on in part of one or more metadata or parameters.

5. The method according to claim 1 , wherein the extracted metadata is extracted using a sampling-based approach from the surveyed set of files.

6. The method according to claim 1 , wherein a metadata parameter is timestamp-based.

7. The method according to claim 6 , wherein timestamp-based metadata includes hour, minute, second and/or date information.

8. The method according to claim 1 , wherein a metadata parameter is a user or group identifier.

9. The method according to claim 1 , wherein a metadata parameter is ownership and permissions based.

10. The method according to claim 1 , wherein a metadata parameter is user identification and/or permission based.

11. A method for automatically creating a honeyfile for a file system, including the steps of:

surveying a file set of a file system to identify one or more metadata in the file set;

extracting the one or more metadata from the file set;

storing the one or more metadata from the file set

analyzing the file set metadata to identify one or more parameters of metadata applicable to the file set;

generating honeyfile metadata based on the one or more identified parameters;

associating the honeyfile metadata into a honeyfile;

evaluating the validity of the generated honeyfile metadata; and

replacing the one or more identified parameters with the generated honeyfile metadata, wherein generating honeyfile data includes creating a distribution of metadata parameter information and sampling proportional to probability.

12. The method according to claim 11 , wherein a frequency of extracted metadata parameters is calculated, and incidence is normalized to create occurrence probabilities.

13. The method according to claim 12 , wherein the honeyfile metadata occurs with substantially the same relative frequency as the extracted metadata.

14. The method according to claim 11 , wherein the honeyfile has a lifecycle term based on in part of one or more metadata or parameters.

15. The method according to claim 11 , wherein the extracted metadata is extracted using a sampling-based approach from the surveyed set of files.

16. The method according to claim 11 , wherein a metadata parameter is timestamp-based.

17. The method according to claim 16 , wherein timestamp-based metadata includes hour, minute, second and/or date information.

18. The method according to claim 11 , wherein a metadata parameter is a user or group identifier.

19. The method according to claim 11 , wherein a metadata parameter is ownership and permissions based.

20. The method according to claim 11 , wherein a metadata parameter is user identification and/or permission based.

Priority Claims (1)
AU 2018247212 · Oct 9, 2018 · national
Continuity (2)
Continuation 16596139 · Oct 8, 2019
Related Publication 20210314356A1 · Oct 7, 2021