IP Library › Granted Patent US 11,831,420
Granted Patent B2
US 11,831,420 · App. 16/848,012 · Granted Nov 28, 2023

Network application firewall

Inventors: Michael Kapelevich (Raanana, IL); Maxim Zavodchik (Kfar Yona, IL); Tomer Zait (Tel Aviv, IL); Ido Breger (Tel Aviv, IL)
Assignee: F5, Inc.
H04L63/1491H04L63/0218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,831,420
App. No.
16/848,012
Filed
Apr 14, 2020
Granted
Nov 28, 2023
Kind
B2
Examiner
NIPA, WASIKA
Art Unit
2433
USPC
726/11
Abstract

Technology related to a network application firewall is disclosed. In one example, a method includes intercepting a response from a network application and destined for a client. The response can be associated with a user identifier. A modified response can be forwarded to the client. The modified response can include a honeytrap embedded within the intercepted response. Engagement with the honeytrap can be detected in a subsequent request to the network application. In response to detecting the engagement with the honeytrap, an indication that the user identifier is malicious can be stored.

Claims (48)

1. A method implemented by a network traffic management system comprising one or more network traffic management apparatuses, server devices, or client devices, the method comprising:

intercepting a response from a network application and destined for a client, the response sent in response to a request associated with a user identifier;

determining that the user identifier associated with the request is a suspicious or malicious user identifier;

based on the determining, forwarding a modified response to the client, the modified response comprising a honeytrap embedded within the intercepted response, wherein the honeytrap comprises a deceptive payload inserted into the intercepted response that appears useful to an attacker when at least part of the deceptive payload is modified during an attack of the network application;

detecting engagement with the honeytrap in a subsequent request to the network application, wherein the detecting comprises detecting a modifying of at least part of the deceptive payload in the subsequent request; and

in response to detecting the engagement with the honeytrap, storing an indication that the user identifier is malicious.

2. The method of claim 1 , further comprising:

determining an attack type of the subsequent request; and

sending a deceptive response to the subsequent request, the deceptive response formatted consistently with the attack type of the subsequent request.

3. The method of claim 1 , wherein the honeytrap is selected from a plurality of honeytraps, and the plurality of honeytraps are dynamically updateable.

4. The method of claim 1 , wherein the honeytrap comprises a false uniform resource identifier (URI), and the engagement with the honeytrap in the subsequent request is a request to access the false URI.

5. The method of claim 1 , wherein the honeytrap comprises a false credential, and the engagement with the honeytrap in the subsequent request further comprises a request to access a resource using the false credential.

6. The method of claim 1 , wherein the response is modified in response to detecting the user identifier associated with the request is suspicious based on a behavioral analysis of a plurality of requests from the user identifier.

7. A system comprising one or more network application firewall modules, networking modules, or server modules, memory comprising programmed instructions stored thereon, and one or more processors configured to be capable of executing the stored programmed instructions to:

intercept a response from a network application and destined for a client, the response sent in response to a request associated with a user identifier;

determine that the user identifier associated with the request is a suspicious or malicious user identifier;

based on the determination, forward a modified response to the client, the modified response comprising a honeytrap embedded within the intercepted response, wherein the honeytrap comprises a deceptive payload inserted into the intercepted response that appears useful to an attacker when the deceptive payload is modified during an attack of the network application;

detect engagement with the honeytrap in a subsequent request to the network application, wherein the detecting comprises detecting a modified version of the deceptive payload in the subsequent request; and

in response to detecting the engagement with the honeytrap, store an indication that the user identifier is malicious.

8. The system of claim 7 , wherein the one or more processors are further configured to be capable of executing the stored programmed instructions to:

determine an attack type of the subsequent request; and

send a deceptive response to the subsequent request, the deceptive response formatted consistently with the attack type of the subsequent request.

9. The system of claim 7 , wherein the honeytrap comprises a false uniform resource identifier (URI), and the engagement with the honeytrap in the subsequent request is a request to access the false URI.

10. The system of claim 7 , wherein the honeytrap comprises a false credential, and the engagement with the honeytrap in the subsequent request further comprises a request to access a resource using the false credential.

11. The system of claim 7 , wherein the response is modified in response to detecting the user identifier associated with the request is suspicious based on a behavioral analysis of a plurality of requests from the user identifier.

12. A non-transitory computer readable medium having stored thereon instructions comprising executable code that, when executed by one or more processors, causes the one or more processors to:

intercept a response from a network application and destined for a client, the response sent in response to a request associated with a user identifier;

determine that the user identifier associated with the request is a suspicious or malicious user identifier;

based on the determination, forward a modified response to the client, the modified response comprising a honeytrap embedded within the intercepted response, wherein the honeytrap comprises a deceptive payload inserted into the intercepted response that appears useful to an attacker when the deceptive payload is modified during an attack of the network application;

detect engagement with the honeytrap in a subsequent request to the network application, wherein the detecting comprises detecting a modified version of the deceptive payload in the subsequent request; and

in response to detecting the engagement with the honeytrap, store an indication that the user identifier is malicious.

13. The computer readable medium of claim 12 , wherein the instructions further comprise executable code that, when executed by the one or more processors, causes the one or more processors to:

determine an attack type of the subsequent request; and

send a deceptive response to the subsequent request, the deceptive response formatted consistently with the attack type of the subsequent request.

14. The computer readable medium of claim 12 , wherein the honeytrap comprises a false uniform resource identifier (URI), and the engagement with the honeytrap in the subsequent request is a request to access the false URI.

15. The computer readable medium of claim 12 , wherein the honeytrap comprises a false credential, and the engagement with the honeytrap in the subsequent request further comprises a request to access a resource using the false credential.

16. The computer readable medium of claim 12 , wherein the response is modified in response to detecting the user identifier associated with the request is suspicious based on a behavioral analysis of a plurality of requests from the user identifier.

17. A network traffic management apparatus, comprising memory comprising programmed instructions stored thereon and one or more processors configured to be capable of executing the stored programmed instructions to:

intercept a response from a network application and destined for a client, the response sent in response to a request associated with a user identifier;

determine that the user identifier associated with the request is a suspicious or malicious user identifier;

based on the determination, forward a modified response to the client, the modified response comprising a honeytrap embedded within the intercepted response, wherein the honeytrap comprises a deceptive payload inserted into the intercepted response that appears useful to an attacker when the deceptive payload is modified during an attack of the network application;

detect engagement with the honeytrap in a subsequent request to the network application, wherein the detecting comprises detecting a modified version of the deceptive payload in the subsequent request; and

in response to detecting the engagement with the honeytrap, store an indication that the user identifier is malicious.

18. The network traffic management apparatus of claim 17 , wherein the programmed instructions stored thereon and one or more processors are further configured to be capable of executing the stored programmed instructions to:

determine an attack type of the subsequent request; and

send a deceptive response to the subsequent request, the deceptive response formatted consistently with the attack type of the subsequent request.

19. The network traffic management apparatus of claim 17 , wherein the honeytrap comprises a false uniform resource identifier (URI), and the engagement with the honeytrap in the subsequent request further comprises a request to access the false URI.

20. The network traffic management apparatus of claim 17 , wherein the response is modified in response to detecting the user identifier associated with the request is suspicious based on a behavioral analysis of a plurality of requests from the user identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2020
From: KAPELEVICH, MICHAEL; ZAVODCHIK, MAXIM; ZAIT, TOMER; BREGER, IDO
To: F5 NETWORKS, INC.
Reel/Frame 053759/0143 →
Continuity (2)
Provisional Application 62936990 · Nov 18, 2019
Related Publication 20210152598A1 · May 20, 2021
Cited By (5)
US 12,470,582 US 12,470,583 US 12,470,584 US 12,476,939 US 12,568,105