IP Library › Granted Patent US 11,916,959
Granted Patent B2
US 11,916,959 · App. 17/645,530 · Granted Feb 27, 2024

Systems and methods for building a honeypot system

Inventors: Yaroslav A. Shmelev (Moscow, RU); Demeter Dan (Moscow, RU); Preuss Marco (Moscow, RU); Mikhail Y. Kuzin (Moscow, RU)
Assignee: AO Kaspersky Lab
H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,959
App. No.
17/645,530
Granted
Feb 27, 2024
Kind
B2
Abstract

Systems and methods for building systems of honeypot resources for the detection of malicious objects in network traffic. A system includes at least two gathering tools for gathering data about the computer system on which it is installed, a building tool configured for building at least two virtual environments, each including an emulation tool configured for emulating the operation of the computer system in the virtual environment, and a distribution tool configured for selecting at least one virtual environment for each computer system and for establishing connection between the computer system and the virtual environment.

Claims (76)

1. A system for building a honeypot environment, the system comprising:

a first computing device including a first gathering tool, the first gathering tool configured to collect data about the first computing device;

a second computing device including a second gathering tool, the second gathering tool configured to collect data about the second computing device, wherein the second computing device is independent of the first computing device;

a building tool configured to:

build a plurality of virtual environments, wherein each virtual environment includes an emulator configured to emulate at least one of the first computing device or the second computing device based on the data collected about the first computing device or the data collected about the second computing device, and

transfer data about the built plurality of virtual environments to a distribution tool; the distribution tool configured to:

select at least one of the plurality of virtual environments for association with the first computing device based on data about the plurality of virtual environments,

select at least one of the plurality of virtual environments for association with the second computing device based on data about the plurality of virtual environments, and

establish connections between the computing devices and the respective virtual environments associated with the computing devices.

2. The system of claim 1 , wherein the building tool is configured to establish connections between the computing devices and the respective virtual environments associated with the computing devices including by:

establishing a connection between the first computing device and the at least one virtual environment associated with the first computing device, wherein the connection facilitates transfer of additional information collected from the first gathering tool to the emulator included in the at least one virtual environment associated with the first computing device; and

establishing a connection between the second computing device and the at least one virtual environment associated with the second computing device, wherein the connection facilitates transfer of additional information collected from the second gathering tool to the emulator included in the at least one virtual environment associated with the second computing device.

3. The system of claim 2 , wherein the distribution tool is further configured to:

after the connection between the first computing device and the at least one virtual environment associated with the first computing device is established, further emulate the first computing device using the additional information using the emulator of the at least one virtual environment associated with the first computing device.

4. The system of claim 1 , wherein the emulator configured to emulate the first computing device emulates at least one of:

substantially similar software functionality as the first computing device;

substantially similar computing resources as the first computing device;

a speed of data transfer between the first computing device and the at least one virtual environment associated with the first computing device exceeding a speed threshold;

operation on a same network as the first computing device; or

a predefined set of vulnerabilities.

5. The system of claim 1 , wherein the distribution tool is further configured to select the at least one of the plurality of virtual environments for association with the first computing device according to:

a usage of computing resources of the at least one of the plurality of virtual environments being below a usage threshold; and

a speed of data transfer between the first computing device and the at least one of the plurality of virtual environments being above a speed threshold.

6. The system of claim 1 , wherein the building tool is further configured to train a distribution model, and wherein the distribution tool is further configured to select the at least one of the plurality of virtual environments for association with the first computing device based on the distribution model.

7. The system of claim 1 , further comprising:

a network control tool configured to intercept network traffic related to the first computing device,

wherein the building tool is further configured to emulate the first computing device based on the intercepted network traffic.

8. The system of claim 7 , wherein the first gathering tool is configured to collect the data about the first computing device prior to the network control tool intercepting network traffic or after the network control tool has completed intercepting network traffic.

9. The system of claim 1 , wherein the building tool is further configured to build a first virtual environment of the plurality of virtual environments and a second virtual environment of the plurality of virtual environments such that computing resources used by the combination of the first virtual environment and the second virtual environment do not exceed a threshold of allocated computing resources.

10. The system of claim 1 , wherein the distribution tool is configured to select the at least one of the plurality of virtual environments for association with the first computing device according to at least one of:

a rate of detection of malicious objects in the at least one associated virtual environment is above a rate detection threshold;

a time for transfer between the first computing device and the at least associated virtual environment is below a transfer threshold; or

a load on the at least associated virtual environment is below a load threshold.

11. A method for building a honeypot environment, the method comprising:

collecting data about a computing system, wherein the computing system includes a gathering tool configured to collect data about the computing system;

selecting at least one of a plurality of pre-built virtual environments for association with the computing system based on the data collected about the computing system, each of the pre-built virtual environments including an emulator configured to emulate the computing system;

intercepting network traffic of the computing system;

emulating the computer system in the selected at least one of the plurality of pre-built virtual environments using the emulator; and

detecting at least one malicious object from the intercepted network traffic based on the emulating.

12. The method of claim 11 , further comprising:

establishing a connection between the computing system and the at least one of the plurality of pre-built virtual environments associated with the computing system;

collecting additional data about the computing system; and

transferring the additional information to the emulator for the emulating of the computer system.

13. The method of claim 11 , wherein selecting at least one of a plurality of pre-built virtual environments for association with the computing system is based on:

a usage of computing resources of the at least one of the plurality of pre-built virtual environments being below a usage threshold; and

a speed of data transfer between the computing system and the at least one of the plurality of pre-built virtual environments being above a speed threshold.

14. The method of claim 11 , further comprising:

training a distribution model, wherein the distribution tool is further configured to select the at least one of the plurality of pre-built virtual environments for association with computing system based on the distribution model.

15. The method of claim 11 , wherein selecting at least one of a plurality of pre-built virtual environments for association with the computing system is based on at least one of:

a rate of detection of malicious objects in the at least one associated virtual environment is above a rate detection threshold;

a time for transfer between the first computing device and the at least associated virtual environment is below a transfer threshold; or

a load on the at least associated virtual environment is below a load threshold.

16. The method of claim 11 , wherein the collecting data and the selecting the at least one of the plurality of pre-built virtual environments are performed at least one of:

before the intercepting of network traffic of the computing system;

during loading of an operating system of the computing system;

during launch of an application of the computing system;

during the intercepting of network traffic of the computing system; or

after the intercepting of network traffic of the computing system.

17. A system for building a honeypot environment, the system comprising:

a virtual environments database configured to store a plurality of previously-built virtual environments;

a distribution model including a plurality of characteristics selected by at least one machine learning method;

computing hardware of at least one processor and a memory operably coupled to the at least one processor; and

instructions that, when executing on the computing hardware, cause the computing hardware to implement:

a building tool configured to:

build a plurality of virtual environments, wherein each virtual environment includes an emulator configured to emulate at least one computing system, and

train the distribution model based on the plurality of previously-built virtual environments, and

a distribution tool configured to select at least one of the plurality of virtual environments for association with a respective computing system based on the distribution model.

18. The system of claim 17 , wherein the instructions that, when executing on the computing hardware, cause the computing hardware to further implement:

a gathering tool configured to collect data about the respective computing system,

wherein the emulator of the at least one of the plurality of virtual environments associated with the respective computing system is configured to emulate the respective computing system.

19. The system of claim 18 , wherein the building tool is further configured to retrain the distribution model based on a result of an analysis tool configured to detect a malicious object in the emulator of the at least one of the plurality of virtual environments associated with the respective computing system.

20. The system of claim 17 , wherein the plurality of previously-built virtual environments were previously built by the building tool to detect a malicious object in previous network traffic.

21. The system of claim 17 , wherein the distribution tool is configured to select the at least one of the plurality of virtual environments for association with a respective computing system according to at least one of:

a rate of detection of malicious objects in the at least one associated virtual environment is above a rate detection threshold;

a time for transfer between the respective computing system and the at least associated virtual environment is below a transfer threshold; or

a load on the at least associated virtual environment is below a load threshold.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2022
From: SHMELEV, YAROSLAV A.; DAN, DEMETER; MARCO, PREUSS; KUZIN, MIKHAIL Y.
To: AO KASPERSKY LAB
Reel/Frame 061769/0001 →
Priority Claims (1)
RU RU2021106663 · Mar 15, 2021 · national
Continuity (1)
Related Publication 20220294822A1 · Sep 15, 2022