IP Library Granted Patent US 12,107,889
Granted Patent B2
US 12,107,889 · App. 17/571,460 · Granted Oct 1, 2024

Cloud-based deception technology utilizing zero trust to identify threat intelligence, telemetry, and emerging adversary tactics and techniques

Inventors: Bhavesh Kothari (Pune, IN); Sahir Hidayatullah (Mumbai, IN); Deepen Desai (San Ramon, CA); Akshay Shah (Bangalore, IN); Reshad Patuck (Mumbai, IN)
Assignee: Zscaler, Inc.
H04L63/1491H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,107,889
App. No.
17/571,460
Granted
Oct 1, 2024
Kind
B2
Abstract

Cloud-based deception systems and methods with zero trust include hosting a decoy cloud environment for a customer that contains a plurality of decoys and that is hosted and separated from a real environment of the customer; receiving traffic from a user associated with the customer; detecting the traffic is related to accessing a fake asset on a user device associated with the user; rerouting the traffic to the decoy cloud environment; and monitoring activity associated with the fake asset in the decoy cloud environment.

Claims (37)

1. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming one or more processors to perform steps of:

hosting a decoy cloud environment for a customer that contains a plurality of decoys and that is hosted and separated from a real environment of the customer, wherein the plurality of decoys are associated with a plurality of fake assets planted on one or more user devices associated with the customer;

receiving traffic from a user associated with the customer via inline monitoring for traffic inspection;

detecting whether the traffic is related to accessing a fake asset on a user device associated with the user or the traffic is unrelated to any fake asset on the user device;

responsive to the traffic being related to accessing the fake asset, rerouting the traffic to the decoy cloud environment as part of the inline monitoring, and monitoring activity associated with the fake asset in the decoy cloud environment, wherein the routing is performed based on deception policies created based on real user access policy; and

responsive to the traffic being unrelated to any fake asset, processing the traffic for threat protection and data protection and either allowing or blocking the unrelated traffic based thereon.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the inline monitoring is performed in a cloud service separate from the real environment of the customer and the user device.

3. The non-transitory computer-readable storage medium of claim 1 , wherein the processing includes one of allowing the unrelated traffic, blocking the unrelated traffic, cleaning the unrelated traffic, threat detecting the unrelated traffic, sandboxing the unrelated traffic, and enriching detection in the cloud-based system based on the detecting.

4. The non-transitory computer-readable storage medium of claim 1 , wherein the fake assets include any of deceptive assets, files, breadcrumbs, lures, bait, network traffic, passwords, keys, session information, and cookies.

5. The non-transitory computer-readable storage medium of claim 1 , wherein the fake assets are generated and planted on the user device based on a role of the user associated with the user device as determined based on historical monitoring of the user.

6. The non-transitory computer-readable storage medium of claim 1 , wherein the steps include:

determining an indication of compromise for the user and/or the user device and providing a notification based thereon.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the rerouting is based on a set of policies that include traffic profile, time of day, and user activity.

8. The non-transitory computer-readable storage medium of claim 1 , wherein the decoy cloud is part of a cloud-based system configured to perform the inline monitoring and includes a connector configured to dial out only and reject inbound connections.

9. A method comprising steps of:

hosting a decoy cloud environment for a customer that contains a plurality of decoys and that is hosted and separated from a real environment of the customer, wherein the plurality of decoys are associated with a plurality of fake assets planted on one or more user devices associated with the customer;

receiving traffic from a user associated with the customer via inline monitoring for traffic inspection;

detecting whether the traffic is related to accessing a fake asset on a user device associated with the user or the traffic is unrelated to any fake asset on the user device;

responsive to the traffic being related to accessing the fake asset, rerouting the traffic to the decoy cloud environment as part of the inline monitoring, and monitoring activity associated with the fake asset in the decoy cloud environment, wherein the routing is performed based on deception policies created based on real user access policy; and

responsive to the traffic being unrelated to any fake asset, processing the traffic for threat protection and data protection and either allowing or blocking the unrelated traffic based thereon.

10. The method of claim 9 , wherein the inline monitoring is performed in a cloud service separate from the real environment of the customer and the user device.

11. The method of claim 9 , wherein the processing includes one of allowing the unrelated traffic, blocking the unrelated traffic, cleaning the unrelated traffic, threat detecting the unrelated traffic, sandboxing the unrelated traffic, and enriching detection in the cloud-based system based on the detecting.

12. The method of claim 9 , wherein the fake assets include any of deceptive assets, files, breadcrumbs, lures, bait, network traffic, passwords, keys, session information, and cookies.

13. The method of claim 9 , wherein the fake assets are generated and planted on the user device based on a role of the user associated with the user device as determined based on historical monitoring of the user.

14. The method of claim 9 , wherein the steps include

determining an indication of compromise for the user and/or the user device and providing a notification based thereon.

15. The method of claim 9 , wherein the rerouting is based on a set of policies that include traffic profile, time of day, and user activity.

16. The method of claim 9 , wherein the decoy cloud is part of a cloud-based system configured to perform the inline monitoring and includes a connector configured to dial out only and reject inbound connections.

17. A cloud-based system comprising a plurality of nodes, each including one or more processors configured to:

host a decoy cloud environment for a customer that contains a plurality of decoys and that is hosted and separated from a real environment of the customer, wherein the plurality of decoys are associated with a plurality of fake assets planted on one or more user devices associated with the customer;

receive traffic from a user associated with the customer via inline monitoring for traffic inspection;

detect whether the traffic is related to accessing a fake asset on a user device associated with the user or the traffic is unrelated to any fake asset on the user device;

responsive to the traffic being related to accessing the fake asset, reroute the traffic to the decoy cloud environment as part of the inline monitoring, and monitor activity associated with the fake asset in the decoy cloud environment, wherein the rerouting is performed based on deception policies created based on real user access policy; and

responsive to the traffic being unrelated to any fake asset, process the traffic for threat protection and data protection and either allowing or blocking the unrelated traffic based thereon.

18. The cloud-based system of claim 17 , wherein the fake assets include any of deceptive assets, files, breadcrumbs, lures, bait, network traffic, passwords, keys, session information, and cookies.

19. The cloud-based system of claim 17 , wherein the fake assets are generated and planted on the user device based on a role of the user associated with the user device as determined based on historical monitoring of the user.

20. The cloud-based system of claim 17 , wherein the decoy cloud is part of the cloud-based system configured to perform the inline monitoring and includes a connector configured to dial out only and reject inbound connections.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2022
From: KOTHARI, BHAVESH; HIDAYATULLAH, SAHIR; DESAI, DEEPEN; SHAH, AKSHAY; PATUCK, RESHAD
To: ZSCALER, INC.
Reel/Frame 058590/0894 →
Priority Claims (1)
IN 202111053875 · Nov 23, 2021 · national
Continuity (1)
Related Publication 20230164182A1 · May 25, 2023
Cited By (3)
US 12,585,767 US 12,613,961 US 12,712,854