IP Library › Granted Patent US 12,199,993
Granted Patent B2
US 12,199,993 · App. 17/808,554 · Granted Jan 14, 2025

Highly collaborative deceptive network alliance

Inventors: Doga Tav (Fredericton, CA); Russell Couturier (Worcester, MA); Ronald Williams (Austin, TX); Jeb R. Linton (Manassas, VA)
Assignee: International Business Machines Corporation
H04L63/1416H04L63/1425H04L63/145H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,993
App. No.
17/808,554
Filed
Jun 24, 2022
Granted
Jan 14, 2025
Kind
B2
Art Unit
2441
USPC
726/22
Abstract

According to one embodiment, a method, computer system, and computer program product for preventing intrusions on a network is provided. The present invention may include generating a sandbox environment responsive to detecting an attacker in the network, wherein the sandbox environment comprises dynamically generated data tailored to the target of the attacker; and moving the attacker to the sandbox environment.

Claims (43)

1. A processor-implemented method for preventing intrusions on a network, the method comprising:

responsive to detecting an attacker in the network, identifying a target file of the attacker;

identifying content factors of the identified file including the title, size, and file format;

dynamically generating, using Markov chains or a generative adversarial network (GAN), one or more decoy files comprising a plurality of text content based on a text content comprising the target file, and wherein the content factors of the one or more decoy files match the content factors of the target file;

generating a sandbox environment comprising the one or more decoy files; and

moving the attacker to the sandbox environment.

2. The method of claim 1 , wherein the sandbox environment further comprises one or more decoy individuals.

3. The method of claim 1 , further comprising:

predicting an intrusion to the network based on activity of the attacker within the sandbox environment.

4. The method of claim 3 , further comprising:

performing a mitigation action based on the predicted intrusion.

5. The method of claim 1 , wherein the plurality of text content is modified to align a probability distribution of the plurality of text content with human-written language.

6. The method of claim 1 , wherein the network further comprises one or more decoy individuals.

7. The method of claim 1 , wherein the sandbox environment further comprises a dynamically generated username and home directory structure.

8. A computer system for preventing intrusions on a network, the computer system comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

responsive to detecting an attacker in the network, identifying a target file of the attacker;

identifying content factors of the identified file including the title, size, and file format;

dynamically creating one or more decoy files comprising a plurality of text content based on a text content comprising the target file, and wherein the content factors of the one or more decoy files match the content factors of the target file;

generating a sandbox environment comprising the one or more decoy files; and

moving the attacker to the sandbox environment.

9. The computer system of claim 8 , wherein the sandbox environment further comprises one or more decoy individuals.

10. The computer system of claim 8 , further comprising:

predicting an intrusion to the network based on activity of the attacker within the sandbox environment.

11. The computer system of claim 10 , further comprising:

performing a mitigation action based on the predicted intrusion.

12. The computer system of claim 8 , wherein the plurality of text content is modified to align a probability distribution of the plurality of text content with human-written language.

13. The computer system of claim 8 , wherein the network further comprises one or more decoy individuals.

14. The computer system of claim 8 , wherein the sandbox environment further comprises a dynamically generated username and home directory structure.

15. A computer program product for preventing intrusions on a network, the computer program product comprising:

one or more computer-readable tangible storage medium and program instructions stored on at least one of the one or more tangible storage medium, the program instructions executable by a processor to cause the processor to perform a method comprising:

responsive to detecting an attacker in the network, identifying a target file of the attacker;

identifying content factors of the identified file including the title, size, and file format;

dynamically creating one or more decoy files comprising a plurality of text content based on a text content comprising the target file, and wherein the content factors of the one or more decoy files match the content factors of the target file;

generating a sandbox environment comprising the one or more decoy files; and

moving the attacker to the sandbox environment.

16. The computer program product of claim 15 , wherein the sandbox environment further comprises one or more decoy individuals.

17. The computer program product of claim 15 , further comprising:

predicting an intrusion to the network based on activity of the attacker within the sandbox environment.

18. The computer program product of claim 17 , further comprising:

performing a mitigation action based on the predicted intrusion.

19. The computer program product of claim 15 , wherein the plurality of text content is modified to align a probability distribution of the plurality of text content with human-written language.

20. The computer program product of claim 15 , wherein the network further comprises one or more decoy individuals.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2022
From: TAV, DOGA; COUTURIER, RUSSELL; WILLIAMS, RONALD; LINTON, JEB R.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 060298/0569 →
Continuity (1)
Related Publication 20230421576A1 · Dec 28, 2023
References Cited (35)
US 9292493B2 · Chandramouli · 2016 [cited by applicant]
US 9392001B2 · Wang · 2016 [cited by applicant]
US 9535731B2 · Ashley · 2017 [cited by applicant]
US 9838427B2 · Quinlan · 2017 [cited by applicant]
US 9860208B1 · Ettema · 2018 [cited by applicant]
US 9985988B2 · Gukal · 2018 [cited by applicant]
US 10193924B2 · Wu · 2019 [cited by applicant]
US 10270807B2 · Sysman · 2019 [cited by applicant]
US 10333977B1 · Shamul · 2019 [cited by applicant]
US 10348763B2 · Gopalakrishna · 2019 [cited by applicant]
US 10375110B2 · Vissamsetty · 2019 [cited by applicant]
US 10432665B1 · Yohai · 2019 [cited by applicant]
US 10601868B2 · Wilcox · 2020 [cited by applicant]
US 11057429B1 · Sellers · 2021 [cited by applicant]
US 20020066034A1 · Schlossberg · 2002 [cited by applicant]
US 20160149950A1 · Ashley · 2016 [cited by examiner]
US 20190068641A1 · Araujo · 2019 [cited by examiner]
US 20200106808A1 · Schütz · 2020 [cited by examiner]
US 20210150789A1 · Szarzynski · 2021 [cited by examiner]
US 20210211438A1 · Trim · 2021 [cited by examiner]
US 20220019674A1 · Frey · 2022 [cited by examiner]
US 20230208858A1 · Mishra · 2023 [cited by examiner]
US 20230262073A1 · Sheu · 2023 [cited by examiner]
US 20230281310A1 · Chen · 2023 [cited by examiner]
Demidenko, “Applications of Symmetric Circulant Matrices to Isotropic Markov Chain Models and Electrical Impedance Tomography,” Advances in Pure Mathematics, Feb. 9, 2017, 11 pages, vol. 7, No. 2, DOI: 10.4236/apm.2017.… [cited by applicant]
Disclosed Anonymously, “Threat actors more frequently—and successfully—target Active Directory,” Sep. 30, 2021, 3 pages, Retrieved from the Internet: <URL: https://www.attivonetworks.com/solutions/threatdetection/>. [cited by applicant]
explainshell.com, “Match Command-line Arguments to Their Help Text,” explainshell.com, [accessed on Apr. 18, 2022], 1 page, Retrieved from the Internet: <URL: https://explainshell.com/#>. [cited by applicant]
github.com, “OpenDXL Ontology,” github.com, [accessed on Apr. 18, 2022], 2 pages, Retrieved from the Internet: <URL: https://github.com/opencybersecurityalliance/opendxl-ontology>. [cited by applicant]
Google AI, “Federated Learning,” federated.withgoogle.com [comic], 67 pages, [accessed on Apr. 18, 2022], Retrieved from the Internet: <URL: https://federated.withgoogle.com/>. [cited by applicant]
Illusive, “Illusive Shadow,” illusive.com, [accessed on Apr. 18, 2022], 1 page, Retrieved from the Internet: <URL: https://illusive.com/products/shadow/>. [cited by applicant]
Macheel, “Silicon Valley is Fighting a New Kind of Identity Fraud,” Cheddar, Mar. 28, 2019, 3 pages, Retrieved from the Internet: <URL: https://medium.com/cheddar/silicon-valley-is-fighting-a-new-kind-of-identity-fraud-… [cited by applicant]
McMahan, et al., “Federated Learning: Collaborative Machine Learning without Centralized Training Data,” Google AI Blog, Apr. 6, 2017 [accessed on Apr. 18, 2022], 5 pages, Retrieved from the Internet: <URL: https://ai.g… [cited by applicant]
Mell, et al., “The NIST Definition of Cloud Computing”, National Institute of Standards and Technology, Special Publication 800-145, Sep. 2011, 7 pages. [cited by applicant]
Screen captures from YouTube video clip entitled “Open Cybersecurity Alliance Status Update—May 2020,” 3 pages, uploaded on Jun. 11, 2020 by Open Cybersecurity Alliance, Retrieved from the Internet: <URL: https://www.yo… [cited by applicant]
Unknown, “Giant Language model Test Room,” GLTR [tweet], [accessed on Apr. 18, 2022], 1 pages, Retrieved from the Internet: <URL: http://gltr.io/dist/index.html>. [cited by applicant]
Cited By (1)
US 12,375,527