IP Library › Granted Patent US 12,368,755
Granted Patent B2
US 12,368,755 · App. 17/752,024 · Granted Jul 22, 2025

Methods and systems for honeyfile creation, deployment, and management

Inventors: Ben Whitham (Campbell, AU); David Liebowitz (Bruce, AU); Kiriya Keat (Narrabundah, AU); Connor Brendish (Nicholls, AU)
Assignee: Penten Pty Ltd
H04L63/1491G06F21/565G06F21/566G06F21/6218G06F2221/034G06Q10/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,755
App. No.
17/752,024
Granted
Jul 22, 2025
Kind
B2
Abstract

A method of automatically manipulating a lifecycle of a honeyfile on a file system, includes: implementing a learning algorithm on a file system; identifying a real file; training the learning algorithm by observing temporal events involving the real file; training a model with the learning algorithm; implementing a user agent on the file system; creating a honeyfile on the file system; deploying the honeyfile on the file system; using the trained model to generate user agent actions; evaluating the honeyfile; and either: deleting the honeyfile; or re-using the trained model to generate user agent actions to automatically modify the honeyfile.

Claims (90)

1. A method for automatically modifying honeyfiles for a file system, comprising:

implementing a user agent on the file system;

training models of user behavior on the file system by observation of real files on the file system, wherein:

interactions with real files are temporal events;

the temporal events are selected from a list comprising at least: create; copy; add content; delete content; and add comment; and

a time between the temporal events is sampled;

providing simple exclusion rules; and

using the trained models to generate user agent actions that automatically modify honeyfiles for a file system, wherein the modifications to the honeyfiles comprise at least one of:

creating multiple draft versions of honeyfiles;

copying files;

deleting files;

adding content in files;

deleting content in files;

replacing content in files; and

adding comments to files.

2. The method of claim 1 , wherein:

the adding content in files uses text generation methods to add topical content;

the replacing content in files uses text replacement methods to replace topical content; and

deleting content in files uses text deletion methods to delete topical content.

3. The method of claim 1 , wherein the modifications to the honeyfiles further comprises simulating having multiple users interact with a file.

4. The method of claim 3 , wherein the multiple users comprise simulated system users who are simulated to read a honeyfile.

5. The method of claim 3 , wherein the multiple users comprise simulated multiple authors who are simulated to modify a honeyfile.

6. The method of claim 1 , wherein the time between the temporal events is sampled, comprises:

observing the temporal events;

estimating parameters of a temporal distribution based on the observed temporal events; and

sampling the temporal distribution to determine the time for the user agent to automatically modify honeyfiles for a file system.

7. The method of claim 1 , wherein the time between the temporal events is sampled from a Poisson distribution.

8. The method of claim 1 , wherein the simple exclusion rules comprise not modifying honeyfiles that do not exist.

9. The method of claim 1 , wherein the modifications to the honeyfiles cause the honeyfile metadata to be modified.

10. A method of manipulating a lifecycle of honeyfiles for a file system, comprising:

creating a honeyfile for the file system automatically;

simulating users who manipulate with the honeyfile to modify content of the honeyfile;

saving the modified honeyfile to the file system.

11. The method of claim 10 , wherein following the saving the modified honeyfile to the file system, further comprising:

deleting the modified honeyfile from the file system.

12. The method of claim 10 , wherein the simulating users comprises:

implementing a user agent on the file system; and

running the user agent on a trained model to automatically manipulate the honeyfile to modify content of the honeyfile.

13. The method of claim 10 , wherein modifying the content of the honeyfile comprises at least one of:

creating multiple draft versions of honeyfiles;

copying files;

deleting files;

adding content in files;

deleting content in files;

replacing content in files; and

adding comments to files.

14. The method of claim 12 , wherein the trained model is trained by:

observing interactions with real files as temporal events;

sampling the temporal events from a list of temporal events comprising at least: create; copy; add content; delete content; and add comment; and

sampling a time between the temporal events.

15. A method of automatically manipulating a lifecycle of a honeyfile on a file system, comprising:

implementing a learning algorithm on a file system;

identifying a real file;

training the learning algorithm by observing temporal events involving the real file;

training a model with the learning algorithm;

implementing a user agent on the file system;

creating a honeyfile on the file system;

deploying the honeyfile on the file system;

using the trained model to generate user agent actions;

evaluating the honeyfile; and

either:

deleting the honeyfile; or

re-using the trained model to generate user agent actions to automatically modify the honeyfile.

16. The method of claim 15 , wherein automatically training the learning algorithm by observing temporal events involving the real file comprises causing the learning algorithm to observe:

the types of temporal events that a real user performs on the real file; and

the time durations between the temporal events that a real user performs on the real file.

17. The method of claim 15 , wherein automatically modifying the honeyfile comprises at least one of modifying the content of the honeyfile or simulating having multiple users interact with a file.

18. The method of claim 15 , wherein evaluating the honeyfile comprises at least one or more of: how well camouflaged is the file; how attractive is the file to the intruder; or how much sensitive content is exposed.

19. The method of claim 17 , wherein simulating having multiple users interact with a file comprises generating a typical number of automatic modifications for normal workdays, evenings, and weekends.

20. A system for automatically modifying honeyfiles for a file system, comprising:

a server connected via an electronic communications network to a file system of at least one user device, the server:

comprising:

a processor/controller;

a database including a file set; and

an interface; and

configured to execute the steps of:

implementing a user agent on a system;

training models of user behavior on the system, wherein:

interactions with files are temporal events;

the temporal events are sampled from a list comprising at least: create; copy; add content; delete content; and add comment; and

a time between the temporal events is sampled;

providing simple exclusion rules; and

running the user agent on the trained user behavior model to automatically modify honeyfiles for a file system; wherein the modifications to the honeyfiles comprise at least one of:

creating multiple draft versions of honeyfiles;

copying files;

deleting files;

adding content in files;

deleting content in files;

replacing content in files; and

adding comments to files.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: WHITHAM, BEN; LIEBOWITZ, DAVID; KEAT, KIRIYA; BRENDISH, CONNOR
To: PENTEN PTY LTD
Reel/Frame 060224/0620 →
Priority Claims (1)
AU 2018247212 · Oct 9, 2018 · national
Continuity (3)
Continuation In Part 17352251 · Jun 18, 2021
Continuation 16596139 · Oct 8, 2019
Related Publication 20220286478A1 · Sep 8, 2022
References Cited (39)
US 9501639B2 · Stolfo et al. · 2016 [cited by applicant]
US 9992259B2 · Lind · 2018 [cited by examiner]
US 10515214B1 · Vincent et al. · 2019 [cited by applicant]
US 10574698B1 · Sharifi Mehr · 2020 [cited by applicant]
US 10686836B1 · Stolfo · 2020 [cited by applicant]
US 11144656B1 · Banerjee et al. · 2021 [cited by applicant]
US 20090249082A1 · Mattsson · 2009 [cited by applicant]
US 20100269175A1 · Stolfo et al. · 2010 [cited by applicant]
US 20120246724A1 · Sheymov et al. · 2012 [cited by applicant]
US 20150302218A1 · Fielder · 2015 [cited by applicant]
US 20160180087A1 · Edwards et al. · 2016 [cited by applicant]
US 20160379289A1 · More · 2016 [cited by applicant]
US 20170104785A1 · Stolfo et al. · 2017 [cited by applicant]
US 20180324213A1 · Borlick et al. · 2018 [cited by applicant]
US 20190034083A1 · Cherubini et al. · 2019 [cited by applicant]
US 20190052675A1 · Krebs · 2019 [cited by applicant]
US 20190098032A1 · Murphey et al. · 2019 [cited by applicant]
US 20190190951A1 · Myron et al. · 2019 [cited by applicant]
US 20200050773A1 · Schroeder et al. · 2020 [cited by applicant]
US 20200053120A1 · Wilcox · 2020 [cited by applicant]
US 20200204590A1 · Whitham et al. · 2020 [cited by applicant]
US 20210067552A1 · Hebert et al. · 2021 [cited by applicant]
US 20210314356A1 · Whitham et al. · 2021 [cited by applicant]
US 20220004532A1 · Portisch et al. · 2022 [cited by applicant]
US 20220255962A1 · Liebowitz et al. · 2022 [cited by applicant]
US 20220286478A1 · Whitham et al. · 2022 [cited by applicant]
US 20240106846A1 · Kapoor · 2024 [cited by examiner]
Bowen, et al., “Baiting inside attackers using decoy documents” 5th International ICST Conference, SecureComm 2009, Athens, Greece; Sep. 2009 https://www.cs.columbia.edu/-amzelos/Papers/2009/DecoyDocumentsSECCOM09.pdf, … [cited by applicant]
Abay, N., et al., “Using Deep Leaning to Generate Relational HoneyData,” ResearchGate, Dec. 2018 (17 pages). [cited by applicant]
[No Author Listed] “Lost in Translation: Improving Decoy Documents via Automated translation”, IEEE CS Security and Privacy Workshops, Voris, Boggs, Stolfo, Dept. of Computer Science, Columbia University, © 2012, Jonath… [cited by applicant]
Bown, et al., “Baiting inside attackers using decoy documents” 5th International ICST Conference, SecureComm 2009, Athens, Greece; Sep. 2009 https://www.cs.columbia.edu/-amzelos/Papers/2009/DecoyDocumentsSECCOM09.pdf, 1… [cited by applicant]
EP 19202330.7, Extended European Search Report dated Feb. 21, 2020, 8 pages—English. [cited by applicant]
Voris, et al., “Bait and Snitch: Defending Computer Systems with Decoys” Proceedings of the cyber infrastructure protection conference, Strategic Studies Institute; Sep. 2013 http://ids.cs.columbia.edu/sites/default/fil… [cited by applicant]
Voris, et al., “Fox in the Trap: Thwarting Masqueraders via Automated Decoy Document Deployment” Presented at the European Workshop on System Security (EuroSec); Jul. 14, 2015. http://ids.cs.columbia.edu/sites/default/f… [cited by applicant]
Voris, et al., “Lost in Translation: Improving Decoy Documents via Automated Translation” IEEE CS Security and Privacy Workshops: SPW 2012: Proceedings: San Francisco, California, USA; May 24, 2012 https://ieeexplore.ie… [cited by applicant]
Whitman, “Automating the generation of enticing text content for high-interaction honeyfiles.” In Proceedings of the 50th Hawaii International Conference on System Sciences; Jan. 1, 2017, pp. 6069-6078. [cited by applicant]
Whitman, “Automating the Generation of Fake Documents to Detect Network Intruders” International Journal of Cyber-Security and Digital Forensics, vol. 2, No. 1, 2013, p. 103-118. [cited by applicant]
Whitman, “Canary Files: Generating Fake Files to Detect Critical Data Loss From Complex Computer Networks” in Conference: The Second International Conference on Cyber Security, Cyber Peacefare and Digital Forensic (Cybe… [cited by applicant]
Yuill, et al., “Honeyfiles: Deceptive Files for Intrusion Detection” In Proceedings of the 2004 IEEE Workshop on Information Assurance, U.S. Military Academy, West Point, NY; Jun. 2004. https://calhoun.nps.edu/handle/10… [cited by applicant]