IP Library › Granted Patent US 12,506,781
Granted Patent B2
US 12,506,781 · App. 18/606,309 · Granted Dec 23, 2025

Generating deceptions using web assembly binaries

Inventors: Gautam Heera Kumar (Bangalore, IN); Mallikarjuna Mustugatti (Bangalore, IN)
Assignee: International Business Machines Corporation
H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,781
App. No.
18/606,309
Granted
Dec 23, 2025
Kind
B2
Abstract

Deception management is provided. Configuration of a plurality of assets in an information technology (IT) environment of an entity is detected based on a scan of the plurality of assets. A plurality of deceptions is generated by customizing predefined deceptions based on specific needs of the entity corresponding to a geographic location of the IT environment. The plurality of deceptions are deployed among the plurality of assets within the IT environment based on the configuration of the plurality of assets in the IT environment.

Claims (65)

1. A computer-implemented method for deception management, the computer-implemented method comprising:

detecting, by a deception management computer, configuration of a plurality of assets in an information technology (IT) environment of an entity based on an agent-less scan of the plurality of assets performed by the deception management computer;

retrieving, by the deception management computer, threat intelligence regarding known cyberattacks and attack behavior corresponding to a geographic location of the IT environment from a cybersecurity system;

generating, by the deception management computer, a plurality of customized deceptions by:

customizing predefined deceptive entities and predefined network-based device emulations using a Web Assembly module integrated within the deception management computer;

compiling each customized deception into a respective Web Assembly binary using Web Assembly System Interface (WASI) or WASI-NN for operating system deployment, wherein the Web Assembly binaries execute independently on target physical host endpoints without shared operating system vulnerabilities and without requiring individual virtual machines or containers;

identifying, by the deception management computer, target physical host endpoints for deployment based on both the configuration of the plurality of assets and threat intelligence information corresponding to the geographic location; and

deploying, by the deception management computer, the plurality of customized deceptions directly on the identified target physical host endpoints using the respective Web Assembly binaries without intermediary trap servers and without assigning IP addresses to the customized deceptions.

2. The computer-implemented method of claim 1 , wherein the plurality of deceptions include at least one of a plurality of deceptive entities and a plurality of network-based device emulations.

3. The computer-implemented method of claim 1 , further comprising:

customizing, by the computer, a plurality of predefined deceptive entities and a plurality of predefined network-based device emulations by generating a deceptive entity Web Assembly binary for each respective deceptive entity of the plurality of predefined deceptive entities and a network-based device emulation Web Assembly binary for each respective network-based device emulation of the plurality of predefined network-based device emulations using a Web Assembly module to form a plurality of customized deceptive entities and a plurality of customized network-based device emulations; and

deploying, by the computer, the plurality of customized deceptive entities and the plurality of customized network-based device emulations on a plurality of target physical host endpoints within the IT environment using the deceptive entity Web Assembly binary of each respective deceptive entity of the plurality of customized deceptive entities and the network-based device emulation Web Assembly binary of each respective network-based device emulation of the plurality of customized network-based device emulations.

4. The computer-implemented method of claim 1 , further comprising:

receiving, by the computer, an alert indicating access to one of a customized deceptive entity or a customized network-based device emulation deployed on a target physical host endpoint of a plurality of target physical host endpoints within the IT environment.

5. The computer-implemented method of claim 1 , further comprising:

sending, by the computer, a notification to a system administrator regarding an access to a customized deceptive entity or a customized network-based device emulation deployed on a target physical host endpoint in response to receiving an alert indicating the access; and

performing, by the computer, a set of action steps automatically to mitigate effects of the access.

6. The computer-implemented method of claim 5 , wherein the set of action steps includes automatically terminating a connection to the IT environment corresponding to the access, automatically removing any files, scripts, or code received during the access, sending a notification to a cybersecurity system regarding the access, and recording information corresponding to the access to prevent similar future access.

7. The computer-implemented method of claim 1 , further comprising:

receiving, by the computer, a download of a plurality of predefined deceptive entities and a plurality of predefined network-based device emulations into a Web Assembly module of the computer; and

receiving, by the computer, an input to deploy the plurality of predefined deceptive entities and the plurality of predefined network-based device emulations within the IT environment of the entity.

8. The computer-implemented method of claim 1 , further comprising:

performing, by the computer, an asset discovery scan of the IT environment to detect a number of physical host endpoints in the IT environment, a location of each of the number of physical host endpoints within the IT environment, configuration of each of the number of physical host endpoints, and a type of operating system running on each of the number of physical host endpoints; and

performing, by the computer, an analysis of the asset discovery scan of the IT environment.

9. The computer-implemented method of claim 1 , further comprising:

retrieving, by the computer, information regarding known cyberattacks and attack behavior corresponding to a geographic location of the IT environment from a cybersecurity system.

10. The computer-implemented method of claim 1 , further comprising:

identifying, by the computer, locations for placement of a plurality of predefined deceptive entities and a plurality of predefined network-based emulations on a plurality of target physical host endpoints within the IT environment based on an analysis of an asset discovery scan of the IT environment and known cyberattacks and attack behavior corresponding to a geographic location of the IT environment.

11. A computer system for deception management, the computer system comprising:

a communication fabric;

a set of computer-readable storage media connected to the communication fabric, wherein the set of computer-readable storage media collectively stores program instructions; and

a set of processors connected to the communication fabric, wherein the set of processors executes the program instructions to:

detect configuration of a plurality of assets in an information technology (IT) environment of an entity based on an agent-less scan of the plurality of assets;

retrieve threat intelligence regarding known cyberattacks and attack behavior corresponding to a geographic location of the IT environment from a cybersecurity system;

generate a plurality of customized deceptions by:

customizing predefined deceptive entities and predefined network-based device emulations using a Web Assembly module,

compiling each customized deception into a respective Web Assembly binary using Web Assembly System Interface (WASI) or WASI-NN for operating system deployment, wherein the Web Assembly binaries execute independently

target physical host endpoints without shared operating system vulnerabilities and without requiring individual virtual machines or containers;

identify target physical host endpoints for deployment based on both the configuration of the plurality of assets and a threat intelligence information corresponding to the geographic location; and

deploy the plurality of assets customized deceptions directly on the identified target physical host endpoints using the respective Web Assembly binaries without intermediary trap servers and without assigning IP addresses to the customized deceptions.

12. The computer system of claim 11 , wherein the plurality of deceptions include at least one of a plurality of deceptive entities and a plurality of network-based device emulations.

13. The computer system of claim 11 , wherein the set of processors further executes the program instructions to:

customize a plurality of predefined deceptive entities and a plurality of predefined network-based device emulations by generating a deceptive entity Web Assembly binary for each respective deceptive entity of the plurality of predefined deceptive entities and a network-based device emulation Web Assembly binary for each respective network-based device emulation of the plurality of predefined network-based device emulations using a Web Assembly module to form a plurality of customized deceptive entities and a plurality of customized network-based device emulations; and

deploy the plurality of customized deceptive entities and the plurality of customized network-based device emulations on a plurality of target physical host endpoints within the IT environment using the deceptive entity Web Assembly binary of each respective deceptive entity of the plurality of customized deceptive entities and the network-based device emulation Web Assembly binary of each respective network-based device emulation of the plurality of customized network-based device emulations.

14. The computer system of claim 11 , wherein the set of processors further executes the program instructions to:

receive an alert indicating access to one of a customized deceptive entity or a customized network-based device emulation deployed on a target physical host endpoint of a plurality of target physical host endpoints within the IT environment.

15. A computer program product for deception management, the computer program product comprising a set of computer-readable storage media having program instructions collectively stored therein, the program instructions executable by a computer to cause the computer to:

detect configuration of a plurality of assets in an information technology (IT) environment of an entity based on an agent-less scan of the plurality of assets;

retrieve threat intelligence regarding known cyberattacks and attack behavior corresponding to a geographic location of the IT environment from a cybersecurity system;

generate a plurality of customized deceptions by:

customizing predefined deceptive entities and predefined network-based device emulations using a Web Assembly module integrated within the deception management computer,

compiling each customized deception into a respective Web Assembly binary using Web Assembly System Interface (WASI) or WASI-NN for operating system deployment, wherein the Web Assembly binaries execute independently

target physical host endpoints without shared operating system vulnerabilities and without requiring individual virtual machines or containers;

identify target physical host endpoints for deployment based on both the configuration of the plurality of assets and a threat intelligence information corresponding to the geographic location; and

deploy the plurality of assets customized deceptions directly on the identified target physical host endpoints using the respective Web Assembly binaries without intermediary trap servers and without assigning IP addresses to the customized deceptions.

16. The computer program product of claim 15 , wherein the plurality of deceptions include at least one of a plurality of deceptive entities and a plurality of network-based device emulations.

17. The computer program product of claim 15 , wherein the program instructions further cause the computer to:

customize a plurality of predefined deceptive entities and a plurality of predefined network-based device emulations by generating a deceptive entity Web Assembly binary for each respective deceptive entity of the plurality of predefined deceptive entities and a network-based device emulation Web Assembly binary for each respective network-based device emulation of the plurality of predefined network-based device emulations using a Web Assembly module to form a plurality of customized deceptive entities and a plurality of customized network-based device emulations; and

deploy the plurality of customized deceptive entities and the plurality of customized network-based device emulations on a plurality of target physical host endpoints within the IT environment using the deceptive entity Web Assembly binary of each respective deceptive entity of the plurality of customized deceptive entities and the network-based device emulation Web Assembly binary of each respective network-based device emulation of the plurality of customized network-based device emulations.

18. The computer program product of claim 15 , wherein the program instructions further cause the computer to:

receive an alert indicating access to one of a customized deceptive entity or a customized network-based device emulation deployed on a target physical host endpoint of a plurality of target physical host endpoints within the IT environment.

19. The computer program product of claim 15 , wherein the program instructions further cause the computer to:

send a notification to a system administrator regarding an access to a customized deceptive entity or a customized network-based device emulation deployed on a target physical host endpoint in response to receiving an alert indicating the access; and

perform a set of action steps automatically to mitigate effects of the access.

20. The computer program product of claim 19 , wherein the set of action steps includes automatically terminating a connection to the IT environment corresponding to the access, automatically removing any files, scripts, or code received during the access, sending a notification to a cybersecurity system regarding the access, and recording information corresponding to the access to prevent similar future access.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2024
From: KUMAR, GAUTAM HEERA; MUSTUGATTI, MALLIKARJUNA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 066787/0126 →
Continuity (1)
Related Publication 20250294056A1 · Sep 18, 2025
References Cited (17)
US 9716727B1 · Seger · 2017 [cited by examiner]
US 9853999B2 · Singh et al. · 2017 [cited by applicant]
US 10333976B1 · Yudovich et al. · 2019 [cited by applicant]
US 10382483B1 · Kafri et al. · 2019 [cited by applicant]
US 10498763B2 · Araujo et al. · 2019 [cited by applicant]
US 11233823B1 · Venkataramani · 2022 [cited by examiner]
US 12041094B2 · Sharifi Mehr · 2024 [cited by examiner]
US 20210067553A1 · Ries · 2021 [cited by examiner]
US 20230106071A1 · Kleymenov · 2023 [cited by examiner]
US 20230231882A1 · Deng · 2023 [cited by examiner]
CN 116232723A · 2023 [cited by examiner]
English language translation of Chinese Patent CN116232723A (9 pages) (Year: 2023). [cited by examiner]
FortiDeceptor, “FortiDeceptor: Deception-based Breach Protection Overview,” Fortinet SecOps Platform, Fortinet, accessed Feb. 27, 2024, https://www.fortinet.com/products/fortideceptor. [cited by applicant]
Github, “deception,” GitHub Topics, 7 pages, GitHub, accessed Feb. 29, 2024, https://github.com/topics/deception. [cited by applicant]
He, “Optimal Deception Asset Deployment in Cybersecurity: A Nash Q-Learning Approach in Multi-Agent Stochastic Games,” Applied Sciences, Dec. 30, 2023, 29 pages, vol. 14, MDPI, accessed Feb. 27, 2024, https://www.mdpi.c… [cited by applicant]
Niakanlahiji, et al., “HoneyBug: Personalized Cyber Deception for Web Applications,” Proceedings of the 53rd Hawaii International Conference on System Sciences, Jan. 10, 2020, 11 pages, ResearchGate, accessed Feb. 27, 2… [cited by applicant]
Shahid, et al., “A deep learning assisted personalized deception system for countering web application attacks,” Journal of Information Security and Applications, vol. 67, Jun. 2022, 17 pages, https://www.sciencedirect.… [cited by applicant]