IP Library Granted Patent US 12,592,968
Granted Patent B2
US 12,592,968 · App. 17/724,625 · Granted Mar 31, 2026

Cloud-based deception technology with granular scoring for breach detection

Inventors: Bhavesh Kothari (Pune, IN); Sahir Hidayatullah (Mumbai, IN); Deepen Desai (San Ramon, CA); Akshay Shah (Bangalore, IN); Reshad Patuck (Mumbai, IN)
Assignee: Zscaler, Inc.
H04L63/1491H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,968
App. No.
17/724,625
Filed
Apr 20, 2022
Granted
Mar 31, 2026
Kind
B2
Examiner
KIM, HEE SOO
Art Unit
2443
USPC
726/23
Abstract

Cloud-based deception systems and methods include monitoring activity associated with a plurality of decoys hosted in a decoy cloud environment for a customer, wherein the decoy cloud environment is separate from a real environment of the customer, and wherein the activity is between one or more fake assets on user devices of users associated with the customer; scoring the activity based on various steps taken between a fake asset and a decoy; and detecting a breach of the customer based on the scoring of the activity. The scoring includes increasing a score based on any activity by an attacker between the fake asset and the decoy.

Claims (30)

1 . A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming one or more processors to perform steps of:

monitoring activity associated with a plurality of decoys hosted in a decoy cloud environment for a customer, wherein the decoy cloud environment is separate from a real environment of the customer, and wherein the activity is between one or more fake assets on user devices of users associated with the customer and corresponding decoys in the decoy cloud environment;

generating a dynamic risk score configured to modulate in direct accord with the activity based on monitoring various steps taken between a fake asset and a decoy, wherein the monitoring is configured to track progressive stages of interaction between the fake assets and the corresponding decoys, and wherein each step taken by a user with the one or more fake assets, including initiating or upgrading a network connection, sending data, executing a decoy file, or using a decoy credential, increases the dynamic risk score in real time; and

detecting a breach of the customer based on the dynamic risk score exceeding a threshold, wherein any interaction with a fake asset is inherently treated as malicious such that the risk score begins from a zero-activity baseline and increases exclusively upon fake asset interactions.

2 . The non-transitory computer-readable storage medium of claim 1 , wherein scoring includes progressively increasing the dynamic risk score by discrete steps based on each additional step taken by an attacker between the fake asset and the decoy, including at least opening a decoy file, using a decoy credential, or attempting to access a decoy application.

3 . The non-transitory computer-readable storage medium of claim 2 , wherein the dynamic risk score is updated in real-time with each step, the step defining any of starting a network connection, upgrading the network connection, sending data, and sending data that has a malicious payload, and wherein the dynamic risk score is compared against a threshold to trigger an automated containment response.

4 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps include:

performing an automated containment response on the user responsive to the breach, including at least quarantining the compromised endpoint or disabling user account access in the real environment.

5 . The non-transitory computer-readable storage medium of claim 4 , wherein the monitoring, scoring, detecting, and performing are all performed in real-time.

6 . The non-transitory computer-readable storage medium of claim 4 , wherein the monitoring, scoring, detecting, and performing are all performed locally at the user device, and wherein the user device only logs activity related to the one or more fake assets.

7 . The non-transitory computer-readable storage medium of claim 4 , wherein the monitoring, scoring, detecting, and performing are all performed in a cloud-based system located between the user device and the Internet.

8 . The non-transitory computer-readable storage medium of claim 1 , wherein the fake assets include any of deceptive assets, files, breadcrumbs, lures, bait, network traffic, passwords, keys, session information, and cookies.

9 . The non-transitory computer-readable storage medium of claim 1 , wherein the fake assets are automatically generated based on a role of the user as determined from historical monitoring, such that a finance user receives financial record breadcrumbs and an R&D user receives R&D-related breadcrumbs.

10 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps include:

updating the scoring over time based on feedback.

11 . A method comprising steps of:

monitoring activity associated with a plurality of decoys hosted in a decoy cloud environment for a customer, wherein the decoy cloud environment is separate from a real environment of the customer, and wherein the activity is between one or more fake assets on user devices of users associated with the customer and corresponding decoys in the decoy cloud environment;

generating a dynamic risk score configured to modulate in direct accord with the activity based on monitoring various steps taken between a fake asset and a decoy, wherein the monitoring is configured to track progressive stages of interaction between the fake assets and the corresponding decoys, and wherein each step taken by a user with the one or more fake assets, including initiating or upgrading a network connection, sending data, executing a decoy file, or using a decoy credential, increases the dynamic risk score in real time; and

detecting a breach of the customer based on the dynamic risk score exceeding a threshold, wherein any interaction with a fake asset is inherently treated as malicious such that the risk score begins from a zero-activity baseline and increases exclusively upon fake asset interactions.

12 . The method of claim 11 , wherein scoring includes increasing the dynamic risk score based on any activity by an attacker between the fake asset and the decoy, including at least opening a decoy file, using a decoy credential, or attempting to access a decoy application.

13 . The method of claim 12 , wherein the dynamic risk score is updated with each step of starting a network connection, upgrading the network connection, sending data, and sending data that has a malicious payload, and wherein the dynamic risk score is compared against a threshold to trigger an automated containment response.

14 . The method of claim 11 , wherein the steps include:

performing an automated containment response on the user responsive to the breach, including at least quarantining the compromised endpoint or disabling user account access in the real environment.

15 . The method of claim 14 , wherein the monitoring, scoring, detecting, and performing are all performed in real-time.

16 . The method of claim 14 , wherein the monitoring, scoring, detecting, and performing are all performed locally at the user device, and wherein the user device only logs activity related to the one or more fake assets.

17 . The method of claim 14 , wherein the monitoring, scoring, detecting, and performing are all performed in a cloud-based system located between the user device and the Internet.

18 . The method of claim 11 , wherein the fake assets include any of deceptive assets, files, breadcrumbs, lures, bait, network traffic, passwords, keys, session information, and cookies.

19 . The method of claim 11 , wherein the fake assets are automatically generated based on a role of the user as determined from historical monitoring, such that a finance user receives financial record breadcrumbs and an R&D user receives R&D-related breadcrumbs.

20 . The method of claim 11 , wherein the steps include:

updating the scoring over time based on feedback.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2022
From: KOTHARI, BHAVESH; HIDAYATULLAH, SAHIR; DESAI, DEEPEN; SHAH, AKSHAY; PATUCK, RESHAD
To: ZSCALER, INC.
Reel/Frame 059647/0201 →
Priority Claims (1)
IN 202111053875 · Nov 23, 2021 · national
Continuity (2)
Continuation 17571460 · Jan 8, 2022
Related Publication 20230164183A1 · May 25, 2023
References Cited (27)
US 10142362B2 · Weith et al. · 2018 [cited by applicant]
US 10419477B2 · Desai et al. · 2019 [cited by applicant]
US 10498605B2 · Weith et al. · 2019 [cited by applicant]
US 10574697B1 · McClintock · 2020 [cited by examiner]
US 10855722B1 · Vadlamani · 2020 [cited by applicant]
US 10873601B1 · Stickle · 2020 [cited by examiner]
US 11032319B1 · Roundy · 2021 [cited by examiner]
US 11770408B2 · Krauss · 2023 [cited by examiner]
US 20090178142A1 · Lieblich · 2009 [cited by examiner]
US 20160065601A1 · Gong · 2016 [cited by examiner]
US 20170359376A1 · Evron · 2017 [cited by examiner]
US 20190108333A1 · Licata · 2019 [cited by examiner]
US 20190281073A1 · Weith et al. · 2019 [cited by applicant]
US 20190306719A1 · Chari · 2019 [cited by examiner]
US 20190319972A1 · Desai · 2019 [cited by applicant]
US 20200320192A1 · Ma et al. · 2020 [cited by applicant]
US 20210058428A1 · Arlitt et al. · 2021 [cited by applicant]
US 20210067553A1 · Ries · 2021 [cited by examiner]
US 20210105289A1 · Desai et al. · 2021 [cited by applicant]
US 20210192043A1 · Bhary et al. · 2021 [cited by applicant]
US 20210194925A1 · Xiao · 2021 [cited by examiner]
US 20210344693A1 · Azad et al. · 2021 [cited by applicant]
US 20220109692A1 · Hebert · 2022 [cited by examiner]
US 20220210163A1 · Norman · 2022 [cited by examiner]
CN 111641620A · 2020 [cited by applicant]
GB 2606591A · 2022 [cited by examiner]
Mar. 20, 2023, Extended European Search Report issued for European Patent Application No. EP 22 19 3125. [cited by applicant]