IP Library › Granted Patent US 12,726,518
Granted Patent B2
US 12,726,518 · App. 18/530,788 · Granted Sep 1, 2026

Honeypotted file detection

Inventors: Eric C. Nanney (Tinley Park, IL); Benjamin Tweel (Romeoville, IL); Pamela Wilson (Chicago, IL)
Assignee: Bank of America Corporation
H04L63/1491H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,518
App. No.
18/530,788
Granted
Sep 1, 2026
Kind
B2
Abstract

A computing platform may train a machine learning model to detect and analyze threat actor activities. The computing platform may generate dynamic honeypotted files and deploy the generated dynamic honeypotted files as adaptive defenses to threat actors in a computing environment. The computing platform may adapt to threat actor activities based on analyzed behavior of the threat actor and any identified tools used by the threat actor to gain access to the computing system. Threat actor activities may be written to a blockchain to publicly record all transactions related to a threat actor's activities for analysis and generation of adaptive defenses to threat actor attacks. The computing platform may cause redirection of the threat actor into a specific computing environment through generation and deployment of dynamic honeypotted files.

Claims (77)

1 . A computing platform comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

generate at least one dynamic honeypotted file, the at least one generated dynamic honeypotted file including at least one unique indicator embedded within the at least one generated dynamic honeypotted file, and wherein a machine learning model is trained using historical threat occurrence information including labelled data on whether access patterns correspond to threat actors;

deploy the at least one generated dynamic honeypotted file into a computing network;

monitor the deployed at least one generated dynamic honeypotted file for threat actor activity;

detect threat actor activity associated with the deployed at least one generated dynamic honeypotted file;

write information regarding the detection of the threat actor activity to a blockchain, the information including detailed data associated with the detection of the threat actor activity; and

transmit a notification of the detection of the threat actor activity and the deployment of the at least one generated dynamic honeypotted file;

access the blockchain to retrieve information regarding access and usage of the generated dynamic honeypotted file;

analyze with a machine learning model the retrieved blockchain information regarding access and usage of at least one generated dynamic honeypotted file;

determine by the machine learning model a mapping of locations of the at least one generated dynamic honeypotted file, wherein the mapping includes geolocation information derived from the detailed data in the blockchain for the at least one generated dynamic honeypotted file and the computing device associated with the threat actor; and

transmit a notification of the determined mapping of the location of the at least one generated dynamic honeypotted file.

2 . The computing platform of claim 1 , wherein the memory stores additional computer readable instructions that, when executed by the at least one processor, cause the computing platform to:

access the blockchain to retrieve information regarding access and usage of the generated dynamic honeypotted file;

analyze with a machine learning model the retrieved blockchain information regarding access and usage of at least one generated dynamic honeypotted file, wherein analyzing the retrieved blockchain information with the machine learning model identifies patterns in threat actor behavior to determine characteristics for the at least one additional dynamic honeypotted file;

generate at least one additional dynamic honeypotted file based on the analyzed information regarding access and usage of at least one dynamic honeypotted file, the at least one generated additional dynamic honeypotted file including at least one unique indicator embedded within the at least one additional generated dynamic honeypotted file;

deploy the at least one generated additional dynamic honeypotted file into the computing network;

monitor the deployed at least one generated additional dynamic honeypotted file for threat actor activity;

detect threat actor activity associated with the deployed at least one generated additional generated dynamic honeypotted file;

write information regarding the detection of the threat actor activity to a blockchain, the information including detailed data associated with the detection of the threat actor activity; and

transmit a notification of the detection of the threat actor activity and the deployment of the at least one generated additional dynamic honeypotted file.

3 . The computing platform of claim 2 , wherein deployment of the at least one generated additional dynamic honeypotted file into the computing network comprises deployment into a sandbox of the computing network.

4 . The computing platform of claim 3 , wherein the memory stores additional computer readable instructions that, when executed by the at least one processor, cause the computing platform, after a specific predetermined time period, to terminate the sandbox to remove threat actor associated with the further threat activity, wherein terminating the sandbox removes the threat actor after isolating and analyzing patterns of the threat actor activity for additional insights.

5 . The computing platform of claim 1 , wherein the determined mapping of the location of the at least one generated dynamic honeypotted file further includes determination of location information of the computing device associated with the threat actor.

6 . The computing platform of claim 1 , wherein the memory stores additional computer readable instructions that, when executed by the at least one processor, cause the computing platform to:

generate, by a reporting system, a summary indicating results of the monitoring and detection; and

transmit, to an administrator device, the summary and one or more commands directing the administrator device to display the summary, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary.

7 . The computing platform of claim 1 , wherein the memory stores additional computer readable instructions that, when executed by the at least one processor, cause the computing platform to search for the unique identifier on the web locate the at least one generated dynamic honeypotted file.

8 . The computing platform of claim 1 , wherein deployment of the at least one generated dynamic honeypotted file into the computing network comprises deployment into a sandbox of the computing network, wherein terminating the sandbox removes the threat actor after isolating and analyzing patterns of the threat actor activity for additional insights.

9 . A method comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

generating at least one dynamic honeypotted file, the at least one generated dynamic honeypotted file including at least one unique indicator embedded within the at least one generated dynamic honeypotted file, and wherein a machine learning model is trained using historical threat occurrence information including labelled data on whether access patterns correspond to threat actors;

deploying the at least one generated dynamic honeypotted file into a computing network;

monitoring the deployed at least one generated dynamic honeypotted file for threat actor activity;

detecting threat actor activity associated with the deployed at least one generated dynamic honeypotted file;

writing information regarding the detection of the threat actor activity to a blockchain, the information including detailed data associated with the detection of the threat actor activity; and

transmitting a notification of the detection of the threat actor activity and the deployment of the at least one generated dynamic honeypotted file;

accessing the blockchain to retrieve information regarding access and usage of the generated dynamic honeypotted file;

analyzing with a machine learning model the retrieved blockchain information regarding access and usage of at least one generated dynamic honeypotted file;

determining by the machine learning model a mapping of locations of the at least one generated dynamic honeypotted file, wherein the mapping includes geolocation information derived from the detailed data in the blockchain for the at least one generated dynamic honeypotted file and the computing device associated with the threat actor; and

transmitting a notification of the determined mapping of the location of the at least one generated dynamic honeypotted file.

10 . The method of claim 9 further comprising at the computing platform comprising at least one processor, a communication interface, and memory:

accessing the blockchain to retrieve information regarding access and usage of the generated dynamic honeypotted file;

analyzing with a machine learning model the retrieved blockchain information regarding access and usage of at least one generated dynamic honeypotted file, wherein analyzing the retrieved blockchain information with the machine learning model identifies patterns in threat actor behavior to determine characteristics for the at least one additional dynamic honeypotted file;

generating at least one additional dynamic honeypotted file based on the analyzed information regarding access and usage of at least one dynamic honeypotted file, the at least one generated additional dynamic honeypotted file including at least one unique indicator embedded within the at least one generated additional dynamic honeypotted file;

deploying the at least one generated additional dynamic honeypotted file into the computing network;

monitoring the deployed at least one generated additional dynamic honeypotted file for threat actor activity;

detecting threat actor activity associated with the deployed at least one generated additional generated dynamic honeypotted file;

writing information regarding the detection of the threat actor activity to a blockchain, the information including detailed data associated with the detection of the threat actor activity; and

transmitting a notification of the detection of the threat actor activity and the deployment of the at least one generated additional dynamic honeypotted file.

11 . The method of claim 10 , wherein deployment of the at least one generated additional dynamic honeypotted file into the computing network comprises deployment into a sandbox of the computing network, wherein terminating the sandbox removes the threat actor after isolating and analyzing patterns of the threat actor activity for additional insights.

12 . The method of claim 11 , wherein the memory stores additional computer readable instructions that, when executed by the at least one processor, cause the computing platform to after a specific predetermined time period, terminate the sandbox to remove threat actor associated with the further threat activity, wherein terminating the sandbox removes the threat actor after isolating and analyzing patterns of the threat actor activity for additional insights.

13 . The method of claim 9 , wherein the determined mapping of the location of the at least one generated dynamic honeypotted file further includes determination of location information of the computing device associated with the threat actor.

14 . The method of claim 9 , wherein the memory stores additional computer readable instructions that, when executed by the at least one processor, cause the computing platform to search for the unique identifier on the web locate the at least one generated dynamic honeypotted file.

15 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

generate at least one dynamic honeypotted file, the at least one generated dynamic honeypotted file including at least one unique indicator embedded within the at least one generated dynamic honeypotted file, and wherein a machine learning model is trained using historical threat occurrence information including labelled data on whether access patterns correspond to threat actors;

deploy the at least one generated dynamic honeypotted file into a computing network;

monitor the deployed at least one generated dynamic honeypotted file for threat actor activity;

detect threat actor activity associated with the deployed at least one generated dynamic honeypotted file;

write information regarding the detection of the threat actor activity to a blockchain, the information including detailed data associated with the detection of the threat actor activity; and

transmit a notification of the detection of the threat actor activity and the deployment of the at least one generated dynamic honeypotted file;

access the blockchain to retrieve information regarding access and usage of the generated dynamic honeypotted file;

analyze with a machine learning model the retrieved blockchain information regarding access and usage of at least one generated dynamic honeypotted file;

determine by the machine learning model a mapping of locations of the at least one generated dynamic honeypotted file, wherein the mapping includes geolocation information derived from the detailed data in the blockchain for the at least one generated dynamic honeypotted file and the computing device associated with the threat actor; and

transmit a notification of the determined mapping of the location of the at least one generated dynamic honeypotted file.

16 . The one or more non-transitory computer-readable storing instructions of claim 15 , that when executed by the computing platform comprising at least one processor, a communication interface, and memory, further cause the computing platform to:

access the blockchain to retrieve information regarding access and usage of the generated dynamic honeypotted file;

analyze with a machine learning model the retrieved blockchain information regarding access and usage of at least one generated dynamic honeypotted file, wherein analyzing the retrieved blockchain information with the machine learning model identifies patterns in threat actor behavior to determine characteristics for the at least one additional dynamic honeypotted file;

generate at least one additional dynamic honeypotted file based on the analyzed information regarding access and usage of at least one dynamic honeypotted file, the at least one generated additional dynamic honeypotted file including at least one unique indicator embedded within the at least one generated additional dynamic honeypotted file;

deploy the at least one generated additional dynamic honeypotted file into the computing network;

monitor the deployed at least one generated additional dynamic honeypotted file for threat actor activity;

detect threat actor activity associated with the deployed at least one generated additional generated dynamic honeypotted file;

write information regarding the detection of the threat actor activity to a blockchain, the information including detailed data associated with the detection of the threat actor activity; and

transmit a notification of the detection of the threat actor activity and the deployment of the at least one generated additional dynamic honeypotted file.

17 . One or more non-transitory computer-readable of claim 15 , wherein the determined mapping of the location of the at least one generated dynamic honeypotted file further includes determination of location information of the computing device associated with the threat actor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2023
From: NANNEY, ERIC C.; TWEEL, BENJAMIN; WILSON, PAMELA
To: BANK OF AMERICA CORPORATION
Reel/Frame 065814/0475 →
Continuity (1)
Related Publication 20250193239A1 · Jun 12, 2025
References Cited (10)
US 11050787B1 · Sharifi Mehr · 2021 [cited by applicant]
US 11611586B2 · Strogov et al. · 2023 [cited by applicant]
US 11818172B1 · Miretsky · 2023 [cited by examiner]
US 20210216630A1 · Karr · 2021 [cited by examiner]
US 20240364740A1 · Ezrielev · 2024 [cited by examiner]
US 20250141896A1 · Thomas · 2025 [cited by examiner]
US 20250175498A1 · Strogov · 2025 [cited by examiner]
CN 111800407B · 2022 [cited by examiner]
WO WO2021181391A1 · 2021 [cited by examiner]
English language transalation of Chinese Patent CN-111800407-B (12 pages) (Year: 2020). [cited by examiner]