IP Library Granted Patent US 7,904,959
Granted Patent B2
US 7,904,959 · App. 11/870,043 · Granted Mar 8, 2011

Systems and methods for detecting and inhibiting attacks using honeypots

Assignee: The Trustees of Columbia University in the City of New York
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,904,959
App. No.
11/870,043
Granted
Mar 8, 2011
Kind
B2
Abstract

In accordance with some embodiments, systems and methods that protect an application from attacks are provided. In some embodiments, traffic from a communication network is received by an anomaly detection component. The anomaly detection component monitors the received traffic and routes the traffic either to the protected application or to a honeypot, where the honeypot shares all state information with the application. If the received traffic is routed to the honeypot, the honeypot monitors the traffic for an attack. If an attack occurs, the honeypot repairs the protected application (e.g., discarding any state changes incurred from the attack, reverting to previously saved state information, etc.).

Claims (50)

1. A method for protecting applications from attacks, the method comprising:

receiving traffic from a communication network that is attempting to reach an application;

transmitting the received traffic through an anomaly detection component, wherein the anomaly detection component predicts whether the received traffic is a potential attack on the application and wherein the anomaly detection component is tuned to achieve a low false negative rate;

receiving an indication from the anomaly detection component relating to the prediction of the potential attack on the application;

in response to receiving the indication from the anomaly detection component, transmitting the received traffic to a honeypot, wherein the honeypot is an instance of the application that shares state information with the application and wherein the honeypot monitors the received traffic for attacks on the application;

receiving an indication from the honeypot that the received traffic is an attack on the application; and

receiving an instruction from the honeypot to repair the state information of the application.

2. The method of claim 1 , wherein the repair further comprises rolling back the state information of the application to previously saved state information.

3. The method of claim 1 , wherein the repair further comprises discarding the state information of the application.

4. The method of claim 1 , wherein the repair further comprises initiating a new instance of the application with previously saved state information.

5. The method of claim 1 , further comprising filtering the received traffic prior to transmitting the received traffic to the anomaly detection component.

6. The method of claim 5 , where the filtering is based on at least one of payload content and source of the attack.

7. The method of claim 1 , further comprising transmitting feedback from the honeypot to the anomaly detection component.

8. The method of claim 7 , further comprising updating the anomaly detection component based at least in part on the feedback from the honeypot.

9. The method of claim 7 , further comprising updating at least one of predictors and models associated with the anomaly detection component.

10. The method of claim 7 , further comprising using the feedback to automatically tune the anomaly detection component.

11. The method of claim 7 , further comprising using the feedback to automatically tune a filter.

12. The method of claim 1 , wherein the application is one of a server application, a client application, an operating system, and an application on a mainframe.

13. A method for protecting applications from attacks, the method comprising:

receiving traffic from a communication network that is attempting to reach an application;

transmitting the received traffic through an anomaly detection component, wherein the anomaly detection component predicts whether the received traffic is a potential attack on the application and wherein the anomaly detection component is tuned to achieve a low false negative rate;

receiving an indication from the anomaly detection component relating to the prediction of the potential attack on the application;

in response to receiving the indication from the anomaly detection component, transmitting the received traffic to a honeypot, wherein the honeypot is an instance of the application that shares state information with the application and wherein the honeypot monitors the received traffic for attacks on the application;

receiving an indication from the honeypot that the received traffic is an attack on the application;

receiving an instruction from the honeypot to repair the state information of the application;

providing a filter before the anomaly detection component;

transmitting feedback from the honeypot to the filter; and

updating the filter based at least in part on the feedback from the honeypot.

14. A system for protecting applications from attacks, the system comprising:

at least one processor that includes:

an anomaly detection component that is tuned to achieve a low false negative rate, wherein the anomaly detection component is configured to:

receive traffic from a communication network that is attempting to reach an application; and

predict whether the received traffic is a potential attack on the application; and

a honeypot that is an instance of the application that shares state information with the application, wherein the honeypot is configured to:

receive an indication from the anomaly detection component relating to the prediction of the potential attack;

monitor the received traffic for attacks on the application; and

in response to determining that the received traffic is an attack on the application, repair the state information of the application.

15. The system of claim 14 , wherein the honeypot is further configured to roll back the state information of the application to previously saved state information.

16. The system of claim 14 , wherein the honeypot is further configured to discard the state information of the application.

17. The system of claim 14 , wherein the honeypot is further configured to initiate a new instance of the application with previously saved state information.

18. The system of claim 14 , further comprising a filter that filters the received traffic prior to transmitting the received traffic to the anomaly detection component.

19. The system of claim 14 , wherein the honeypot is further configured to transmit feedback from the honeypot to the anomaly detection component.

20. The system of claim 19 , wherein the anomaly detection component is further configured to update the anomaly detection component based at least in part on the feedback from the honeypot.

21. The system of claim 19 , wherein the anomaly detection component is further configured to update at least one of predictors and models associated with the anomaly detection component.

22. The system of claim 19 , wherein the anomaly detection component is further configured to tune the anomaly detection component based at least in part of the feedback.

23. A system for protecting applications from attacks, the system comprising:

at least one processor that includes:

an anomaly detection component that is tuned to achieve a low false negative rate, wherein the anomaly detection component is configured to receive traffic from a communication network that is attempting to reach an application and predict whether the received traffic is a potential attack on the application;

a honeypot that is an instance of the application that shares state information with the application, wherein the honeypot is configured to receive an indication from the anomaly detection component relating to the prediction of the potential attack, monitor the received traffic for attacks on the application, and, in response to determining that the received traffic is an attack on the application, repair the state information of the application; and

a filter configured to receive the traffic before the anomaly detection component, wherein the filter receives feedback from the honeypot and is updated based at least in part on the feedback from the honeypot.

Assignments (2)
CONFIRMATORY LICENSE Recorded Feb 28, 2012
From: COLUMBIA UNIVERSITY
To: NAVY, SECRETARY OF THE UNITED STATES OF AMERICA
Reel/Frame 027854/0115 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2008
From: SIDIROGLOU, STYLIANOS; KEROMYTIS, ANGELOS D.; ANAGNOSTAKIS, KOSTAS G.
To: THE TRUSTEES OF COLUMBIA UNIVERSITY IN THE CITY OF NEW YORK
Reel/Frame 020484/0360 →
Continuity (3)
Continuation PCTUS2006014704 · Apr 18, 2006
Provisional Application 60672280 · Apr 18, 2005
Related Publication 20080141374A1 · Jun 12, 2008